OpenTelemetry, Cybersecurity and Observability – KubeCon Europe 2025
KubeCon welcomes Alan Shimel and guest Stephane Estevez from Cisco/Splunk, who discusses his background and Splunk’s transformation into a cybersecurity and observability leader. The conversation highlights the significance of OpenTelemetry for data collection, with new features announced to improve auto-instrumentation. They also highlight Splunk’s ongoing support for the open-source community and its future role in OpenTelemetry.
Transcript
This is Textron tv. Hey everyone, it's Alan Shimel. It's lunchtime here at CubeCon.
I don't, well, you can only see this way, but if you would see that way, you would see droves of people lined up to get their, uh, brown bag lunches that they, you know, famous here at CubeCon. Um, but let me introduce you to our next guest. His name is Stefan Estevez.
Estevez. Estevez. Yes.
Esteve. Stefan is with Cisco, actually with Splunk. A Cisco company.
Yes, Exactly. You more precise. That's, that's the right way.
And, uh, he's based in Paris, here at London for today's, uh, CubeCon event. Stefan, welcome to Tech Drunk tv. Thank you for having me.
Let's start off with a little bit about you. Give us your background and what your position is with Splunk, if you don't mind. Okay.
I mean, uh, I joined Splunk like seven years ago. Um, initially as a product marketing director for observability, EA wide now, um, what we call a market advisor. Uh, so it's roughly the same, but a little bit more, uh, interactions with the customers.
And, um, prior to that, I spent all my life in data centers. So I'm more coming from the other part of the fence. Yeah, the production environment, uh, working for cloud providers, ISPs, MSPs, That's not a bad thing.
And what's your current position with Splunk? Um, market advisor, uh, for observability. So my role basically is to understand the market trends and, uh, explain to the customer what's going on on observability nowadays.
And that's why I, I'm here for cubicle because Sure. It's cubicle observability. I mean it's Makes sense.
You know, I followed Splunk a long time. 2020 years. I bet.
Oh yeah. It's, Uh, when I used to, when they used to have the really nice black t-shirts that were very catchy. You Mean those ones Similar?
Yeah, yeah. Like that. They still have 'em, Of course, Obviously You can find them on eBay.
I see. The people, I even seen them. We have them for free.
I have some in the back of my jaw. Okay. I had put them away way back.
'cause they would, they, they used to have really, you know, the, the writing, the, the wearing shirts were very funny. Anyway, of course, Splunk is now part of Cisco. Yes.
And as part of Cisco, I've always wondered, is Splunk a security company? Is Splunk an observability company? What, you know, how does it fit in into the bigger Cisco picture?
Okay. So let's step one step back if you Okay, go Ahead. As you said, we no longer a startup.
We started like more than 20 years ago as a data platform. Yes. We started with logs.
Yes. Unfortunately, we were a little bit too successful. So people still think that we do logs only, but even when we started, uh, we could collect any kind of, uh, machine data, right?
It could come from GPS location to whatever you want into the data platform. And then we wanted this data to talk, ask questions to this data. And then very quickly the, our customers find out that, hold on, but I can get data from everything and then I can improve my security posture.
And that's how we became a cybersecurity company as well. So we added, um, a sim solution, an orchestration solution for that. I mean, many solutions on top of what Splunk can do in cybersecurity.
And a few years ago also, we moved into the observability even before observability was a word, to be honest. Right. Um, so now we are also an observability solution, but that all these are consequences are starting as a data platform, right?
So we address many different markets nowadays, But at the end of the day, it's all about the data. You got it. Exactly.
Whatever you want. I mean, the idea is we work on, uh, digital resilience and basically you need to, to be digitally resilient, you need to be good at security and at availability and performance and observability and cybersecurity. Excellent.
Now big presence here. Yeah. And you know, both cybersecurity and observability and for that matter data are all very, you know, core to the whole CNCF Yes.
Mission. And you look at the, the breadth of the open source projects they support. But I, observability has certainly become huge over the last, let's say three years.
Yeah. Three, four years. Open Telemetry is, I think the second or third largest is the second, second largest.
Very, very close to Kubernetes. Yeah. It's, uh, Speaks for itself.
Uh, let's talk about Splunk, the observability company. Yeah. Well, and open source.
Okay. So, um, let's talk about Open Telemetry in that case. Go ahead.
Uh, because we, we really a strong build. I mean, we believe that Open Telemetry is basically the future of telemetry, right? And as you said, uh, it's becoming the second largest project, so it's no brainer.
It's becoming the defacto way of collecting telemetry data. Everybody's contributing. So we, everybody has kind of the same, you know, importance I would say there.
But at Splunk we strongly believe that it's the, the way to go for observability. So our strategy has been to fully invest in open telemetry. So we contributed as much as we can.
So we started contributing of course on the log part because we known for that. But very quickly, then we moved into, uh, helping with, uh, instrumenting languages, right? So we worked a lot on, uh, no GS and net adoption in Open Telemetry.
Now we're working on Go as well. And in the latest news, what we just released, in fact we announced it today. Uh, so, uh, maybe we'll be the first ones to broke as that.
Well, we should define what today is 'cause we're not live. Oh, Okay. So it's Being recorded.
April. April. So today it's right Wednesday, April 2nd, you guys.
Exactly. So we just announced, uh, the new version of, um, our own distribution of, uh, open Telemetry. And what we are announcing is a service inventory.
And basically what it does, uh, the idea is to how can we automatically instrument the customer environments? How we, we can automatically discover, uh, uh, MongoDB or Oracle or Kafka and automatically make, um, instrumented and get all the telemetry data without having to configure anything, you know, doing all the ya stuff that people is doing with, uh, open telemetry. So our job is to really improve the auto instrumentation because we're coming from the enterprise business, right?
So we are addressing mainly big companies, not only, but mainly big companies that really love Open Telemetry. But sometimes it requires a little bit some work, you know, to configure it, install it, deploy it. And this is where we really want to have.
So we contributed. So we have own distribution, which is open source still, but always we try to, once it's deployed on our distribution to give it back to the community. But it is just a question of when you give it to the mainstream, there is feedback, there's a process to follow.
So we just, you know, bring that value to our customers first and then give it to the community once the community is ready to get it in the mainstream, basically. Love it. And how active is Splunk in the open telemetry?
Uh, like managing, maintaining, contributing From, from, from the initial, right. I mean, uh, one of the, you know, open Telemetry is merging two different projects and one of them was managed by Morgan Lin, for instance, which is now part of, uh, Splunk as, uh, director of product management. So it's, it's having the right people and the right brains, uh, but's also the developers.
So we have a team only dedicated on that, only on Open telemetry in Raco in Europe, in fact, that day in day out, uh, code around open telemetry, but also provide support because we provide support to our customers on open telemetry as well. So, I mean, we are open telemetry native and it's a strong statement, which mean that we'll never ask for observability purposes to install any proprietary agents. Never.
It's all relying on open telemetry. I love it. Alright.
You mentioned one announcement here today. Yep. Any other news coming out of, uh, Splunk and Observability here at CubeCon?
Uh, speak. I mean, that's the main one because Yeah, that's big. It's, it's related to Cube Krn, right?
Sure. And, uh, the CNCF, uh, outside that we keep doing the integration with Cisco, as you mentioned, we have been acquired by Cisco. Um, even if, uh, the observability part of Cisco is not part of Splunk, it's like a reverse acquisi good now, Uh, AppDynamics, which is now a dynamics.
Yep. But we keep working with, uh, the other part of Cisco with Thousand Ice, which also support Open Telemetry and others to, uh, really help getting this observability view not only to any customers, but also inside the Cisco environment really to provide more value to Cisco customers as well. So there's a lot of, uh, things coming on this area as well.
Absolutely. Let's go back to the announcement. Yes.
So you are contributing this functionality that you announced Yeah. Will be part of Open Telemetry or that's only Splunk? So for the moment it's only Splunk, but then we're pushing it into, uh, the community.
Uh, if you look back, for instance, we have been actively working on profiling, uh, so, and we give it back to the, to the community. We always, all the developments, because again, we can code the way we want. We code as fast as we can to provide value to customers on top of open telemetry with our own distribution, which is open source as well.
But we always then provide, give it back to the CNCF and to the community. And that requires more time because then you discuss, you get feedback to make sure that it becomes a mainstream. And then we, we use the mainstream one.
We abandon the feature we develop to the customers to provide it and use the mainstream one. 'cause what we want is the customers to not be logged in with Splunk, right? It's how can we provide features that they can find in proprietary agents, right?
But with open source and keep the open source mindset for telemetry data and not be logged in with vendors because we, it's an interest for absurdity, but as you mentioned, we also a cyber security company and we know that the security teams love open temperature because they know what it does. They can see the code. And Plus all the things you can do with open teary, anonymized data, feed to date and all these kind of things.
And as a key player in both areas, we want to protect that because I mean, if you do good as a backend right, there's no reason why people will leave, but they need to have the freedom to leave. Yeah. So that's, that's Thing.
Well everybody is anti-lock. Yeah. Though sometimes they talk about anti-lock and then they, without realizing it, they're locked it, you know.
Exactly. Well, yeah. So that's why, again, that's why I mentioned that and I keep hammering on that.
We are open tele chain native. Again, never ask for observability to install anything proprietary on the customer side. Right.
Get that freedom. Excellent. Um, for people at home who want to stay current on what Splunk is doing with open telemetry, with observability, where should they, like should they go to Splunk or go to you think stay with the project or both?
I mean, usually, I mean it's, it's, it depends on what do you need. I mean, you can stay with the project and still a Splunk observative will work without any problem, but you will still, like, if you use any other solution, you will have to do some configuration work. Right.
If you want to avoid that and use all the auto instrumentation, service discovery, and so inventory and so on, you can use own distribution and then when this comes back to the mainstream, you will have it and you're still, you know, free to move out if you want to. That's the idea. It's getting the best of both worlds as much as Possible.
Morning Arctic. Excellent. Uh, how would you, I know it's only the first day of this.
Yeah, well it's already crowded. I mean, for The first, yeah. Well no, they're gonna have over 12,000 people.
About a hundred more than we're in Paris actually. Uh, yeah. Well, So it'll be, you know, there's the largest European, I think it's the largest one.
It keeps getting bigger. Next year is Amsterdam. Yeah.
In the year after that. Barcelona. Oh, they already planned for the, usually they give, I don't know if it's official.
So you have Insights. So you have some insights. I know someone who knows so far.
Okay. Uh, but anyway, you know, it, it is growing bigger. How do you see Splunk's role in this Growing over the, What, what do you mean future?
So Will, will Splunk be more active in Open Telemetry or in maybe some of the other projects? I mean, I don't know how we can be more You already, Because I mean we, we contribute as much as we can. We have dedicated teams, uh, to that.
One of the co-founders is with us. Um, we, we even working for in the future, so we're working on, uh, auto instruments, uh, compiled languages like, uh, c plus plus like, uh, go and things like that. I mean, we full steam on that.
Uh, we have hundreds of developers dedicated to that. You can even visit them on the open telemetry, uh, booth. So you will find some guys there that in fact are Splunk Are sp sprinklers.
But that's, that's the point. That's how you support. Yeah.
Yeah. I mean, and we supporting it and so on officially and things like that. Uh, so I dunno what, what else we can do.
Right. Well, We'll find out. Anyway, thank you for coming by and thank you for visiting with us here.
Excellent, Stefan. Thank you. Best of luck.
Thank you very much. Stefan Esteve here at uh, CubeCon. It's lunchtime.
We'll probably take a little break here, but we'll have a lot more coming at you. Go check out Open Telemetry and what Splunk is doing. Actually check out the announcement.
Stefan was, uh, referring to it. Interesting stuff. We're here at CubeCon.
We'll be back.