
Overview
Splunk Cloud [DSOR] combines the benefits of the Private Offer feature along with Carahsoft's contract vehicles in providing customers a seamless acquisition process for their cloud-based products and solutions from AWS Marketplace.
If you're looking for security and operational visibility across your AWS environment - including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more - then Splunk Cloud is the right solution for you. Organizations of all sizes leverage Splunk visibility with AWS agility to rapidly troubleshoot applications, ensure security and compliance, and monitor business-critical services in real-time. Splunk Cloud makes it easy to gain end-to-end visibility across your AWS and hybrid environment. Leverage Splunk Cloud with the free Splunk App for AWS to gain critical security, operational and cost optimization insight into your AWS deployment. Whether you're managing applications, infrastructure or a security operations center in the cloud, Splunk delivers Operational Intelligence for a real-time understanding of what's happening across your business and IT so you can make informed decisions.
Highlights
- Collect and index any machine-generated data from virtually any source or location in real time. Just point Splunk Cloud at your data, and it immediately starts collecting and indexing so you can start searching and analyzing.
- Splunk Cloud offers single-pane-of-glass visibility across on-premise Splunk Enterprise and Splunk Cloud deployments, enabling customers to deploy Splunk as software or SaaS according to their business requirements, while maintaining centralized visibility.
- Splunk Cloud includes support for Splunk apps and other content. Splunk apps deliver a targeted user experience for different roles, use cases and enterprise technologies. These apps can help you visualize data in new ways or provide pre-defined views of leading technologies such as Linux, Windows, VMware and more.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Splunk Cloud Subscription 500GB | Splunk Cloud Subscription with Federal Compliance impact level controls, Encryption at Rest - Dynamic Data Archive - 500GB Increments - 82 Units | $1,620.00 |
Vendor refund policy
No refunds
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Splunk offers a variety of support options to help ensure your success.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
![Druva Data Security Cloud - Backup and Recovery [Private Offer Only]](https://d7umqicpi7263.cloudfront.net/img/product/0d579195-f6b8-40b2-a43e-ee704941c6e9.png)
![Tenable Cloud Security [Private Offer Only]](https://d7umqicpi7263.cloudfront.net/img/product/22b9f065-b28f-4713-a430-d04cee1d6c4b.png)
Customer reviews
Centralized monitoring has improved log analysis and accelerated incident investigations
What is our primary use case?
My experience with Splunk Cloud Platform was good, as I used it during my initial days for analyzing and monitoring large volumes of data. At that time, my role was to ingest logs, parse data, build use cases, create a dashboard, and configure alerts across different systems like endpoint applications and cloud services. One of the biggest advantages I have seen is that it allows us to bring all of our data into a single platform and generate meaningful insights from it.
What is most valuable?
One of the best features in Splunk Cloud Platform is the ability to ingest any type of data and store it in one place, which gives complete visibility across the environment. The other feature is the SPL search engine, which is extremely powerful, allowing deep analysis and correlation of events. Once you understand SPL, it becomes one of the best tools for investigating data.
Then I would say dashboarding and visualization capabilities, especially with Dashboard Studio, which allows highly customizable and visually rich dashboards.
Regarding the effectiveness of the search capabilities, during my time, I was searching for firewall logs, and there are substantial volumes of firewall logs in GBs per day. When I search for these logs, if you start with the index and then your index name, it is pretty much faster, but I would say it is not faster than LogScale, as LogScale's search feature is better than Splunk Cloud Platform.
What needs improvement?
I see the areas of improvement for Splunk Cloud Platform in cost, as it can be relatively expensive, especially with high data volumes. Another area is the learning curve of SPL, which can challenge new users. Moreover, the AI-driven search query generation features I have come across recently are quite good.
In terms of missing features, if they can integrate more AI, like AI generation queries, then that could be helpful.
For how long have I used the solution?
The last time I worked with Splunk Cloud Platform was eight months ago.
How are customer service and support?
I have interacted with the technical support and customer service teams, particularly while building an add-on, where they helped me find the issue. They are quite good at what they do.
Which solution did I use previously and why did I switch?
Regarding switching from Splunk Cloud Platform to LogScale, it was not handled by me; it was on the managerial side. The main issue was the cost because, as data grows in Splunk Cloud Platform, it becomes very expensive. Comparatively, LogScale provides the same features and threat detection capabilities but allows for faster searches with an index-free architecture and at a lower cost.
How was the initial setup?
The initial setup of Splunk Cloud Platform was handled by the Splunk team, as it is hosted on public cloud AWS , and it was straightforward.
What was our ROI?
In terms of ROI with Splunk Cloud Platform, I see major benefits such as improved efficiency and reduced manual effort. For example, tasks that previously required multiple people can now be handled by fewer resources due to automation and centralized dashboards. We also see improvements in faster detection and response times, as alerts notify us proactively when issues occur.
Which other solutions did I evaluate?
In evaluating other options in the market, we looked at DataDog, which we saw for observability. However, DataDog is mainly for observability purposes, while Splunk Cloud Platform gives vast capabilities for different types of use cases, allowing us to create customizable add-ons.
The main differences, both pros and cons, of Splunk Cloud Platform in comparison to CrowdStrike technologies include the con that Splunk Cloud Platform's search engine does not have an index-free architecture like LogScale, which provides better speed when searching large amounts of data. A pro for Splunk Cloud Platform is that it has extensive documentation and a strong community for support, whereas LogScale has a less active community and lacks proper documentation.
What other advice do I have?
My advice for organizations considering Splunk Cloud Platform is to fully utilize it by ingesting as much relevant data as possible rather than limiting it to specific use cases. Also, invest time in learning SPL and best practices, and leverage the large Splunk community and pre-built integrations to maximize value. I would rate this product an 8 out of 10 overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized log monitoring has unified diverse data and drives proactive incident response
What is our primary use case?
Splunk Cloud Platform is used for centralized log collection, data ingestion and parsing, building dashboards and alerts, depending upon the client's requirement. Logs are collected from different sources like AWS , EDR, firewalls, and Windows. All logs are brought into one place, analyzed, dashboards are created, and alerts are set up for monitoring and security use cases. It acts as a single platform for monitoring and analysis.
What is most valuable?
One of the best things about Splunk Cloud Platform is that any type of data can be brought into one platform and worked on. This flexibility is very useful in real-world scenarios. For example, logs are ingested from multiple sources, and then dashboards are built for visibility. Alerts can be created for incidents, and meaningful custom dashboards can be created depending on the client's requirements. Trends can be tracked easily, such as trends of servers. Insights can be shared with teams. Since it is cloud-based, infrastructure does not need to be managed as Splunk handles back-end operations. This saves time, effort, and cost. For Enterprise, a particular infrastructure responsibility would normally need to be handed over to a particular team or person, but that team could be negligible by using Splunk Cloud Platform.
Splunk indexes logs as they are ingested, and by using the SPL language, Splunk Processing Language, particular data can be searched from the indexed data. Indexed logs are stored bucket-wise, so there is never randomness of the data. When searching for a particular type of data, that same type of data is always obtained from the particular span being searched for.
For proactive solutions, if log ingestion drops suddenly or a data source stops sending logs, alerts are configured to trigger when data drops by 70 to 80 percent. Notifications are received via email or any other configured platform for alerting. ServiceNow tickets can also be created for a particular issue. This helps transition from reactive to proactive monitoring.
For ingestion in Splunk Cloud Platform, the main aspect is data inputs. Infrastructure does not need to be managed as it is already managed by the Splunk teams. Data input ingestion is very easy as it has vast ingestion apps. Custom universal forwarders can also be used. Splunk has a universal forwarder product that can be installed at a particular server or application, which brings data to Splunk Cloud Platform. This universal forwarder product is a great choice for data ingestion as it gives customizable ingestion to any kind of application or server. For visualization, customized dashboards can be built, and pre-built dashboards from apps can also be used. For example, the AWS app has pre-built dashboards that can be used for monitoring AWS servers. Many applications are available.
What needs improvement?
The licensing cost is the one issue with Splunk Cloud Platform. Licensing cost is high, so for small organizations it may not be affordable. If customizable licensing options were provided, it could be more adaptable.
For how long have I used the solution?
Splunk Cloud Platform has been used for nearly one year.
What do I think about the stability of the solution?
Splunk Cloud Platform is very stable and reliable for customers. Setting the pricing aside, it is a great platform for clients.
What do I think about the scalability of the solution?
Splunk Cloud Platform is more scalable. The back-end part is provided, so it is highly scalable. Everything can be managed with the back-end, and everything can be built or managed.
How are customer service and support?
ServiceNow ticketing tools are used for monitoring and alerting purposes. Microsoft Teams alerting has also been integrated. If anything goes wrong on Splunk Cloud Platform, alerts can be received via email or can be set up to appear on Microsoft Teams .
Which solution did I use previously and why did I switch?
Splunk Enterprise platform was previously used, and it is known that Splunk also provides the cloud version. The main difference between Enterprise and Cloud is that if a team for infrastructure management is available, Splunk Enterprise platform should be chosen. If a particular team for infrastructure management is not available, Splunk Cloud Platform would be easier for the client to manage.
How was the initial setup?
There is no initial setup required for the cloud. Splunk already provides the infrastructure according to the need. Nothing needs to be managed or installed. Splunk only asks which cloud provider should be used. For example, if AWS is selected, everything is installed according to the need and provided. There is no involvement required.
What about the implementation team?
For Enterprise, the implementation was great. For the cloud, it would be great as it is the same thing and just a different product.
What was our ROI?
ROI depends on the user needs or the client's need. Sometimes it occurs once in a while, and sometimes if an issue occurs, then it could occur simultaneously.
Which other solutions did I evaluate?
Different solutions have been used, including Splunk Enterprise platform and CrowdStrike LogScale. For the observability part, DataDog and Dynatrace are being used.
What other advice do I have?
For more proactive solutions, if log ingestion drops suddenly or a data source stops sending logs, alerts are configured to trigger when data drops by 70 to 80 percent. Notifications are received via email or any other configured platform for alerting. ServiceNow tickets can also be created for a particular issue. This helps transition from reactive to proactive monitoring. This review has been given a rating of 8.5.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cloud analytics has improved security insights and simplifies proactive performance monitoring
What is our primary use case?
I use Splunk Cloud Platform as our overall tool to gain insight from our platform, for our security use cases, and to build a framework that shows what is happening in our organization or what is happening in our applications, the current status, or if we are facing any issues with our systems. I ingest various types of logs from different systems to Splunk Cloud from our forwarders and build dashboards and alerts on top of that. My primary use case is to understand our architecture or our overall environment, including what is happening and whether there are any vulnerabilities, or to conduct analysis on our applications. If there are any performance issues, I can learn about them from the dashboards that we have built and can optimize our architecture or overall application performance.
What is most valuable?
What I like about Splunk Cloud Platform is that it gives me flexibility and freedom in that I do not need to worry about the actual architecture of Splunk. I do not need to install it anywhere manually, and I only need to worry about what data I need to ingest and how I will create a dashboard on top of that. It provides support so I do not need to worry about the platform. It functions as Software as a Service, so I can directly use it and if I am facing any issue, Splunk support is available to help me anytime.
I do not have any limitations with Splunk Cloud Platform. I can access it from my own private network or anywhere, and I can access it from the public network as it is on a cloud. That is also a plus point for me.
In terms of assessing the effectiveness of Splunk Cloud Platform's search capabilities in uncovering operational insights, its storage capability is excellent. Previously, we were managing it at an enterprise level, but it was costly to us because of data redundancy and the availability zones. With Splunk Cloud Platform, we do not need to worry about data backup, which is a very good point.
The alerts have helped us in proactive issue resolution. If we are currently getting any error, we will get notified in the next 15 minutes or 30 minutes according to the schedule of the search.
Splunk Cloud Platform's ingest and visualization features have helped improve our data reporting, truly the best available in terms of customizability. We have two options, classic and Dashboard Studio for dashboard purposes. In classic, we get options to build custom dashboards using custom JavaScript. We can insert our own graphics to provide better visuals where insights to our management team will not be dependent on the numerical base. We have charts to showcase our current situation, which will be really great for management.
In terms of benefits, if we were needing two persons for SAP to analyze if we have any issues, now we just need one person doing multiple tasks. We have built an automation system, or a dashboard, which gives us insight so that we do not need to go and look up every service. Splunk Cloud Platform really impacted our workflow and increased our productivity.
What needs improvement?
In Splunk Cloud Platform particularly, there is nothing specific that I would like to see improved or enhanced, but the cost is currently very high. If that part could get a little bit cheaper, then that would be really great.
In terms of enhancement for Splunk Cloud Platform, I would say if we could create add-ons or if we get the capability to build add-ons directly through cloud, not talking about the add-on builder framework, but something editor-like where we will directly edit our conf files from any specific app or TA provided by Splunk Cloud Platform itself. If we get that feature, it will be really beneficial. Instead of doing configuration from the UI, we would prefer to get access to back-end conf files and do it manually because when we were using enterprise, we had pretty much hands-on experience with that.
For how long have I used the solution?
I have been using Splunk Cloud Platform for around two years.
How are customer service and support?
I would evaluate customer service and technical support of Splunk as really good. They provide on-call support and they reply to cases that we open, so the support is really good and collaborative.
Which solution did I use previously and why did I switch?
We have not previously used a different product. We have tried other tools, but they were very limited to the use cases that we are trying to capture. I chose to go with Splunk Cloud Platform because it has vast capabilities.
How was the initial setup?
The initial setup with Splunk Cloud Platform was really straightforward because, as it is a cloud platform, Splunk provided us the complete package where we do not need to worry about our infrastructure or configuration. If we need any help, they are always available, so it was very straightforward.
What about the implementation team?
The implementation was done by the Splunk team.
Which other solutions did I evaluate?
We evaluated products like Dynatrace or DataDog, which were very specific. They were providing us only observability-specific tasks. However, we have some VML logs or firewall logs for which we would not get that much analysis from those products. That is why we chose to go with Splunk Cloud Platform.
What other advice do I have?
We use Splunk default alert actions and we have installed third-party integrations, such as ServiceNow integration, where we are creating ServiceNow incidents or ServiceNow tickets from our alerts.
The impact of Splunk Cloud Platform's integrations with third-party tools on our daily operations is very helpful for our overall infrastructure monitoring. We have third-party integrations, such as SAP or Dell Boomi . To ensure that our SAP and site integration are running smoothly and none of its API is getting high or something unusual, we can easily detect that instead of going into SAP and analyzing.
We have our own machine learning logic where we are creating alerts based on our machine learning algorithm. If we are missing any data from the forwarders, then we have a built-in threshold mechanism where if the data from the last seven days is coming around 80 GB, then the next day it should be getting related to that. If we are not getting that, then we will get alerts. I have not particularly used Splunk ML Toolkit.
From the features perspective, I would say if we were getting calls from back two or three months, I was waiting for the Otel feature in Splunk Cloud Platform. Now we have support of Otel in the current latest Splunk version, so we are planning to upgrade Splunk Cloud Platform to the latest. The feature that I was looking for is now currently available, so I do not have anything specific at the moment.
In terms of pricing, the cost is high, but we are getting pretty much value out of what we are paying and what should be available to us in the market. In terms of that, it is really good with no question on that.
My advice to other organizations considering Splunk Cloud Platform is to make sure you use it as much as you can. There is a really big community of Splunk that you can explore to see what data you can ingest. There is a possibility you are already using other services from which you can get logs into Splunk and build analysis on top of that. Do not limit yourself to any specific use cases. I have seen some organizations only ingest specific logs, such as firewall logs or DNS logs. But they have different types of machines and applications running for their infrastructure. They can ingest logs from those as well and build analysis on top of that. There are pre-built add-ons that provide that functionality to them and they do not need to worry about development. So use it as extensively as possible. Overall, I would rate this product a nine out of ten.
Centralized monitoring has transformed our multi-tenant security operations and automated response
What is our primary use case?
My main use case for Splunk Cloud Platform is that in our organization, we use it as a centralized multi-tenant log ingestion across cloud and on-premises for all customer environments with index-level isolation. Splunk is used for ES for SOC operations enabling correlation searches, threat detection, and compliance reporting at scale.
A quick specific example of how I use Splunk Cloud Platform for SOC operations or threat detection in my daily work is privileged access anomaly detection. The correlation search flags abnormal login patterns using SPL plus UEBA baseline, and the automated response via SOAR or ITSM triggers alerts which create incidents and execute playbooks to disable accounts or isolate the hosts. We also use it for continuous monitoring with dashboards tracking MITRE attack and cases across all tenants with real-time alerting.
We use Splunk Cloud Platform for data onboarding and normalization to standardize logs across customers for consistent analytics and ES use cases. We also use role-based access control plus tenant isolation to ensure secure access control per customer within the shared Splunk Cloud Platform deployment.
What is most valuable?
The best features Splunk Cloud Platform offers are the multi-tenant data isolation plus role-based access control, secure index-level segregation for managing multiple global customers in a shared Splunk Cloud Platform environment. Additionally, features such as native integrations with SIEM , SOAR , and ITSM enable us to automate incident response, ticketing, and end-to-end security workflows across client environments. The high-scale injection plus SPL correlation process handles large volumes of infrastructure security logs with real-time analytics for managing SOC and cloud operations.
Splunk Cloud Platform has positively impacted our organization as we have achieved faster incident detection and response, lower MTTR with real-time SPL alerts and automated workflows. It has also improved our multi-tenant visibility and centralized monitoring, reducing tool sprawl. We also saw better compliance and audit readiness with consistent log retention and reporting.
What needs improvement?
Splunk Cloud Platform can be improved by having better multi-cloud integration for AWS , Azure , and GCP metrics and events out of the box. It should offer more cost-efficient storage retention options for high-volume multi-tenant log data and have simpler dashboard and alert management to reduce setup and maintenance effort across global customers. Additionally, the advanced anomaly detection tuning can be improved.
For how long have I used the solution?
I have been using Splunk Cloud Platform for two years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Splunk Cloud Platform is scalable for multi-tenant environments, handling terabytes of logs daily across global customers without performance impact. The auto-scaling injection and indexing ensure consistent performance as log volume grows, and it supports centralized dashboards and correlation searches across all tenants at enterprise scale.
How are customer service and support?
The customer support for Splunk Cloud Platform is responsive and knowledgeable. Support teams understand cloud and SOC issues and provide actionable guidelines quickly. They are also aligned to enterprise-level SLAs with timely escalation processes for critical incidents.
Which solution did I use previously and why did I switch?
We previously used an on-premises ELK stack plus custom scripts for log aggregation and monitoring. We switched to Splunk Cloud Platform for centralized multi-tenant visibility, real-time alerting, and automated SOC operations and workflows. The key reason for shifting is scalability, reliability, and built-in compliance and reporting across local customers.
How was the initial setup?
My experience with pricing, setup cost, and licensing is that the pricing is on the premium side because it scales with data injection and retention across multiple customers, which means that the price can grow quickly. The setup cost is moderate, and initial tenant onboarding, index setup, and dashboard configuration require effort. The licensing is flexible based on features such as Core, ES, and SOAR, but it needs careful planning for multi-tenant uses.
What was our ROI?
We have seen a return on investment as we observed a 50 to 60 percent reduction in manual SOC work, which allows freeing staff for higher-value tasks. We also saw incident response time drop by 40 to 50 percent, improving SLA compliance across customers. Furthermore, the overall cost saving from tool consolidation and automation delivered measurable return on investment within the first year.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, I evaluated other options including DataDog and Sumo Logic for log aggregation and monitoring. We also considered on-premises SIEM solutions but they lacked multi-tenant scalability and automation, so we chose Splunk Cloud Platform for real-time correlation, SOC automation, and enterprise-grade compliance features.
What other advice do I have?
The advice I would give to others looking into using Splunk Cloud Platform is to plan multi-tenant indexing and role-based access control earlier to ensure secure data separation. I would also tell my peers to leverage SOAR and ITSM integration from the start to automate incident response and reduce manual effort. I would rate my overall experience with Splunk Cloud Platform as an eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Improved security monitoring has provided wide observability and streamlined incident investigations
What is our primary use case?
I am also an end user of Splunk Cloud Platform . My usual use cases for Splunk Cloud Platform are to search logs and search data as I need for my security incidents. Searching logs and data for security incidents is my main use case.
What is most valuable?
The most valuable features or capabilities of Splunk Cloud Platform that I have found so far are mainly the search and the indexing engine, and I also find the data management of Splunk better. I have used both Splunk Enterprise and Splunk Cloud Platform, and I feel that the data management on Splunk Cloud Platform is handled by the Splunk team with much better expertise than its Enterprise Platform, where we had to manage storage and everything ourselves.
The effectiveness of Splunk Cloud's search capabilities in uncovering operational insights is pretty good. Once you know Splunk Query Language, or SPL, it is way better than any other data management tool, especially when analyzing and monitoring security logs, as it makes searching and minimizing threats much easier for me.
I use Splunk Cloud's alerting mechanisms to send alerts to my email, whether something happens in real-time or through scheduled Splunk query alerts for operational tasks like security incidents or operational warnings, such as when my storage is 90% full.
Splunk Cloud Platform's ingest and visualization features have helped me improve my data reporting significantly, as data ingestion and visualization are great, especially for creating dashboards from various sources like endpoints, firewalls, and web applications.
Operationally, Splunk Cloud Platform has provided wide observability where we had almost none before, significantly improving our security posture and our ability to defend the organization.
What needs improvement?
In my opinion, there isn't much to improve in Splunk Cloud Platform, but one suggestion would be to integrate AI or provide a more graphical query builder to reduce the learning curve for new users wanting to learn SPL.
For how long have I used the solution?
I have been working with Splunk Cloud Platform for around eight months.
What do I think about the stability of the solution?
I rate Splunk Cloud Platform a ten out of ten for stability and reliability, as I have found it truly reliable while using it on AWS and as a SaaS platform, given the capability for high availability and multiple indexers ensuring data continuity.
What do I think about the scalability of the solution?
I would rate Splunk Cloud Platform a nine out of ten for scalability. I think it's scalable due to the ease of integrating and deploying multiple indexers for data processing, although it does require some technical knowledge to configure properly for smooth operation.
How are customer service and support?
I do not often communicate with the technical support of Splunk Cloud Platform. I often visit Splunk's documentation portal for troubleshooting and assistance with my queries, and I find it quite good. They offer videos to help users learn how to use Splunk and Splunk Query Language.
I feel that Splunk's documentation is highly maintained, regular updates seem to happen, and I don't have any suggestions for improvement as it is currently at its best.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did not use a different solution for the same use cases prior to Splunk Cloud Platform. I only used Wazuh for security data logging but would not compare it to Splunk due to its broader capabilities.
How was the initial setup?
I did participate in the initial setup and deployment of Splunk Cloud Platform, but I wasn't part of the decision-making aspect. The initial setup process for deploying Splunk Cloud Platform was quite easy as we only needed to identify our data sources and determine the appropriate ingestion method, followed by some technical configuration, assuming we knew how our data was structured.
What was our ROI?
I might not be the right person to comment on the return on investment in terms of cost, but operationally, Splunk Cloud Platform has provided wide observability where we had almost none before, significantly improving our security posture and our ability to defend the organization.
Which other solutions did I evaluate?
I did not evaluate other options or vendors before choosing Splunk Cloud Platform. I did not participate in the decision-making process for choosing Splunk Cloud Platform, as I have worked operationally with it but was not involved in procurement.
What other advice do I have?
I have not used Splunk Cloud's machine learning tools. I do not personally integrate Splunk Cloud Platform with third-party tools; however, I know that my separate team has integrated quite a few tools, leveraging Splunk's vast library known as Splunk Enterprise Applications.
I have been working with Splunk Enterprise Platform , which is the on-premises version of Splunk Cloud Platform, and it is almost the same except for the maintenance efforts required and the deeper learning curve. I wouldn't say there's room for improvement in Splunk Enterprise Platform purely regarding the search engine, as it largely depends on the resources allocated to the indexer for its performance. I have been working with Splunk Enterprise Platform for approximately three to four months.