The ground breaking partnership between Splunk and AWS Security Hub Extended delivers a significant advantage for the SOC, by streamlining operations, reducing blind spots and disrupting attacks more rapidly. Splunk elevates AWS Security Findings as native findings, bypassing complex parsing and surfacing high priority incidents in near real time to analysts, significantly reducing MTTD. Splunk enriches the findings through our unified, AI powered SecOps platform capabilities. For procurement teams, Security Hub Extended offers unprecedented agility, providing a single contract, consolidated billing, and a flexible monthly commitment model managed entirely by AWS, allowing organizations to scale their security operations without long term lock in.
Streamline Procurement: Scale security spend with business needs. Overcome the friction of multi vendor management through the Security Hub Extended model. With AWS as the seller of record, organizations benefit from unified contracting and streamlined Level 1 support. The flexible monthly commitment pricing eliminates the risk of rigid, multi year lock ins, giving security leaders the commercial agility to adapt their architecture and spend as their environment evolves.
Unify Security Operations: Reduce blind spots to regain decision advantage. Shift from reactive logging to proactive defense. By normalizing Security Hub Extended findings via OCSF, Splunk enables near real-time, high fidelity correlation against on premises and hybrid data. This helps to drive end to end visibility across complex, multi cloud, and hybrid environments, allowing teams to make faster, data driven decisions without toggling between disjointed tools.
Disrupt Attacks Early: Stop indicators of attack before objectives are met. Deploy a unified, AI powered SecOps platform directly within the AWS ecosystem. As a strategic SIEM launch partner, Splunk Enterprise Security Essentials fuses AWS telemetry with industry leading Splunk security analytics to create a single source of truth, enriched with TI and deep context. This allows analysts to predict and intercept an attackers next step, turning isolated alerts into actionable intelligence to help stop threats before they impact the business.
Highlights
The Power of Splunk SIEM. The Simplicity of AWS Security Hub Extended.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay based on how much data you send into the platform each day, measured in GB per day per month. Five ingest bands set the rate, from 50-99 GB/day up to 10,000+ GB/day. The per-GB rate drops as your daily ingest band rises, so larger volumes carry a lower unit price. Each ingest band includes 90 days of storage. Two independent add-ons let you buy more storage in 500 GB blocks: searchable (hot) storage for active use, and archival (cold) storage for retention. You combine an ingest band with any storage add-ons you need.
Top-of-mind questions for buyers
What counts as one GB/day for billing, and how is my daily ingest volume measured?
One GB/day is one gigabyte of data sent into the platform per day, billed monthly. Your ingest band is set by your daily data volume from any source, structured or unstructured. The platform monitors data across on-premises, hybrid, and multi-cloud environments to total your daily ingest.
What happens to my per-GB rate if my daily ingest crosses into a higher band?
Your rate follows the band your daily ingest volume falls into. As your daily volume rises into a higher band, the per-GB rate drops. Each band spans a set range, from 50-99 GB/day up to 10,000+ GB/day. You are billed at the rate for the band matching your volume.
How do the searchable and archival storage add-ons combine with my ingest charge on the bill?
Your ingest band already includes 90 days of storage. The two storage add-ons bill separately, each in 500 GB blocks. Searchable (hot) storage keeps data active for querying; archival (cold) storage holds data for retention. You add either or both to your ingest band, and each appears as its own charge.
www.splunk.com
Helpful?
Vendor refund policy
All purchases are final, no returns or refunds.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Level 1 support provided by AWS.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
If you are looking for security and operational visibility across your AWS environment including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more then Splunk Cloud is the right solution for you.
Transform your AWS security operations with Falcon Next-Gen SIEM. Stop threats fast with unified visibility across AWS security tools and your security ecosystem. Prioritize the alerts that matter most and streamline investigations with automation and AI. Meet key compliance requirements with prebuilt dashboards and log retention. Get started in minutes with automated onboarding and flexible, pay-as-you-go consumption billing.
Splunk SIEM is a powerful and modular cybersecurity solution that integrates the core data analytics engine of Splunk Enterprise (available on-premises or via Splunk Cloud Platform) with the advanced capabilities of Splunk Enterprise Security (ES). This combination forms a comprehensive Security Information and Event Management (SIEM) system designed to address the full spectrum of modern security operations.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.