Listing Thumbnail

    Splunk Cloud

     Info
    Sold by: Splunk 
    Deployed on AWS
    If you are looking for security and operational visibility across your AWS environment including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more then Splunk Cloud is the right solution for you.
    4.2

    Overview

    If you're looking for security and operational visibility across your AWS environment - including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more - then Splunk Cloud is the right solution for you. Organizations of all sizes leverage Splunk visibility with AWS agility to rapidly troubleshoot applications, ensure security and compliance, and monitor business-critical services in real-time. Splunk Cloud makes it easy to gain end-to-end visibility across your AWS and hybrid environment. Leverage Splunk Cloud with the free Splunk App for AWS to gain critical security, operational and cost optimization insight into your AWS deployment. Whether you're managing applications, infrastructure or a security operations center in the cloud, Splunk delivers Operational Intelligence for a real-time understanding of what's happening across your business and IT so you can make informed decisions. It's easy to get started - and remember - when choosing a product option, match your location and anticipated index volume per day. Splunk Cloud is now FedRAMP authorized: Moderate

    Highlights

    • Collect and index any machine-generated data from virtually any source or location in real time. Just point Splunk Cloud at your data, and it immediately starts collecting and indexing so you can start searching and analyzing.
    • Splunk Cloud offers single-pane-of-glass visibility across on-premise Splunk Enterprise and Splunk Cloud deployments, enabling customers to deploy Splunk as software or SaaS according to their business requirements, while maintaining centralized visibility.
    • Splunk Cloud includes support for Splunk apps and other content. Splunk apps deliver a targeted user experience for different roles, use cases and enterprise technologies. These apps can help you visualize data in new ways or provide pre-defined views of leading technologies such as Linux, Windows, VMware and more.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (20)

     Info
    Dimension
    Description
    Cost/12 months
    US - 5GB/Day
    Index Volume
    $8,100.00/GB
    US - 10GB/Day
    Index Volume
    $13,800.00/GB
    US - 20GB/Day
    Index Volume
    $24,000.00/GB
    US - 50GB/Day
    Index Volume
    $50,000.00/GB
    US - 100GB/Day
    Index Volume
    $80,000.00/GB
    EMEA - 5GB/Day
    Index Volume
    $9,315.00/GB
    EMEA - 10GB/Day
    Index Volume
    $15,870.00/GB
    EMEA - 20GB/Day
    Index Volume
    $27,600.00/GB
    EMEA - 50GB/Day
    Index Volume
    $57,500.00/GB
    EMEA - 100GB/Day
    Index Volume
    $92,000.00/GB

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Splunk offers a variety of support options to help ensure your success.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Data Anonymization, Data Security and Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    7 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Real-time Data Collection and Indexing
    Collects and indexes machine-generated data from virtually any source or location in real time with immediate search and analysis capabilities.
    Multi-deployment Visibility
    Provides single-pane-of-glass visibility across on-premise and cloud deployments, enabling centralized monitoring across hybrid environments.
    AWS Service Integration
    Supports integration with AWS services including CloudTrail, Config, and VPC Flow Logs for comprehensive AWS environment monitoring.
    Pre-built Application Support
    Includes support for Splunk apps with pre-defined views for leading technologies such as Linux, Windows, and VMware.
    FedRAMP Authorization
    Maintains FedRAMP Moderate authorization for compliance with federal security standards.
    Real-time Data Collection and Indexing
    Collects and indexes machine-generated data from virtually any source or location in real time with automatic indexing upon data ingestion.
    Complex Event Correlation
    Correlates complex events spanning multiple diverse data sources using time-based correlations, transaction-based correlations, sub-searches, lookups, and joins.
    Scalable Data Processing
    Scales to collect and index tens of terabytes of data per day with distributed computing architecture.
    High Availability Clustering
    Provides clustering technology for availability and fault tolerance across distributed computing environments.
    Machine Data Search and Analysis
    Enables searching, analyzing, and visualization of machine data generated by IT systems and technology infrastructure across physical, virtual, and cloud environments.
    Data Routing and Destination Management
    Routes data to multiple destinations with capability to deliver specific data to targeted tools while archiving full fidelity data to cost-effective storage
    Data Optimization and Reduction
    Reduces data streams by up to 50% through removal of unused log and metric data
    Event Processing and Transformation
    Processes event data through centralized parsing with capabilities to route, optimize, reformat, and enrich data in flight
    Role-Based Access Control
    Implements role-based access control with support for external authentication via LDAP, Splunk, and OpenID Connect identity providers
    Real-Time Monitoring and Configuration
    Provides GUI-based configuration and testing interface with live data capture and real-time observability pipeline monitoring

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    91 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    51%
    44%
    4%
    1%
    0%
    23 AWS reviews
    |
    68 external reviews
    External reviews are from G2  and PeerSpot .
    reviewer2805738

    Cloud security service has transformed onboarding, reduced maintenance, and unified orchestration

    Reviewed on Mar 02, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We use Splunk Cloud Platform  for security and want to implement it as a SIEM  solution. We also want to replace our old legacy SIEM  solution because we are adopting a cloud solution instead of an on-premises solution. Another use case is that we want to use this tool in our managed service offering. We do not use the solution to resell licenses to our customers, but rather to provide services to them. We appreciate the powerful integration that Splunk Cloud Platform  offers, making it easy to integrate with any sources and any data. It is able to handle data that resides in an S3  bucket or elsewhere, not just ingested directly into the SIEM itself. We are also looking at Splunk Cloud Platform's strategy, which is very interesting because of the integration they will have regarding Agentic AI and automation. A unique solution for orchestration and automation, called SOAR  in cybersecurity, combined with SIEM in a unique platform is a very interesting strategy from our point of view.

    It is Enterprise Security in the cloud. This is a cloud solution.

    What is most valuable?

    Splunk Cloud Platform is a very mature solution and an enterprise-grade solution that brings the work we have to do with customers to an enterprise-grade level. It is something that we can manage from a single pane, and it is quite easy to deploy. I see a benefit that is not strictly related to the features that Splunk Cloud Platform offers, but it depends on the company belonging to Cisco now because we are a Cisco partner and Splunk Cloud Platform is a pillar, a vertical technology in the security area of the partnership. The benefit of partnering with Splunk Cloud Platform falls into the Cisco partnership and the benefits we can have in this important partnership we have as a company.

    Compared to my previous situation, the first benefit of this solution is the speed and the effort reduction in terms of onboarding new customers and maintaining the entire platform. I will not have any more effort for system upgrades and infrastructure maintenance. This is one of the biggest benefits I can have from the solution. I save a lot of money because I do not have to spend resources anymore to maintain and operate the infrastructure and the systems.

    What needs improvement?

    I think it is really effective, and we are still at the beginning. The capability to search for insights is very powerful and also supported by AI and machine learning. The capabilities are increasing day by day, and new features are being released and will be released soon.

    I am not able to answer right now, but I am confident they will be able to predict a trend because they promise they are able to do this using machine learning algorithms and Agentic AI features. They say they will be able to predict the behavior of your network or your infrastructure. I am really confident about this, and I hope it will be true because I need this.

    There is something that they say will be improved, and I am still waiting for it. This is the Agentic AI elements inside the platform that I mentioned before. There is something present today, but the full feature is not released yet. From my point of view, it is a bit late. It is okay for me because we are adopting it and we can work on this, and it is acceptable for my timing. However, from a market perspective, they are a bit late. Competitors in some cases are earlier adopters. But I am sure they will release a very powerful tool, as per the Cisco approach. They want to win when they start doing something, and I am confident they will release a very powerful tool.

    For how long have I used the solution?

    I have been working with it for one month.

    What do I think about the stability of the solution?

    It is still a bit early to answer. We have just seen it on paper, and we have to check it.

    Which solution did I use previously and why did I switch?

    In my previous experience, I had enterprise security, but on-premises a few years ago, three years ago. It was integrated with another SOAR  from another vendor.

    How was the initial setup?

    It is something that we can manage from a single pane. It is quite easy to deploy.

    What's my experience with pricing, setup cost, and licensing?

    Compared to my situation, it does not have any meaning because I have something legacy now. However, it is a good price on the market. It depends because if you look at the list price, it is a bit expensive from my point of view. But once you are in the partnership with Splunk Cloud Platform and with Cisco, you can have good discounts, you can make the deal and discuss, and they are willing to help you as a partner in finding the solution and finding your target. So it is good from my point of view. But if you look at the list price, it is expensive.

    Which other solutions did I evaluate?

    We evaluated QRadar, FortiSIEM , and Palo Alto SIEM. We chose Splunk Cloud Platform because of a combination of different aspects, not just for price or features. It is the whole combination of the features, the benefits, the cost, the partnership, and there is no one aspect leading the choice. It is a mix and a combination.

    What other advice do I have?

    Today, we are working with the SIEM solution, which is quite a legacy term. Saying SIEM is not really effective. It is the Enterprise Security solution, and we are now in the process to implement it. We are adopting the solution and are at the beginning. We have studied a lot, we are training people, and we are changing and modifying our process as per what the technology allows us to do. We are also evaluating the observability solution. We are working on two different paths, and one is at a more mature stage, while the other one is at an evaluation stage.

    We are setting up alerts as expected.

    We are integrating Splunk Cloud Platform SIEM solution with our SOAR solution, which is today from another vendor and not Splunk Cloud Platform. Then we will see tomorrow what we want to do if we want to use the unique platform, the unique Splunk Cloud Platform with SOAR, Agentic AI, SOC automation, and everything, or if we want to keep using our actual SOAR. We are integrating Splunk Cloud Platform with this SOAR.

    My recommendation is to look at the future and look at the strategy. Do not look at the features today but look at the features tomorrow and not just at the technical features but at the whole strategy to integrate in one single platform all the capabilities that a SIEM solution or a log gathering solution might have. Putting together orchestration, observability, security, this kind of strategy is what an integrator should evaluate in my opinion.

    I would rate this product an 8 out of 10.

    Tejas Shah

    Unified data monitoring has enabled proactive alerts and predictive analysis for daily operations

    Reviewed on Feb 27, 2026
    Review provided by PeerSpot

    What is our primary use case?

    The main use cases for Splunk Cloud Platform  include data collection, parsing activities, use case building, data ingestion, and creating dashboards and reports. My clients use it for similar purposes.

    What is most valuable?

    The best thing about Splunk Cloud Platform  is that you can bring any data and store it in one place. You can build meaningful insights from it, have the same data ingested, create beautiful insights, have alerting done on it, and have dashboards and reports built on top of it.

    Splunk Cloud Platform's ingest and visualization features do not bind you with a limitation in the volume you want to ingest. Since we are using the compute-based licensing feature of Splunk Cloud Platform, there is no limitation to the volume of data we ingest on the platform. All Splunk Cloud Platform instances are also Smart Store supported, so that eases storage utilization concerns.

    One of the best advantages of using Splunk Cloud Platform is that there are lots of proactive alert notifications from Splunk support if anything goes down on the infrastructure end or if there is anything wrong with your environment. Splunk support is on top of things, notifying you beforehand if something is going wrong and that their team is already aware and working on a fix.

    What needs improvement?

    I don't see any new requirements in terms of improvements for Splunk Cloud Platform at this time. Splunk's dashboarding, reporting, and visualizations are evolving at a larger scale with the new Splunk Dashboard Studio in place. There were some limitations with the classic dashboard where you had to be aware of different HTML, CSS, and custom JavaScript for better visualizations. That's being migrated towards Splunk Dashboard Studio, which is evolving at a great pace, providing similar functionalities. I have not faced any current challenges regarding Splunk Cloud Platform's limitations. I still think, however, that better configuration and customization options for workload management could be enhanced, but that applies to Splunk Enterprise as well. It's just my understanding and what I foresee, but I'm not sure if it will be a priority right now, as even without workload management, a lot can be done, and the product team might have a different roadmap.

    For how long have I used the solution?

    I have been working with Splunk Cloud Platform for almost six years.

    How are customer service and support?

    My feedback remains that you have your designated account manager who helps navigate all the cases. Sometimes, the support team may not be fully knowledgeable about the challenge you face, but through their internal escalation structure, they manage to find viable solutions sooner or later or provide updates on when issues will be fixed. I think their support is pretty good on that part.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The best thing about the initial setup process of Splunk Cloud Platform is that you don't have to deploy your own Splunk Cloud Platform deployment; Splunk handles it for you. For the on-premises setup, you do need the initial configuration for end devices to send logs to Splunk Cloud Platform, but it's straightforward. It's just one package that you install on your end device, and after restarting, everything is sorted. There is no hassle in configuring Splunk Cloud Platform or getting on-premises devices to send data to it.

    What other advice do I have?

    We do use Splunk Cloud Platform's alerting mechanism. We have set up hundreds and thousands of alerts for different use cases. For example, if any of the data sources stop the ingestion or the volume has been relatively quite down, we have set up alerting for that. It creates a ServiceNow  incident that falls under our team's responsibility and sends an email as a notification that this alert has been triggered, such as when XYZ feed has gone down or the data from XYZ feed has decreased up to 80% or 70%, whatever the threshold set. We definitely use all the different alerting mechanisms and alert actions provided by Splunk Cloud Platform.

    Whenever we see a situation where we don't want to be reactive, we attempt to do a predictive analysis of the data ingested in our Splunk Cloud Platform. This analysis depends on an alert-to-alert basis. For instance, when talking about a data source going down, if the situation arises, we should be triggered at a threshold of around 80% decrease. In that situation, we keep a buffer of 10% and alert ourselves to notify at a 70% decrease in the feed so that we can take preemptive measures to ensure that the feed comes back online before the situation escalates.

    In terms of machine learning, we are using the Splunk-supported machine learning toolkit that also has new features for artificial intelligence. We do use them for outlier detection and predictive analysis in terms of different alerting we have enabled in our environment.

    To predict trends in our data, the example I shared previously involves understanding if the volume is going down or not. We do this using the machine learning toolkit itself. We have our data ingested into Splunk Cloud Platform, and each index and source type has some dedicated volume getting ingested daily. We create an average of the total volume ingested over the past 60 days, 45 days, and 90 days, and then we identify the volume ingested yesterday. We compare it with the average of the last 45 days and try to detect any deviation. All of this is part of the machine learning toolkit application itself. That's how predictive analysis and outlier detection work, and we're using that in our daily operations as well.

    With different vendors, there is no problem having Splunk Cloud Platform integrated with them. For example, we already have our alerting enabled so that whenever any alert gets triggered, an incident is created in ServiceNow . I have also worked on integrating Jira  and other different Atlassian products with Splunk Cloud Platform. It's user-friendly and straightforward to integrate Splunk Cloud Platform with different vendors without much issue.

    For any organizations looking to configure Splunk Cloud Platform, I believe it's a simple process. It's just important to stick to the fundamentals and understand how Splunk Cloud Platform operates. The documentation is quite clear. One notable advantage of Splunk Cloud Platform is the Ingest Processor and Edge Processor, which help optimize data before feeding into Splunk Cloud Platform. We've seen a reduction of around 40% to 60% in the total volume ingested using efficient data pipelines. We provide services for optimizing data pipelines and feeds, and those tools can be quite helpful. But if you're looking to configure Splunk Cloud Platform for on-premises servers, downloading the universal forwarder package from the Splunk Cloud Platform search head is all you need.

    I would rate this product a 9 out of 10.

    Charles Roberti

    Security monitoring has improved and provides timely alerts for cyber threats

    Reviewed on Feb 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Splunk Cloud Platform  is used as a way for companies to enhance their cybersecurity and ensure security. In cybersecurity, it is important to protect against all malwares, and the platform is effective in searching vulnerabilities or searching threats.

    What is most valuable?

    Splunk Cloud Platform 's ingest and visualization features help with data reporting. The platform's alerting mechanism is valuable, as there is software that makes alarms in case of attacks. Splunk Cloud Platform is used as a way for companies to enhance their cybersecurity as a question of security to ensure the security.

    What needs improvement?

    I think that Splunk Cloud Platform is good, and I rate it seven or eight.

    For how long have I used the solution?

    We have worked with Splunk Cloud Platform for approximately three years. We have also been working with Splunk Observability Cloud  for approximately three years.

    What do I think about the stability of the solution?

    Splunk Cloud Platform is a good platform for us.

    How are customer service and support?

    The technical support of Splunk is good as well, and they are helpful.

    How would you rate customer service and support?

    Positive

    What was our ROI?

    Implementation has some benefit for the company.

    What's my experience with pricing, setup cost, and licensing?

    We think that the price of the product is quite reasonable.

    What other advice do I have?

    We have clients that use Splunk, but we do not use Splunk ourselves. As a person with deployment experience, I find it difficult to answer the question about implementation because we are obliged to have a platform. There are many platforms, and the implementation is not simple, but we have no special difficulties with Splunk. We think that integration of Splunk Cloud Platform with third-party tools is easy to implement.

    reviewer2747775

    Security monitoring has become proactive with customizable alerts and clear dashboards

    Reviewed on Feb 19, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My major use case for Splunk Cloud Platform  is for SOC, SIEM  mostly.

    What is most valuable?

    What I like about Splunk Cloud Platform  is the easy reading of the dashboards and finding the data, which brought me the biggest benefits.

    The alerting mechanism in Splunk Cloud Platform is customizable, so we could adapt it to our needs and assign the right priorities and based on this, define the action.

    Visualization features and ingesting in Splunk Cloud Platform helped to improve my data reporting, but that was also a different team that was providing the log ingestion.

    Other features that were really great in Splunk Cloud Platform include real-life monitoring, so we could have logs right away, and parsing was fine, so when it was correctly ingested and Splunk Cloud Platform parsed it correctly, then we had no issues with receiving the correct alerts.

    What needs improvement?

    Splunk Cloud Platform could improve in how quickly it reacts to users reporting issues.

    Splunk Cloud Platform can be complex depending on the log source in terms of deployment.

    For how long have I used the solution?

    I used Splunk Cloud Platform for seven years.

    What do I think about the stability of the solution?

    Splunk Cloud Platform was stable, and I did not see any performance issues or downtime, although it happened; the issue was that we had to really fine-tune the log quality so that it would not be ingested too much and handled for nothing.

    What do I think about the scalability of the solution?

    Regarding the scalability of Splunk Cloud Platform, I would say it is scalable, but maybe the pricing may affect the scalability because it may not be that beneficial to onboard too many log sources if they generate too many false positives and then you reach over the limit of the license.

    How are customer service and support?

    I would rate the technical support for Splunk Cloud Platform probably a three, because there was some support, but I remember that we were using our proxy company to submit it for us because they were bigger and maybe more convincing to Splunk.

    How would you rate customer service and support?

    Negative

    How was the initial setup?

    The biggest issue during deployment of Splunk Cloud Platform was correct log parsing.

    What about the implementation team?

    I can describe the impact of integration with third-party solutions in Splunk Cloud Platform as limited experience since I was the only one on the receiving end of it, and I was not integrating it with any solutions or with any other vendors; we also had the company who was supporting us in the configuration part, so we didn't even have to do it fully by ourselves.

    What was our ROI?

    I don't see ROI with Splunk Cloud Platform, such as time saving or money saving because I'm security operations, so I don't think in management terms.

    What other advice do I have?

    I have about the same amount of experience in this domain with SOC solutions, as I haven't worked with SOC SIEM  solutions such as Splunk Cloud Platform before, so it's the same. My overall review rating for Splunk Cloud Platform is 8.

    Airlines/Aviation

    Powerful Real-Time Insights, But Pricing Can Spiral Without Log Filtering

    Reviewed on Feb 13, 2026
    Review provided by G2
    What do you like best about the product?
    Real-time visibility and powerful SPL queries for rapid root cause analysis.
    What do you dislike about the product?
    High and Unpredictable Costs: The pricing (whether based on data ingestion volume or "Workload" compute units) scales rapidly. If you don't aggressively filter logs before they hit the cloud, your bill can spiral quickly
    What problems is the product solving and how is that benefiting you?
    Splunk IT Cloud (comprising Splunk Cloud Platform and the Observability suite) is designed to solve the problem of "Data Sprawl"—the overwhelming amount of fragmented information generated by modern, multi-cloud environments.
    View all reviews