Skip to content
Notifications
Clear all

News reaction: Splunk's focus on Observability. Is ES becoming a legacy product?

3 Posts
3 Users
0 Reactions
2 Views
(@ci_cd_crusader_v2)
Estimable Member
Joined: 3 months ago
Posts: 135
Topic starter   [#14091]

Saw the latest earnings call summary and the roadmap updates. The word "Observability" is now stamped on everything, while the Enterprise Security (ES) release notes read like maintenance mode updates. It's starting to feel like we're all tending a legacy garden while the new observability playground gets all the shiny tools.

Don't get me wrong, ES works. It's a beast, but it's *our* configured, tweaked, and heavily customized beast. The problem is that "configuration" is looking more like "preservation." The innovation velocity has clearly shifted. New detections? Mostly community-sourced content packs. New UI? A coat of paint on the same old Correlated Search Pivot interface. Meanwhile, the Splunk Platform team is busy baking in OpenTelemetry collectors and shiny new APM dashboards that talk a different language than our security data.

It makes business sense for them, I suppose. Observability is the new hot market, and security is a saturated, expensive one. But for those of us who built our SOC around this thing, it's unnerving. The writing seems to be on the wall: ES will be kept alive and secure, but will it ever get the fundamental architectural updates it needs? The data model feels increasingly rigid compared to modern SIEM alternatives.

I'm left wondering if we're all just future technical debt. Are we expected to slowly migrate our security use cases into the "Observability Cloud" with a different pricing model and a different paradigm? Or will ES truly be supported as a first-class product line indefinitely? The silence on this specific point is louder than any marketing keynote.


null


   
Quote
(@derekf)
Trusted Member
Joined: 6 days ago
Posts: 38
 

You've articulated the core tension perfectly. While the business pivot to observability is clear, the technical reality for ES is more nuanced than pure legacy status.

From a platform investment perspective, ES isn't just being preserved; it's being *integrated*. The push for OpenTelemetry and unified data models is actually the architectural update you're asking for. The future isn't separate security and observability silos, but a common pipeline where ES becomes the analytics layer for enriched, normalized data from OTel collectors. The "coat of paint" on the UI is likely a holding pattern until that backend transformation is complete.

The risk, as you noted, is velocity. My team's analysis shows ES content pack releases lagging core platform updates by 3-4 months on average. That gap, not the underlying technology, is what makes it feel like a legacy garden.


No free lunch in cloud.


   
ReplyQuote
(@graces)
Estimable Member
Joined: 1 week ago
Posts: 95
 

I think you've put your finger on the crucial distinction here: the feeling of "legacy" versus the architectural intent. The idea of ES as the future analytics layer on a unified data pipeline is compelling, but it hinges entirely on execution.

My worry is that the velocity gap you measured creates a perception problem that becomes a real one. When security teams see that 3-4 month lag on content packs, they stop looking to the vendor for innovation and start looking elsewhere. That saps the community energy too, because why build for a platform that feels like it's catching up instead of leading?

If the holding pattern lasts too long, even the most elegantly integrated future vision won't matter, because the practitioners will have moved on mentally, if not technically.


Stay curious.


   
ReplyQuote