Listing Thumbnail

    Splunk Cloud

     Info
    Sold by: Splunk 
    Deployed on AWS
    If you are looking for security and operational visibility across your AWS environment including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more then Splunk Cloud is the right solution for you.
    4.1

    Overview

    If you're looking for security and operational visibility across your AWS environment - including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more - then Splunk Cloud is the right solution for you. Organizations of all sizes leverage Splunk visibility with AWS agility to rapidly troubleshoot applications, ensure security and compliance, and monitor business-critical services in real-time. Splunk Cloud makes it easy to gain end-to-end visibility across your AWS and hybrid environment. Leverage Splunk Cloud with the free Splunk App for AWS to gain critical security, operational and cost optimization insight into your AWS deployment. Whether you're managing applications, infrastructure or a security operations center in the cloud, Splunk delivers Operational Intelligence for a real-time understanding of what's happening across your business and IT so you can make informed decisions. It's easy to get started - and remember - when choosing a product option, match your location and anticipated index volume per day. Splunk Cloud is now FedRAMP authorized: Moderate

    Highlights

    • Collect and index any machine-generated data from virtually any source or location in real time. Just point Splunk Cloud at your data, and it immediately starts collecting and indexing so you can start searching and analyzing.
    • Splunk Cloud offers single-pane-of-glass visibility across on-premise Splunk Enterprise and Splunk Cloud deployments, enabling customers to deploy Splunk as software or SaaS according to their business requirements, while maintaining centralized visibility.
    • Splunk Cloud includes support for Splunk apps and other content. Splunk apps deliver a targeted user experience for different roles, use cases and enterprise technologies. These apps can help you visualize data in new ways or provide pre-defined views of leading technologies such as Linux, Windows, VMware and more.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (20)

     Info
    Dimension
    Description
    Cost/12 months
    US - 5GB/Day
    Index Volume
    $8,100.00/GB
    US - 10GB/Day
    Index Volume
    $13,800.00/GB
    US - 20GB/Day
    Index Volume
    $24,000.00/GB
    US - 50GB/Day
    Index Volume
    $50,000.00/GB
    US - 100GB/Day
    Index Volume
    $80,000.00/GB
    EMEA - 5GB/Day
    Index Volume
    $9,315.00/GB
    EMEA - 10GB/Day
    Index Volume
    $15,870.00/GB
    EMEA - 20GB/Day
    Index Volume
    $27,600.00/GB
    EMEA - 50GB/Day
    Index Volume
    $57,500.00/GB
    EMEA - 100GB/Day
    Index Volume
    $92,000.00/GB

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Splunk offers a variety of support options to help ensure your success.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Data Anonymization, Data Security and Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    7 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Real-time Data Collection and Indexing
    Collects and indexes machine-generated data from virtually any source or location in real time with immediate search and analysis capabilities.
    Multi-deployment Visibility
    Provides single-pane-of-glass visibility across on-premise and cloud deployments, enabling centralized monitoring across hybrid environments.
    AWS Service Integration
    Supports integration with AWS services including CloudTrail, Config, and VPC Flow Logs for comprehensive AWS environment monitoring.
    Pre-built Application Support
    Includes support for Splunk apps with pre-defined views for leading technologies such as Linux, Windows, and VMware.
    FedRAMP Authorization
    Maintains FedRAMP Moderate authorization for compliance with federal security standards.
    Real-time Data Collection and Indexing
    Collects and indexes machine-generated data from virtually any source or location in real time with automatic indexing upon data ingestion.
    Complex Event Correlation
    Correlates complex events spanning multiple diverse data sources using time-based correlations, transaction-based correlations, sub-searches, lookups, and joins.
    Scalable Data Processing
    Scales to collect and index tens of terabytes of data per day with distributed computing architecture.
    High Availability Clustering
    Provides clustering technology for availability and fault tolerance across distributed computing environments.
    Machine Data Search and Analysis
    Enables searching, analyzing, and visualization of machine data generated by IT systems and technology infrastructure across physical, virtual, and cloud environments.
    Data Routing and Destination Management
    Routes data to multiple destinations with capability to deliver specific data to targeted tools while archiving full fidelity data to cost-effective storage
    Data Optimization and Reduction
    Reduces data streams by up to 50% through removal of unused log and metric data
    Event Processing and Transformation
    Processes event data through centralized parsing with capabilities to route, optimize, reformat, and enrich data in flight
    Role-Based Access Control
    Implements role-based access control with support for external authentication via LDAP, Splunk, and OpenID Connect identity providers
    Real-Time Monitoring and Configuration
    Provides GUI-based configuration and testing interface with live data capture and real-time observability pipeline monitoring

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.1
    62 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    39%
    58%
    3%
    0%
    0%
    28 AWS reviews
    |
    34 external reviews
    External reviews are from PeerSpot .
    Aakash LS

    Log monitoring has become faster and root cause analysis improves production issue resolution

    Reviewed on Apr 03, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have experience with Splunk Cloud Platform . We use it for log monitoring, debugging, and various other purposes.

    Since I joined as a software developer, I have been working with Splunk Cloud Platform  for around two years. It is the main tool we use during production issues. We monitor it not only in production issues, but also when we move code to UAT, QA, or XPT environments. We first monitor and check Splunk logs to ensure everything is functioning correctly and to identify what is going wrong.

    Splunk Cloud Platform helps in analyzing logs from different services, not just one service, and identifying errors. Especially during production issues, it is our primary platform for understanding where everything goes wrong and determining the root cause. The main feature I appreciate is the Search and Processing Language, which we call SPL. It allows us to query and filter logs efficiently. We can filter by time, whether for a few minutes or hours, and we can filter by various other parameters, such as which user has made the most requests, user-wise breakdowns, specific error patterns, exceptions, or failures. We can use time-based filtering and keyword searches to narrow down on the relevant logs we wish to see at any particular point in time.

    I use the alerting mechanisms present in Splunk Cloud Platform. Without Splunk, we would have to manually go to production logs and search for various things manually, which could be very time-consuming. When we use Splunk, these mechanisms are automated. We only need to change the query sometimes because we search for different mnemonics and different teams. If we adjust the region or the team and then provide the particular keyword we are searching for, this helps us change the logs and see what we really need.

    What is most valuable?

    Splunk Cloud Platform helps in analyzing logs from different services, not just one service, and identifying errors. Especially during production issues, it is our primary platform for understanding where everything goes wrong and determining the root cause. The main feature I appreciate is the Search and Processing Language, which we call SPL. It allows us to query and filter logs efficiently. We can filter by time, whether for a few minutes or hours, and we can filter by various other parameters, such as which user has made the most requests, user-wise breakdowns, specific error patterns, exceptions, or failures. We can use time-based filtering and keyword searches to narrow down on the relevant logs we wish to see at any particular point in time.

    I use the alerting mechanisms present in Splunk Cloud Platform. Without Splunk, we would have to manually go to production logs and search for various things manually, which could be very time-consuming. When we use Splunk, these mechanisms are automated. We only need to change the query sometimes because we search for different mnemonics and different teams. If we adjust the region or the team and then provide the particular keyword we are searching for, this helps us change the logs and see what we really need.

    One unique feature with Splunk Cloud Platform is that it can be used not only for log creation but also for creating dashboards. I have created one dashboard myself for visually representing data. This dashboard checks various clients and services to see how many hits we have seen. I made it as a pie chart, and when we click on one of those sections, we are able to see how many hits that service has received. For that particular service, we can check how many users have contributed to that hit. When we send that visualization to higher management, they make decisions based on what service to focus more on. The decisions matter and vary according to management priorities.

    What needs improvement?

    The Search Processing Language of Splunk Cloud Platform has a steep learning curve. To extract the correct amount of logs needed, you must understand the exact mnemonics. Writing efficient SPL queries requires time to become accustomed to the language. Only after you have a good grasp of the basics of Splunk Cloud Platform and understand how to trace logs will you be able to use it perfectly.

    Handling a large volume of logs requires proper filtering strategies. Logs keep coming in very large quantities, but you need to know how to properly filter them. Proper filtering strategies must be understood and implemented.

    The setup and configuration for Splunk Cloud Platform is complex, especially from a developer perspective. Although it was relatively easy for me, the setup and configuration were handled by the platform team, which had to deal with the complexity in the initial phases.

    The initial onboarding process when I first started using Splunk Cloud Platform was not very complex. When Splunk was initially onboarded to the company, I understand that was a complex process. Since I joined, the process has been fairly simple. We just had to submit an access request for a particular mnemonic or for a particular team and we are able to check the logs for that mnemonic once we get access. The approval process is a bit tedious in our organization. We have an approval process for every tool, not only Splunk Cloud Platform. Once you receive approval, you should be good. However, we can only check for that particular team or mnemonic. If we wish to check for other services, we have to submit a request form again, and that goes through several layers of approvals before we are able to see the logs.

    Splunk Cloud Platform does not require any maintenance on my end as a developer. We only use it for checking logs. Maintenance is handled by the platform team. Sometimes Splunk experiences downtime for a few minutes, which we are notified about via email, sometimes during weekends. I am not certain what happens during those phases, but as developers, we are unable to use it for that short period of time, sometimes around half an hour during midnight hours on weekends. Otherwise, it functions well.

    For how long have I used the solution?

    I have been using this solution for two years.

    What do I think about the stability of the solution?

    Splunk Cloud Platform has fairly good stability. However, I have noticed that the Show Source feature, which displays detailed versions of logs, sometimes takes a little time. Whenever the system needs to show 100 lines or 1,000 lines, that takes some time usually. When a large number of logs sometimes enter the system, we sometimes see lag. Especially during the Show Source function, when checking the detailed logs of any particular log, I have seen this issue sometimes. Otherwise, everything is fine.

    What do I think about the scalability of the solution?

    Splunk Cloud Platform is quite scalable. All services and event-based streaming, such as Kafka, have all logs flowing through Splunk Cloud Platform. We have seen that it handles this well and is great at scaling to meet our needs.

    How are customer service and support?

    I have not contacted the technical support of Splunk Cloud Platform yet. Even when we are unable to get something resolved, we have our seniors and experts in our team and adjacent teams who help us understand where we are going wrong with the queries and other issues. I have not personally contacted the technical support yet.

    How was the initial setup?

    The initial onboarding process when I first started using Splunk Cloud Platform was not very complex. When Splunk was initially onboarded to the company, I understand that was a complex process. Since I joined, the process has been fairly simple. We just had to submit an access request for a particular mnemonic or for a particular team and we are able to check the logs for that mnemonic once we get access. The approval process is a bit tedious in our organization. We have an approval process for every tool, not only Splunk Cloud Platform. Once you receive approval, you should be good. However, we can only check for that particular team or mnemonic. If we wish to check for other services, we have to submit a request form again, and that goes through several layers of approvals before we are able to see the logs.

    Which other solutions did I evaluate?

    I have not used any alternatives to Splunk Cloud Platform since I joined my organization. We have been using Splunk only for observability and tracking and monitoring. So far there are no other alternatives that we have tried out in our organization.

    What other advice do I have?

    From a developer perspective, I am involved in coding, checking logs, monitoring, observability, and other related tasks. The platform team takes care of the setup and configurations, which is complex initially. The pricing aspect is handled by management and not something I am directly involved in. I would rate this product a 9 out of 10.

    Kalpesh Pawar

    Centralized security monitoring has improved threat detection and automated incident response

    Reviewed on Apr 02, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Splunk Cloud Platform  serves as our main use case for centralized security telemetry injection across customer environments with tenant-level index segregation. We also use it for SPL-based correlation plus detection rules, powering our SOC use cases and threat detection workflows. We have integrated it with SOAR  and ITSM  for automated incident response and lifecycle management.

    In one of our customer environments, we detect brute force login attempts using SPL correlation for failed login spikes plus source IP anomaly. The alert triggers a SOAR  playbook to block the IP on the firewall and create ITSM  tickets with context. This reduces response time significantly and prevents account compromise at an early stage.

    We also use Splunk Cloud Platform  for threat hunting and MITRE ATT&CK mapping, leveraging SPL and ES dashboards across customer environments.

    What is most valuable?

    The best features Splunk Cloud Platform offers for us include Search Processing Language plus the flow relation engine, which enables deep multi-source analysis and real-time threat detection across cloud environments. The real-time monitoring plus alerting automation helps us with continuous KPI tracking with custom alerts and automated actions, improving incident response in our SOC operations.

    Splunk Cloud Platform has positively impacted our organization by achieving 42 to 45% faster detection, threat detection, and response using real-time correlation and automation. We have also improved SOC efficiency with centralized visibility across all customer environments and reduced tools sprawl by consolidating multiple security or monitoring tools into a single platform.

    What needs improvement?

    There are not many things that need to be improved, but Splunk Cloud Platform should have improved multi-tenant role-based access control with granularity to simplify access control across our customers. It also needs faster search performance for large datasets to speed up deep threat investigations.

    We would like more native integrations with cloud and security tools to reduce custom connectors in customer environments. The user interface can be improved as it gives an old-school feeling while using it and can be made more intuitive.

    For how long have I used the solution?

    I have been using Splunk Cloud Platform for three years.

    How are customer service and support?

    As we have the premium plans, the customer support offering is via ticketing system, phone support, and email support on an SLA basis. For critical issues, customer support is strong and very responsive. The 24 by 7 monitoring plus NOC support helps us detect and resolve platform issues proactively in cloud environments. Overall, the support team and technical support engineers are knowledgeable and understand the customer environment very well. The support is very good, and the documentation provided on Splunk Cloud Platform is very helpful.

    What other advice do I have?

    I would like to highlight the main feature that helps our team, which is role-based access control plus index-level segregation, ensuring secure tenant operations in our SOC model.

    Earlier, our analysts manually correlated logs across tools. Now, SPL correlation for ES dashboards provides a unified view, reducing the normal triage time. The auto alerting plus SOAR integration eliminates manual ticket creation and initial investigation steps, streamlining workflow and improving analyst productivity while significantly reducing time per incident.

    Splunk Cloud Platform supports integration with other security tools and platforms in our environment by using native integrations like Syslog APIs to inject data from firewalls, EDR, cloud, and identity platforms. The SOAR and ITSM integrations via webhooks and APIs enable automated incident response and ticketing workflows. It also supports bidirectional integration for enrichment and action, such as blocking IPs and updating cases.

    Splunk Cloud Platform helps with compliance or regulatory requirements in our organization by using centralized log retention plus audit trails to meet compliance requirements. For example, we track user activity and access logs across customer environments. We also have pre-built ES correlation searches and reports mapped to standards like ISO, PCI DSS, helping in audit readiness. The role-based access plus data segregation ensures compliance with multi-tenant security and governance policy, not only for our customers but for our internal organization as well.

    As a SaaS, Splunk Cloud Platform enables scalability by handling growing log volume through auto-scaling indexing as we onboard new customers without making infrastructure changes. The index-level segregation plus role-based access control allows us to easily expand to multi-tenant customers while maintaining data isolation for all customers. Additionally, it supports distributed search and concurrent queries, ensuring performance for SOC operations at scale.

    We manage cost and budgeting for Splunk Cloud Platform as our usage grows by using injection filtering plus cloud tiering to reduce unnecessary data and control license use, which our team handles very well. We also implement index lifecycle policies like the retention of logs and cloud storage to optimize storage costs across multiple customers. The main challenge is injection-based pricing at scale, so we continuously monitor usage and optimize high-volume sources.

    Splunk Cloud Platform helps our team with threat intelligence or sharing across customer environments by allowing us to inject threat intel feeds into Splunk Cloud Platform and correlate them with customer logs using SPL. The shared IoC enrichment plus ES correlation searches enable us to reuse detection across multiple tenants while supporting centralized intel management with controlled sharing, thus improving detection and consistency across all customer environments.

    I recommend that designing data onboarding, index strategy, and role-based access control should be upfront for a scalable multi-tenant architecture. I suggest customers go for this product as you can optimize injection, filtering, normalization, and retention early to control cost as data grows. I also suggest bargaining on prices, as I have seen salespeople negotiate, and you can get the best deal out of that. I would rate this product an 8 overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Hemanthreddy Vakiti

    Centralized logs have transformed payment issue troubleshooting and now streamline incident resolution

    Reviewed on Apr 02, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use Splunk Cloud Platform  to check logs. As a product developer, whenever I try to make a transaction to see whether it has proceeded smoothly, we check the logs. In logs, we can see from the payload how the message gets generated, which is very useful for us.

    I work as a product developer for Guidewire, an insurance tool, where we mostly face payment-related issues. It follows a check lifecycle where it starts from awaiting submission, requesting, requested, issued, cleared, pending stop, stopped, and everything. We have various check lifecycles. Suppose if a lifecycle is missed and the user is trying to proceed with a transaction starting from awaiting submission and moving directly to issued instead of requesting to issued, we face an illegal state change exception. Without Splunk Cloud Platform  logs, we wouldn't know what type of exception we are facing. We help the user after checking the logs as well.

    Recently we faced an issue where we use another software called One-Ink, where most of our process checks get updated to our database. From there, they were doing IP whitelisting where most of the payment-related features were done. IP whitelisting means giving out an IP address only for certain individuals where they can do payment-related changes. When they were doing that, they missed two or three of the IP addresses that were needed to be processed, and we had a global outage for check-related issues. We checked logs to know whether the issue was or how the issue got generated. We had to create a new payload and check it from Splunk Cloud Platform to see whether the payload got generated and the affected claims were resolved.

    Generally, when we face a certain issue, if a check-related transaction will have a public ID generated, for that public ID, we don't have it in the UI. We have to query the database to get the public ID. Public IDs are primary keys and using those primary keys as a substitute, you have to search through our logs.

    What is most valuable?

    Logs can ask which type of log you need to give it, such as a claims pay logger or a state change logger or any other logger as a filter. Then you need to give that public ID and it would give you all the fields that were changed in that specific criteria that you were searching.

    For me, with Splunk Cloud Platform, if you don't give the necessary filtration values, it has its own querying type. If you do not give a proper query or anything for the log to be generated on a primary key, it won't give you the values. It takes too much time and it checks a large number of values. Sometimes it goes more than a million, so that takes a lot of time. However, if you use proper filtration, it takes much less time. It saves our time and we could also pause the values, we could pause the search fields, we could resume the certain fields, we could skip a few fields, and we could check right from the payload whether which messages were generated and how the transaction was proceeded.

    What needs improvement?

    Splunk Cloud Platform holds only three months' worth of data. If you try to search for more than three months or prior to three months, it wouldn't store the values because the data stores a large number of data. I believe that's the limit for us. I believe having flexible memory would ease us because whenever we face an incident, if we want to look for this occurrence or root cause, if it is prior to three months, we wouldn't have proper logs to check.

    I wish it would take a little less time and not search through unnecessary things. Of course, querying depends on the developer's knowledge, but storage is also an issue because I feel memory is not flexible enough. If we try to increase our memory, it will charge us a considerable amount of money.

    For how long have I used the solution?

    I have been using Splunk Cloud Platform for around one year and three months.

    What do I think about the stability of the solution?

    We face occasional downtime issues where when we try to scale up, we face a considerable amount of challenges. If we consider one month, we would face around two to three days of downtime issues.

    What do I think about the scalability of the solution?

    Scalability is a little issue for us because it's not currently adapting to our rightful needs. I believe they should upgrade on their side to match our tempo.

    How are customer service and support?

    I never really reached the customer support, but they provide proper documentation, so all that was required. Mostly our support team takes care of any needs that were needed by us.

    Which solution did I use previously and why did I switch?

    I did not use any solution prior to this because in this project, this was the tool that was working when I started.

    How was the initial setup?

    We picked this tool because it was on top of a line in the market and it suited our specific criteria. We are developers, so it suited and matched our tempo.

    What was our ROI?

    I would say initially, to read Splunk Cloud Platform logs, it would prove very difficult because it is definitely not beginner-friendly. It will take around 15 days to one month to just adapt to what is a log and where you need to find the error because a payload and every logger is a complex form where line by line it will be written, but what that line is, they won't show that. It is definitely not a beginner-friendly tool, but it is definitely the best tool that is available in the market for insurance-related products.

    What's my experience with pricing, setup cost, and licensing?

    Related to the pricing factor, I think it is slightly on the costlier side, but I wouldn't know much because I'm not on the management side. My organization divides developers and management, so we wouldn't know the price for it.

    What other advice do I have?

    Generally, at our morning call, we go through our incident team-wise and assign incidents based on what we can do. Before we can do that, we check whether this is doable or not. We go through the logs and find if any check-related issues or claim-related issues that we face. We go through the logs and first check where the problem is because most of the problems that we faced were related to permission issues, where the user might not have permission and tries to make a few changes when that person doesn't have permission. They face a few errors or issues and cannot log in through certain sites or anything. Splunk Cloud Platform helps us reduce the time and effort through checking the logs. If we didn't have this, we would have checked the history loggers, where it checks and tracks even the person who viewed that particular claim. It would take a considerable amount of time.

    Initially, we were a team of 300 people where our project started with three different teams. Before having this, prior to Splunk Cloud Platform logs, we used to depend mostly on the history loggers where it tracks our history or movement. Any small changes would be tracked down there, but we wouldn't have any sort of search criteria where we cannot search. We would have to manually go through step by step, one column after another, to see who has done what changes. That would prove an issue. After Splunk Cloud Platform was introduced to us, we saved a considerable amount of time. Time is a major factor for us developers.

    Our team started off with 300, and now we are 30 people. We saved a considerable amount of money and resources that are required to hire more people. We started off with a team of more than 300 people and require less than 30 people right now. I think it's over a five year duration where we came to this number, but I think fewer employees are needed because of this, and we spend little effort because logs track everything. It helps us in our day-to-day task.

    Storage is the major issue that we face occasionally because whenever we are trying to solve a root cause issue that is a PRB, we would require a lot of history loggers which would not be available for us. The second issue would be that it is not that scalable. I don't think increasing our storage would cost us a less amount, but it would cost us more. I would rate this product an 8 out of 10.

    Dipesh-Bhawsar

    User behavior insights have improved threat detection but complex setup still needs refinement

    Reviewed on Mar 31, 2026
    Review from a verified AWS customer

    What is our primary use case?

    We have an internal solution and we are working for our own enterprise solution. I'm working in Principal Financial Group where we have our in-house security operations center, so we do not have any clients; we are conducting our security monitoring for our own infrastructure.

    Our major focus is on User Behavior Analytics , UBA . We are focusing on integration of all security controls that we have, meaning the log collection from all the security controls and all the servers. The use cases we are focusing on are MITRE framework, phishing, and User Behavior Analytics, UBA.

    What is most valuable?

    UBA is a great application within Splunk Cloud Platform .

    That feature gives us behavioral analytics within the logs, so we do not need to write complex queries. By using UBA, we achieve threat detection without needing complex correlation rules; UBA gives us a perfect output from it.

    The log ingestion is very good, and the visualization part is also very good. I can create multiple dashboards from the logs we are receiving; it is similar to other SIEM  solutions.

    What needs improvement?

    Splunk Cloud Platform  is good, but sometimes it lags. When I run a very simple query with a perfectly created query in the search bar, it gives a good result, but if I create a very simple query without index and source types, it takes too much time to draw the visuals.

    It is somewhat complex because Splunk Cloud Platform has multiple components like heavy forwarders and indexers. There are multiple integration approaches that we use, for example, syslog and for Windows, it is WMI. For most of the applications, we are using API integration, which is very good, but for syslog and other WMI kind of configurations, first, I need to integrate them so they start sending logs to the heavy forwarders. On heavy forwarders, I have to configure syslog-ng , and there are multiple configuration files that I have to configure for each data source.

    The improvement part is that I have worked on multiple SIEM  solutions, starting with RSA NetWitness, QRadar, ArcSight, and Splunk Cloud Platform. All SIEM solutions have the same issues; at the time of POC, the vendors tell us that they have many features, but at the time of implementation, we find minor issues everywhere, from integration to querying logs and deploying configuration files. There are minor issues that need fixing for more operational efficiency.

    For how long have I used the solution?

    I have been working with Splunk Cloud Platform for around one and a half years.

    What do I think about the stability of the solution?

    Splunk Cloud Platform is stable and reliable with no issues, though sometimes minor issues happen; it is not as though the system goes down or anything.

    What do I think about the scalability of the solution?

    The more I scale, the more I have to pay for Splunk Cloud Platform. I have to properly fine-tune the logs, filtering them for what I want to take into Splunk Cloud Platform for security monitoring. Only the logs required for security monitoring should be taken into Splunk Cloud Platform; if we have compliance requirements to just store logs, then Splunk Cloud Platform is not the right platform.

    How are customer service and support?

    I am not that happy, but they provide timely responses. They are available at the time of need; however, there are a few things like issues with log parsing that they will not cover in normal support calls. I needed to create an ODS, On-Demand Service, for those kinds of issues.

    Which other solutions did I evaluate?

    Pricing is too high for Splunk Cloud Platform. Nowadays, people are using Cribl  solution that we host just before Splunk Cloud Platform. From a heavy forwarder, logs go to Cribl , and there is a filter mechanism available in Cribl, so we can only send the events of interest to Splunk Cloud Platform, which reduces our pricing heavily. Otherwise, when collecting logs from devices such as Linux, Windows, and firewalls, we get debug logs as well, and Splunk Cloud Platform charges based on the ingestion—how much data we ingested into Splunk Cloud Platform.

    What other advice do I have?

    We are currently working with Splunk Cloud Platform only. We are exploring machine learning tools, but they are not deployed yet, so there is currently a POC going on.

    Splunk Cloud Platform does what it has to do but nothing extraordinary; it is a simple dashboard application like other SIEM solutions.

    There are multiple support cases because we have a very large architecture of Splunk Cloud Platform. We have eight heavy forwarders and thousands of log sources integrated with Splunk Cloud Platform, so from time to time, I observe issues related to integration, applications, and the internal workings of Splunk Cloud Platform. Thus, we need to raise support cases to troubleshoot those.

    Overall, I would rate this review a 7 out of 10.

    Jigar Hirani

    Cloud analytics has improved security insights and simplifies proactive performance monitoring

    Reviewed on Mar 27, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I use Splunk Cloud Platform  as our overall tool to gain insight from our platform, for our security use cases, and to build a framework that shows what is happening in our organization or what is happening in our applications, the current status, or if we are facing any issues with our systems. I ingest various types of logs from different systems to Splunk Cloud from our forwarders and build dashboards and alerts on top of that. My primary use case is to understand our architecture or our overall environment, including what is happening and whether there are any vulnerabilities, or to conduct analysis on our applications. If there are any performance issues, I can learn about them from the dashboards that we have built and can optimize our architecture or overall application performance.

    What is most valuable?

    What I like about Splunk Cloud Platform  is that it gives me flexibility and freedom in that I do not need to worry about the actual architecture of Splunk. I do not need to install it anywhere manually, and I only need to worry about what data I need to ingest and how I will create a dashboard on top of that. It provides support so I do not need to worry about the platform. It functions as Software as a Service, so I can directly use it and if I am facing any issue, Splunk support is available to help me anytime.

    I do not have any limitations with Splunk Cloud Platform. I can access it from my own private network or anywhere, and I can access it from the public network as it is on a cloud. That is also a plus point for me.

    In terms of assessing the effectiveness of Splunk Cloud Platform's search capabilities in uncovering operational insights, its storage capability is excellent. Previously, we were managing it at an enterprise level, but it was costly to us because of data redundancy and the availability zones. With Splunk Cloud Platform, we do not need to worry about data backup, which is a very good point.

    The alerts have helped us in proactive issue resolution. If we are currently getting any error, we will get notified in the next 15 minutes or 30 minutes according to the schedule of the search.

    Splunk Cloud Platform's ingest and visualization features have helped improve our data reporting, truly the best available in terms of customizability. We have two options, classic and Dashboard Studio for dashboard purposes. In classic, we get options to build custom dashboards using custom JavaScript. We can insert our own graphics to provide better visuals where insights to our management team will not be dependent on the numerical base. We have charts to showcase our current situation, which will be really great for management.

    In terms of benefits, if we were needing two persons for SAP to analyze if we have any issues, now we just need one person doing multiple tasks. We have built an automation system, or a dashboard, which gives us insight so that we do not need to go and look up every service. Splunk Cloud Platform really impacted our workflow and increased our productivity.

    What needs improvement?

    In Splunk Cloud Platform particularly, there is nothing specific that I would like to see improved or enhanced, but the cost is currently very high. If that part could get a little bit cheaper, then that would be really great.

    In terms of enhancement for Splunk Cloud Platform, I would say if we could create add-ons or if we get the capability to build add-ons directly through cloud, not talking about the add-on builder framework, but something editor-like where we will directly edit our conf files from any specific app or TA provided by Splunk Cloud Platform itself. If we get that feature, it will be really beneficial. Instead of doing configuration from the UI, we would prefer to get access to back-end conf files and do it manually because when we were using enterprise, we had pretty much hands-on experience with that.

    For how long have I used the solution?

    I have been using Splunk Cloud Platform for around two years.

    How are customer service and support?

    I would evaluate customer service and technical support of Splunk as really good. They provide on-call support and they reply to cases that we open, so the support is really good and collaborative.

    Which solution did I use previously and why did I switch?

    We have not previously used a different product. We have tried other tools, but they were very limited to the use cases that we are trying to capture. I chose to go with Splunk Cloud Platform because it has vast capabilities.

    How was the initial setup?

    The initial setup with Splunk Cloud Platform was really straightforward because, as it is a cloud platform, Splunk provided us the complete package where we do not need to worry about our infrastructure or configuration. If we need any help, they are always available, so it was very straightforward.

    What about the implementation team?

    The implementation was done by the Splunk team.

    Which other solutions did I evaluate?

    We evaluated products like Dynatrace  or DataDog, which were very specific. They were providing us only observability-specific tasks. However, we have some VML logs or firewall logs for which we would not get that much analysis from those products. That is why we chose to go with Splunk Cloud Platform.

    What other advice do I have?

    We use Splunk default alert actions and we have installed third-party integrations, such as ServiceNow  integration, where we are creating ServiceNow  incidents or ServiceNow tickets from our alerts.

    The impact of Splunk Cloud Platform's integrations with third-party tools on our daily operations is very helpful for our overall infrastructure monitoring. We have third-party integrations, such as SAP or Dell Boomi . To ensure that our SAP and site integration are running smoothly and none of its API is getting high or something unusual, we can easily detect that instead of going into SAP and analyzing.

    We have our own machine learning logic where we are creating alerts based on our machine learning algorithm. If we are missing any data from the forwarders, then we have a built-in threshold mechanism where if the data from the last seven days is coming around 80 GB, then the next day it should be getting related to that. If we are not getting that, then we will get alerts. I have not particularly used Splunk ML Toolkit.

    From the features perspective, I would say if we were getting calls from back two or three months, I was waiting for the Otel feature in Splunk Cloud Platform. Now we have support of Otel in the current latest Splunk version, so we are planning to upgrade Splunk Cloud Platform to the latest. The feature that I was looking for is now currently available, so I do not have anything specific at the moment.

    In terms of pricing, the cost is high, but we are getting pretty much value out of what we are paying and what should be available to us in the market. In terms of that, it is really good with no question on that.

    My advice to other organizations considering Splunk Cloud Platform is to make sure you use it as much as you can. There is a really big community of Splunk that you can explore to see what data you can ingest. There is a possibility you are already using other services from which you can get logs into Splunk and build analysis on top of that. Do not limit yourself to any specific use cases. I have seen some organizations only ingest specific logs, such as firewall logs or DNS logs. But they have different types of machines and applications running for their infrastructure. They can ingest logs from those as well and build analysis on top of that. There are pre-built add-ons that provide that functionality to them and they do not need to worry about development. So use it as extensively as possible. Overall, I would rate this product a nine out of ten.

    View all reviews