Deploy Splunk Enterprise into a new VPC on AWS

or deploy Splunk Enterprise into your existing VPC

(Deployment requires subscription to the Splunk AMI)

To deploy a Splunk Enterprise cluster on AWS, view the Quick Start deployment guide. The guide provides step-by-step instructions to help you get the most out of your Splunk Enterprise deployment. To try out additional Quick Starts, view our complete catalog.


Use this Quick Start to deploy a distributed Splunk Enterprise environment on the AWS Cloud.

The Splunk platform makes machine data accessible and usable. Splunk Enterprise enables you to search, monitor, and analyze machine data from any source to gain valuable intelligence and insights across your entire organization.

With Splunk Enterprise on the AWS Cloud, you gain the flexibility of the AWS infrastructure to tailor your Splunk Enterprise deployment according to your needs, and you can modify your deployment on demand, as these needs change.

This Quick Start includes AWS CloudFormation templates that deploy Splunk Enterprise automatically into a highly available AWS Cloud environment.

  • What you'll build

    Use this Quick Start to set up the following Splunk Enterprise environment on AWS:

    • A virtual private cloud (VPC) configured across two Availability Zones, with a public subnet provisioned in each Availability Zone, if you choose to deploy Splunk Enterprise into a new VPC.
    • Two Elastic Load Balancing (ELB) load balancers: one to load-balance HTTP web traffic to the search head instances, and the other to load-balance HTTP event traffic destined for the Splunk HTTP Event Collector (HEC) across all indexer instances.
    • An IAM user with fine-grained permissions for access to AWS services necessary for the deployment process.
    • Appropriate security groups for each instance or function to restrict access to only necessary protocols and ports.
    • In the public subnets, EC2 instances for Splunk Enterprise, including the following:

      • Splunk indexer cluster with the number of indexers you specify (3-10), distributed across the number of Availability Zones you specify.
      • Splunk search heads, either stand-alone or in a cluster, based on your input during deployment. In the latter case, the search heads are distributed across the number of Availability Zones you specify.
      • Splunk license server and indexer cluster master, co-located.
      • Splunk search head deployer, where applicable.
      • (Optional) User-provided Splunk apps and/or add-ons, loaded and pre-installed across indexers and search heads, based on your input.
    • Your choice to create a new VPC or deploy Splunk Enterprise into your existing VPC.

    For details, see the Quick Start deployment guide.

  • Deployment details

    Build your Splunk Enterprise cluster in 10-30 minutes, in a few simple steps:

    1. Sign up for an AWS account at
    2. Subscribe to the Splunk Enterprise AMI in the AWS Marketplace. (To take full advantage of Splunk Enterprise features, we recommend that you obtain a license by contacting
    3. Launch the Quick Start into a new VPC, if you want to build a new AWS infrastructure. 
      Launch the Quick Start into an existing VPC, if you already have your AWS environment set up. 
      Each deployment takes 10-30 minutes, depending on whether you decide to enable search head clustering.
    4. Send data to the Splunk indexers. 

    To customize your deployment, you can choose different instance types for Splunk Enterprise resources, and customize the number of instances, replication factor, indexer disk size, and other Splunk settings.  

    For detailed instructions, see the Quick Start deployment guide.

  • Cost and licenses

    You are responsible for the cost of the AWS services used while running this Quick Start reference deployment. There is no additional cost for using the Quick Start.

    The AWS CloudFormation template for this Quick Start includes configuration parameters that you can customize. Some of these settings, such as instance type, will affect the cost of deployment. For cost estimates, see the pricing pages for each AWS service you will be using.

    This Quick Start requires a subscription to the Amazon Machine Image (AMI) for Splunk Enterprise, which is available from AWS Marketplace. The AMI offers a 60-day trial license that provides limited access to Splunk Enterprise features. In order to utilize the deployment created by this Quick Start, you will need to obtain a Splunk Enterprise license by contacting