
Overview
If you're looking for security and operational visibility across your AWS environment - including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more - then Splunk Cloud is the right solution for you. Organizations of all sizes leverage Splunk visibility with AWS agility to rapidly troubleshoot applications, ensure security and compliance, and monitor business-critical services in real-time. Splunk Cloud makes it easy to gain end-to-end visibility across your AWS and hybrid environment. Leverage Splunk Cloud with the free Splunk App for AWS to gain critical security, operational and cost optimization insight into your AWS deployment. Whether you're managing applications, infrastructure or a security operations center in the cloud, Splunk delivers Operational Intelligence for a real-time understanding of what's happening across your business and IT so you can make informed decisions. It's easy to get started - and remember - when choosing a product option, match your location and anticipated index volume per day. Splunk Cloud is now FedRAMP authorized: Moderate
Highlights
- Collect and index any machine-generated data from virtually any source or location in real time. Just point Splunk Cloud at your data, and it immediately starts collecting and indexing so you can start searching and analyzing.
- Splunk Cloud offers single-pane-of-glass visibility across on-premise Splunk Enterprise and Splunk Cloud deployments, enabling customers to deploy Splunk as software or SaaS according to their business requirements, while maintaining centralized visibility.
- Splunk Cloud includes support for Splunk apps and other content. Splunk apps deliver a targeted user experience for different roles, use cases and enterprise technologies. These apps can help you visualize data in new ways or provide pre-defined views of leading technologies such as Linux, Windows, VMware and more.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Splunk offers a variety of support options to help ensure your success.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Unified monitoring has improved incident response while query optimization still needs work
What is our primary use case?
The main use cases for Splunk Cloud Platform involve forwarding logs from our application database using Splunk Forwarder to the Splunk tools so that we can have dashboards to check in case of any production issues, vulnerabilities, or incident cases.
What is most valuable?
What I appreciate about Splunk Cloud Platform is that observability is strong, and we can have real-time data with fast time to value. We can conduct advanced searches by leveraging the search processing language, and AI assistants are available to query and analyze data sets. This makes it excellent for unified observability and advanced searches.
Splunk Cloud Platform improves the way the organization functions by being used during SIEM and ITSM tickets to enhance infrastructure monitoring so that we can have customizable dashboards, interactive visualization, and out-of-the-box reporting for all stakeholders, whether technical or non-technical. Through this, we can achieve unified observability and full-stack visibility.
What needs improvement?
I would like to see Splunk Cloud Platform become more user-friendly compared to others. For example, Grafana is very user-friendly where you can easily create graphs.
Regarding missing features or functionalities, I believe index management and performance optimization should be enhanced so that we can optimize the SPL queries instead of using transactions whenever feasible.
For how long have I used the solution?
I have been working in my current field and in the industry for around 13.5 years.
What do I think about the stability of the solution?
I find Splunk Cloud Platform to be stable overall.
What do I think about the scalability of the solution?
Regarding the platform's ability to scale aligning with my organization's demand fluctuations, scalability requires some changes to our architecture involving planning related to the framework so it can adapt to growing data volume and user demands. Every day MFT and integration demands are increasing, so we must choose the right topologies for a scalable architecture, and role distribution should be in place. We need to use load balancing and capacity planning. We should take advantage of what Splunk Enterprise is providing by reviewing components such as Splunk Enterprise deployment, distributing indexing and searching so that we can use that platform to manage all user objects and data storage.
How are customer service and support?
I evaluate customer service and technical support from Splunk to be good. On a scale of one to ten, I would rate the technical support about nine.
Which solution did I use previously and why did I switch?
Currently there are no IBM solutions in use, but earlier I worked on App Connect Enterprise and IBM Integration Bus, which are integration-related technologies.
How was the initial setup?
The setup process of Splunk is straightforward. If we can provide the process document, it is easy. We conducted some development depending on the forwarder. By using the universal forwarder, we collected logs. We have to set up the indexes and search heads for medium enterprises. For large enterprises, the setup is more complex because we need clustering mechanisms such as load balancing, search head cluster, and index cluster. We can accomplish this by using the universal forwarder and indexes; Splunk will manage the indexes, storage, and upgrades, but as a customer we must manage the universal forwarder, data onboarding, and dashboards. These parts depend on the skill sets we have available.
What about the implementation team?
My company has a business relationship with Splunk as we are a customer, and they onboard the vendor as per their policy. We are managing them and are not part of that setup.
What was our ROI?
I find Splunk Cloud Platform to be cost-effective. If we optimize it, we can achieve ROI by seeing reduced downtime and improved operational efficiency. We can make changes in one go by having perfect compliance automation related to GDPR and PCI DSS.
The key differences and strengths of Splunk Cloud Platform in comparison to other technologies indicate that Splunk Cloud provides consolidated capabilities such as SIEM, log management, reporting tools, and monitoring dashboards that deliver better performance in monitoring. Depending on cost, if we optimize that very effectively, we can achieve good ROI by reducing ingested data volume, using data retention tiers, or summary indexing. Through this approach we can improve Splunk Cloud Platform ROI and use that tool very effectively.
What's my experience with pricing, setup cost, and licensing?
Regarding the pricing aspect, setup cost, and licensing of Splunk Cloud Platform, I have not directly joined that process, but it depends on the ingestion volume. It is based on the volume of data ingested per day, so we have to exclude unnecessary data sources and remove duplicate events to optimize cost improvement areas. We can establish data retention policies depending on hot and warm data so that the data will have summary indexing and reduce infrastructure cost and storage cost. We should have the right size infrastructure, and we have to monitor that license usage.
Which other solutions did I evaluate?
The key differences and strengths of Splunk Cloud Platform in comparison to other technologies indicate that Splunk Cloud provides consolidated capabilities such as SIEM, log management, reporting tools, and monitoring dashboards that deliver better performance in monitoring. Depending on cost, if we optimize that very effectively, we can achieve good ROI by reducing ingested data volume, using data retention tiers, or summary indexing. Through this approach we can improve Splunk Cloud Platform ROI and use that tool very effectively.
The main drawbacks of Splunk Cloud Platform include that while it removes the infrastructure management overhead, it has limitations such as volume growth becoming expensive. The licensing is typically based on ingestion volume or workload, so we must optimize that, and there is no direct access to the underlying server; we must use forwarding tools. Some advanced configurations are needed to support tickets or manage change processes. These are dependencies where we have to rely on vendor dependencies for maintenance windows. Data residency and compliance concerns also exist, where scenarios such as GDPR, banking, and healthcare have strict regulations regarding where data must be stored, so we have to consider that concern when making the decision.
What other advice do I have?
Generally, most enterprises find that Splunk Cloud Platform is reducing operational overhead, and we should focus more on security. It is a good choice when needing a managed service or for cloud-first organizations. For security and compliance, when custom scripts and third-party add-ons are needed, there are restrictions, and for very large volumes of multiple terabytes, it is not advisable because the licensing cost is very high and optimization will be critical. If complete administrative control is needed, we can avoid using Splunk Cloud Platform. I would rate this review overall as a seven out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Advanced ai-driven threat hunting has improved detection speed and streamlined investigations
What is our primary use case?
I was a consumer using Splunk Cloud Platform at that time. I have been familiar with Splunk Cloud Platform. I was a user of Splunk Cloud Platform and a customer also.
What is most valuable?
Splunk Cloud Platform is a data analysis tool that works on big data and unstructured data. What I appreciated about it is that Splunk data processing is very good. When I performed search and threat hunting on Splunk, I was very satisfied.
Splunk Cloud Platform supports AI automation and can empower analysts to use AI assistance and agentic playbooks to accelerate threat detection, investigation, and mean time to detect or mean time to respond.
Since Splunk already offers me an embedded AI solution, why would I go to any other AI solution? Splunk is helping us in the new era of AI.
What needs improvement?
There is always room for improvement. Splunk can improve because it is a very expensive product. Because of the cost, we do not have as many skilled resources for Splunk, which makes it very difficult to find a compatible resource to help us troubleshoot.
For how long have I used the solution?
I have worked with Splunk Cloud Platform for around 10 to 11 months.
What do I think about the stability of the solution?
Splunk Cloud Platform is a very vendor-diverse product. You can integrate almost anything around the infrastructure. It totally supports integration.
What do I think about the scalability of the solution?
Splunk Cloud Platform is currently the best option in the market if you have the capacity to pay what Splunk requires. If you are tight on budget, you can consider other options. With respect to price, Splunk is the best solution, but it is expensive.
When comparing it with LogRhythm, LogRhythm is for small organizations, but Splunk has financial considerations. Splunk has more advantages than LogRhythm when comparing from a financial perspective.
How are customer service and support?
Splunk Cloud Platform is currently owned by Cisco, and Cisco has very great support in my region.
Which solution did I use previously and why did I switch?
I was only using Splunk Cloud Platform.
How was the initial setup?
If you are planning to deploy Splunk Cloud Platform, there is a whole lot of architecture planning involved. You need to plan accordingly as per your infrastructure needs.
What about the implementation team?
I was on the technical side, and the finances were managed by the governance team. I cannot answer questions regarding the subscription model and pricing structure.
What was our ROI?
Splunk Cloud Platform is a Gartner leading product. Splunk is superior in comparison with any other SIEM.
What's my experience with pricing, setup cost, and licensing?
Splunk Cloud Platform is a Gartner leading product. Splunk is superior in comparison with any other SIEM.
Which other solutions did I evaluate?
Splunk Cloud Platform should be improved in certain aspects. In comparison with QRadar, QRadar has dedicated log sources, but Splunk does not have dedicated log sources. We can only sort the log sources from the IPs or hostnames. Splunk can do that, or if they do not do that, it will not affect anything, but it could be beneficial for a SOC analyst to specify the data source.
What other advice do I have?
I cannot suggest additional features that could improve the rating further. I gave this review a rating of 9.
Daily analytics have transformed how I monitor searches, alerts, and integrations at scale
What is our primary use case?
My use case for Splunk Cloud Platform involves working in an organization that provides a daily full dashboard showing daily searches, daily ingestion, daily alerts, and more.
What is most valuable?
I really appreciate the ingestion features of Splunk Cloud Platform, which allow us to ingest data in various ways such as through an HEC token or Splunk Heavy Forwarder. Creating dashboards is very easy; currently, they provide two ways: a drag-and-drop grid layout or the traditional coding method.
I find the search capabilities effective because SPL, Splunk Query Language, is very easy to use. They are currently providing SPL2 with AI enhancing features that make searching really easy.
I use the alerting mechanisms with Splunk queries, having created multiple alerts that can send emails or display in the dashboard, making the alerting mechanism very helpful.
In terms of visualization features, creating dashboards on Splunk Cloud Platform is really easy, especially with the grid platform for drag-and-drop. The dashboard analytics feature is very helpful and fun to use.
I would describe the impact of integrations with third-party tools as powerful. We use add-ons like AWS CloudWatch, and integrating with any app on Splunk Cloud Platform is very easy.
What needs improvement?
Splunk Cloud Platform has room for improvement because managing the architecture for a newcomer, such as an intern, can be hard. They could provide better documentation and videos to help with learning.
I find the documentation of Splunk Cloud Platform fine in what I have learned, but having more visual videos to accompany the documents would be helpful for learners.
For how long have I used the solution?
I have been using Splunk Cloud Platform for six months in my training as well as in production, learning about creating apps, creating custom commands, and creating dashboards and analytical capabilities.
What's my experience with pricing, setup cost, and licensing?
The pricing of Splunk Cloud Platform is a concern for me; it is very costly, making it hard for small to medium vendors to afford.
Splunk does not actually save resources for us because it only helps with security. We have to buy more computational power for advanced usage.
Which other solutions did I evaluate?
I compare Splunk Cloud Platform with others like CrowdStrike and NG-SIEMs. While they are similar, Splunk is really way ahead, providing everything required.
For small and middle-class organizations, I would not recommend Splunk Cloud Platform because there are cheaper tools available. However, I would recommend it for very large organizations.
What other advice do I have?
Time-wise, Splunk Cloud Platform does save me time because if I am ingesting daily 2TB of data, I create the dashboard one time, and it updates automatically, allowing me to do data analytics more easily. I would rate this product a 9.
Centralized monitoring has accelerated incident investigations and provides hybrid security visibility
What is our primary use case?
In my daily work as an SOC L1, my use cases involve using Splunk Cloud Platform primarily for centralized log management and real-time incident detection. It acts as our central nervous system for security data. We stream logs from our other tools such as Wazuh directly into Splunk Cloud Platform, and the biggest use case for us is the speed of investigation. When an alert comes in, I can search through a massive amount of data in seconds to trace exactly what happened. It helps us to visualize the attack chain and prioritize what actually needs attention.
What is most valuable?
The biggest thing I appreciate about Splunk Cloud Platform is the stability of this platform. It is always up, and I have never had to worry about maintenance or downtime interrupting my shift. Search performance is another huge advantage, allowing me to query massive data sets in seconds when I am hunting for a specific log.
Since we are using Splunk Cloud Platform, the initial deployment is easy because we do not have to deal with the back-end infrastructure, which is a huge relief. It is a true SaaS experience, so you are not spending time patching servers or worrying about hardware capability. For me as an L1, the deployment part is really about onboarding our data sources. Once you have the connector set up pulling the logs from device endpoints and other tools such as Wazuh, it is fairly smooth.
For me as an analyst, maintaining Splunk Cloud Platform is really about keeping the data pipeline healthy. My focus is on making sure our Universal Forwarders are pushing data properly from our endpoints or other tools. I also keep an eye on index health and manage our retention policies so we do not exceed our storage systems.
About the app ecosystem within Splunk Cloud Platform, instead of us having to spend hours or days manually figuring out how to parse logs or map them to a common information model such as CIM, we can usually grab the right app from Splunkbase, and it does the heavy lifting for us, normalizing the data so that when I run a search, the fields are already in a structured and searchable format. It saves me so much time in day-to-day investigations, and because I do not have to worry about whether the log format is broken, the app handles that translation.
About visibility within Splunk Cloud Platform, the hybrid visibility is actually one of its strongest points. Since we handle a mix of environments for our clients according to their requirements, being able to pull everything into one central place is critical for us. We use Universal Forwarders on our on-premises servers to securely stream logs up to the Splunk Cloud Platform instance. For me, it effectively erases the boundary between on-premises and cloud. It does not matter if the log is coming from a server in our local data center or a cloud-hosted app. It all lands in that same single pane of glass.
What needs improvement?
The biggest downside about Splunk Cloud Platform for me is the cost. It is definitely on the expensive side, and you have to be very careful about what you ingest from sources. We are always mindful of our log volume because if you are not constantly tuning your filters or managing what data goes in, the cost can add up fairly quickly.
What do I think about the scalability of the solution?
In terms of scalability, Splunk Cloud Platform is one of the things that makes my L1 task much easier. As we onboard more devices or increase our log ingestions and stay ahead of threats, I never have to worry about the platform hitting the wall. With Splunk Cloud Platform, it just handles it. I have noticed that even when we ramp up the data from other tools such as Wazuh or add new endpoints, the search speed remains really consistent. It does not get sluggish or slow down, which is huge when I am in the middle of an investigation.
How are customer service and support?
We have a team to contact for technical support for Splunk Cloud Platform. I have not really been involved in that technical support phase, and I do not have much knowledge about that process or what is going on in the background. I would give around an eight out of ten for technical support for Splunk Cloud Platform.
Which other solutions did I evaluate?
I have not currently used any alternatives to Splunk Cloud Platform. I have not gained hands-on experience with other cloud platforms.
What other advice do I have?
I would give Splunk Cloud Platform an 8.5 overall rating for everything. We are a customer of Splunk Cloud Platform.
Custom views and shared dashboards have improved how I organize and collaborate on sensitive data
What is our primary use case?
My usual use cases for Splunk Cloud Platform include data, data integration, and dashboards. I currently have three use cases.
What is most valuable?
I find the features and capabilities of Splunk Cloud Platform to be highly valuable because of how customizable it is for my view and the data we need to put into it. The ability to organize the data and set up different views is particularly useful.
I also appreciate how easy it is to work with coworkers on the platform to collaborate on the same issues.
The tangible benefits I've observed since starting with Splunk Cloud Platform are significant. It's pretty much the standard for what we use it for. If we're working with a consultant or we bring in someone new, most people know the platform or at least have been exposed to it. This exposure and the platform's big name and familiarity make it easy to direct people around in it, show them the data, and collaborate.
What needs improvement?
I'm not quite sure how Splunk Cloud Platform could be improved or enhanced. I would suggest keeping what works. Sometimes it can feel slightly slow in what it brings up, but I don't know if a lot of times that's on our end with the data that's getting in. Staying up to date with current trends and technologies will be good enough for me. It's already a good platform, and I wouldn't recommend too many changes or tweaks.
The major thing that could be optimized is the speed, so it could be a bit faster.
For how long have I used the solution?
I've been working with Splunk Cloud Platform for about three years.
What do I think about the stability of the solution?
Splunk Cloud Platform has been living up to my expectations regarding reliability and stability so far.
I think we rarely ever have Splunk Cloud Platform crash or error out where we're not able to bring up the site and access what we need to do in it. Usually, in the rare case that it does happen, it's usually back up within 20 to 30 minutes. Stability-wise, sometimes it'll get slow, but usually, if we are patient, it pulls up everything we need it to.
What do I think about the scalability of the solution?
I believe Splunk Cloud Platform scales pretty well. We use it for quite a bit of the data and things that we house and have coming in, and it's usually pretty snappy. Every once in a while, we may have to reload something or have trouble putting in data, but this happens maybe once every couple of days or so, which is expected for how heavy we use it. For the most part, it's pretty smooth.
How are customer service and support?
I do not often communicate with the technical support of Splunk Cloud Platform. I've never communicated with their support.
Which solution did I use previously and why did I switch?
I did not use a different solution for the same use cases before Splunk Cloud Platform.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Cloud Platform; it was recommended.
What other advice do I have?
Once everything was set up better for me, Splunk Cloud Platform provides pretty good visibility into the different data we put into it. I would rate the visibility and ease at about a seven out of ten.
I measure that ease by looking at failure rates, how long it takes to update anything, and the UI and how easy it is. I am confident and happy with these metrics.
I would rate the scalability level of Splunk Cloud Platform at about an eight.
I have not used the zero-setup feature for AI models in Splunk Cloud Platform. We have not really integrated that feature at all.
I decided to go with Splunk Cloud Platform because it is an industry widely used platform. It was vetted by the US government as a right to use, and that compliance is needed for the work I do. It's a vetted, trusted platform to move and organize very sensitive data.
I believe there was some Splunk training through a link. I'm not sure if it was on the website, training, documentation, and videos and things on just best use cases and features. That was a little while ago, though.
The materials I felt were surface level, good-to-know information. They were helpful, but very basic.
It was a while ago, and that was just my impression of it back then. I'm not exactly sure if I would want them to provide more detailed information at this stage.
I don't deal with the pricing side of it. I wouldn't know how the subscription model impacts my financial planning for data platform investments.
I prefer native models in Splunk's environment. I prefer it because it keeps me in control more and keeps the data local.
This preference influences my data strategy because it'll allow us to be within our own environment, not have to obfuscate or change the way we would use a model that wasn't local to us. Instead of having to navigate around or omit or change details, we can upload what we need to and know that the data won't go past our service.
My overall rating for Splunk Cloud Platform is an eight out of ten.