
Overview
If you're looking for security and operational visibility across your AWS environment - including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more - then Splunk Cloud is the right solution for you. Organizations of all sizes leverage Splunk visibility with AWS agility to rapidly troubleshoot applications, ensure security and compliance, and monitor business-critical services in real-time. Splunk Cloud makes it easy to gain end-to-end visibility across your AWS and hybrid environment. Leverage Splunk Cloud with the free Splunk App for AWS to gain critical security, operational and cost optimization insight into your AWS deployment. Whether you're managing applications, infrastructure or a security operations center in the cloud, Splunk delivers Operational Intelligence for a real-time understanding of what's happening across your business and IT so you can make informed decisions. It's easy to get started - and remember - when choosing a product option, match your location and anticipated index volume per day. Splunk Cloud is now FedRAMP authorized: Moderate
Highlights
- Collect and index any machine-generated data from virtually any source or location in real time. Just point Splunk Cloud at your data, and it immediately starts collecting and indexing so you can start searching and analyzing.
- Splunk Cloud offers single-pane-of-glass visibility across on-premise Splunk Enterprise and Splunk Cloud deployments, enabling customers to deploy Splunk as software or SaaS according to their business requirements, while maintaining centralized visibility.
- Splunk Cloud includes support for Splunk apps and other content. Splunk apps deliver a targeted user experience for different roles, use cases and enterprise technologies. These apps can help you visualize data in new ways or provide pre-defined views of leading technologies such as Linux, Windows, VMware and more.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Splunk offers a variety of support options to help ensure your success.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Advanced ai-driven threat hunting has improved detection speed and streamlined investigations
What is our primary use case?
I was a consumer using Splunk Cloud Platform at that time. I have been familiar with Splunk Cloud Platform. I was a user of Splunk Cloud Platform and a customer also.
What is most valuable?
Splunk Cloud Platform is a data analysis tool that works on big data and unstructured data. What I appreciated about it is that Splunk data processing is very good. When I performed search and threat hunting on Splunk, I was very satisfied.
Splunk Cloud Platform supports AI automation and can empower analysts to use AI assistance and agentic playbooks to accelerate threat detection, investigation, and mean time to detect or mean time to respond.
Since Splunk already offers me an embedded AI solution, why would I go to any other AI solution? Splunk is helping us in the new era of AI.
What needs improvement?
There is always room for improvement. Splunk can improve because it is a very expensive product. Because of the cost, we do not have as many skilled resources for Splunk, which makes it very difficult to find a compatible resource to help us troubleshoot.
For how long have I used the solution?
I have worked with Splunk Cloud Platform for around 10 to 11 months.
What do I think about the stability of the solution?
Splunk Cloud Platform is a very vendor-diverse product. You can integrate almost anything around the infrastructure. It totally supports integration.
What do I think about the scalability of the solution?
Splunk Cloud Platform is currently the best option in the market if you have the capacity to pay what Splunk requires. If you are tight on budget, you can consider other options. With respect to price, Splunk is the best solution, but it is expensive.
When comparing it with LogRhythm, LogRhythm is for small organizations, but Splunk has financial considerations. Splunk has more advantages than LogRhythm when comparing from a financial perspective.
How are customer service and support?
Splunk Cloud Platform is currently owned by Cisco, and Cisco has very great support in my region.
Which solution did I use previously and why did I switch?
I was only using Splunk Cloud Platform.
How was the initial setup?
If you are planning to deploy Splunk Cloud Platform, there is a whole lot of architecture planning involved. You need to plan accordingly as per your infrastructure needs.
What about the implementation team?
I was on the technical side, and the finances were managed by the governance team. I cannot answer questions regarding the subscription model and pricing structure.
What was our ROI?
Splunk Cloud Platform is a Gartner leading product. Splunk is superior in comparison with any other SIEM.
What's my experience with pricing, setup cost, and licensing?
Splunk Cloud Platform is a Gartner leading product. Splunk is superior in comparison with any other SIEM.
Which other solutions did I evaluate?
Splunk Cloud Platform should be improved in certain aspects. In comparison with QRadar, QRadar has dedicated log sources, but Splunk does not have dedicated log sources. We can only sort the log sources from the IPs or hostnames. Splunk can do that, or if they do not do that, it will not affect anything, but it could be beneficial for a SOC analyst to specify the data source.
What other advice do I have?
I cannot suggest additional features that could improve the rating further. I gave this review a rating of 9.
Daily analytics have transformed how I monitor searches, alerts, and integrations at scale
What is our primary use case?
My use case for Splunk Cloud Platform involves working in an organization that provides a daily full dashboard showing daily searches, daily ingestion, daily alerts, and more.
What is most valuable?
I really appreciate the ingestion features of Splunk Cloud Platform, which allow us to ingest data in various ways such as through an HEC token or Splunk Heavy Forwarder. Creating dashboards is very easy; currently, they provide two ways: a drag-and-drop grid layout or the traditional coding method.
I find the search capabilities effective because SPL, Splunk Query Language, is very easy to use. They are currently providing SPL2 with AI enhancing features that make searching really easy.
I use the alerting mechanisms with Splunk queries, having created multiple alerts that can send emails or display in the dashboard, making the alerting mechanism very helpful.
In terms of visualization features, creating dashboards on Splunk Cloud Platform is really easy, especially with the grid platform for drag-and-drop. The dashboard analytics feature is very helpful and fun to use.
I would describe the impact of integrations with third-party tools as powerful. We use add-ons like AWS CloudWatch, and integrating with any app on Splunk Cloud Platform is very easy.
What needs improvement?
Splunk Cloud Platform has room for improvement because managing the architecture for a newcomer, such as an intern, can be hard. They could provide better documentation and videos to help with learning.
I find the documentation of Splunk Cloud Platform fine in what I have learned, but having more visual videos to accompany the documents would be helpful for learners.
For how long have I used the solution?
I have been using Splunk Cloud Platform for six months in my training as well as in production, learning about creating apps, creating custom commands, and creating dashboards and analytical capabilities.
What's my experience with pricing, setup cost, and licensing?
The pricing of Splunk Cloud Platform is a concern for me; it is very costly, making it hard for small to medium vendors to afford.
Splunk does not actually save resources for us because it only helps with security. We have to buy more computational power for advanced usage.
Which other solutions did I evaluate?
I compare Splunk Cloud Platform with others like CrowdStrike and NG-SIEMs. While they are similar, Splunk is really way ahead, providing everything required.
For small and middle-class organizations, I would not recommend Splunk Cloud Platform because there are cheaper tools available. However, I would recommend it for very large organizations.
What other advice do I have?
Time-wise, Splunk Cloud Platform does save me time because if I am ingesting daily 2TB of data, I create the dashboard one time, and it updates automatically, allowing me to do data analytics more easily. I would rate this product a 9.
Centralized monitoring has accelerated incident investigations and provides hybrid security visibility
What is our primary use case?
In my daily work as an SOC L1, my use cases involve using Splunk Cloud Platform primarily for centralized log management and real-time incident detection. It acts as our central nervous system for security data. We stream logs from our other tools such as Wazuh directly into Splunk Cloud Platform, and the biggest use case for us is the speed of investigation. When an alert comes in, I can search through a massive amount of data in seconds to trace exactly what happened. It helps us to visualize the attack chain and prioritize what actually needs attention.
What is most valuable?
The biggest thing I appreciate about Splunk Cloud Platform is the stability of this platform. It is always up, and I have never had to worry about maintenance or downtime interrupting my shift. Search performance is another huge advantage, allowing me to query massive data sets in seconds when I am hunting for a specific log.
Since we are using Splunk Cloud Platform, the initial deployment is easy because we do not have to deal with the back-end infrastructure, which is a huge relief. It is a true SaaS experience, so you are not spending time patching servers or worrying about hardware capability. For me as an L1, the deployment part is really about onboarding our data sources. Once you have the connector set up pulling the logs from device endpoints and other tools such as Wazuh, it is fairly smooth.
For me as an analyst, maintaining Splunk Cloud Platform is really about keeping the data pipeline healthy. My focus is on making sure our Universal Forwarders are pushing data properly from our endpoints or other tools. I also keep an eye on index health and manage our retention policies so we do not exceed our storage systems.
About the app ecosystem within Splunk Cloud Platform, instead of us having to spend hours or days manually figuring out how to parse logs or map them to a common information model such as CIM, we can usually grab the right app from Splunkbase, and it does the heavy lifting for us, normalizing the data so that when I run a search, the fields are already in a structured and searchable format. It saves me so much time in day-to-day investigations, and because I do not have to worry about whether the log format is broken, the app handles that translation.
About visibility within Splunk Cloud Platform, the hybrid visibility is actually one of its strongest points. Since we handle a mix of environments for our clients according to their requirements, being able to pull everything into one central place is critical for us. We use Universal Forwarders on our on-premises servers to securely stream logs up to the Splunk Cloud Platform instance. For me, it effectively erases the boundary between on-premises and cloud. It does not matter if the log is coming from a server in our local data center or a cloud-hosted app. It all lands in that same single pane of glass.
What needs improvement?
The biggest downside about Splunk Cloud Platform for me is the cost. It is definitely on the expensive side, and you have to be very careful about what you ingest from sources. We are always mindful of our log volume because if you are not constantly tuning your filters or managing what data goes in, the cost can add up fairly quickly.
What do I think about the scalability of the solution?
In terms of scalability, Splunk Cloud Platform is one of the things that makes my L1 task much easier. As we onboard more devices or increase our log ingestions and stay ahead of threats, I never have to worry about the platform hitting the wall. With Splunk Cloud Platform, it just handles it. I have noticed that even when we ramp up the data from other tools such as Wazuh or add new endpoints, the search speed remains really consistent. It does not get sluggish or slow down, which is huge when I am in the middle of an investigation.
How are customer service and support?
We have a team to contact for technical support for Splunk Cloud Platform. I have not really been involved in that technical support phase, and I do not have much knowledge about that process or what is going on in the background. I would give around an eight out of ten for technical support for Splunk Cloud Platform.
Which other solutions did I evaluate?
I have not currently used any alternatives to Splunk Cloud Platform. I have not gained hands-on experience with other cloud platforms.
What other advice do I have?
I would give Splunk Cloud Platform an 8.5 overall rating for everything. We are a customer of Splunk Cloud Platform.
Custom views and shared dashboards have improved how I organize and collaborate on sensitive data
What is our primary use case?
My usual use cases for Splunk Cloud Platform include data, data integration, and dashboards. I currently have three use cases.
What is most valuable?
I find the features and capabilities of Splunk Cloud Platform to be highly valuable because of how customizable it is for my view and the data we need to put into it. The ability to organize the data and set up different views is particularly useful.
I also appreciate how easy it is to work with coworkers on the platform to collaborate on the same issues.
The tangible benefits I've observed since starting with Splunk Cloud Platform are significant. It's pretty much the standard for what we use it for. If we're working with a consultant or we bring in someone new, most people know the platform or at least have been exposed to it. This exposure and the platform's big name and familiarity make it easy to direct people around in it, show them the data, and collaborate.
What needs improvement?
I'm not quite sure how Splunk Cloud Platform could be improved or enhanced. I would suggest keeping what works. Sometimes it can feel slightly slow in what it brings up, but I don't know if a lot of times that's on our end with the data that's getting in. Staying up to date with current trends and technologies will be good enough for me. It's already a good platform, and I wouldn't recommend too many changes or tweaks.
The major thing that could be optimized is the speed, so it could be a bit faster.
For how long have I used the solution?
I've been working with Splunk Cloud Platform for about three years.
What do I think about the stability of the solution?
Splunk Cloud Platform has been living up to my expectations regarding reliability and stability so far.
I think we rarely ever have Splunk Cloud Platform crash or error out where we're not able to bring up the site and access what we need to do in it. Usually, in the rare case that it does happen, it's usually back up within 20 to 30 minutes. Stability-wise, sometimes it'll get slow, but usually, if we are patient, it pulls up everything we need it to.
What do I think about the scalability of the solution?
I believe Splunk Cloud Platform scales pretty well. We use it for quite a bit of the data and things that we house and have coming in, and it's usually pretty snappy. Every once in a while, we may have to reload something or have trouble putting in data, but this happens maybe once every couple of days or so, which is expected for how heavy we use it. For the most part, it's pretty smooth.
How are customer service and support?
I do not often communicate with the technical support of Splunk Cloud Platform. I've never communicated with their support.
Which solution did I use previously and why did I switch?
I did not use a different solution for the same use cases before Splunk Cloud Platform.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Cloud Platform; it was recommended.
What other advice do I have?
Once everything was set up better for me, Splunk Cloud Platform provides pretty good visibility into the different data we put into it. I would rate the visibility and ease at about a seven out of ten.
I measure that ease by looking at failure rates, how long it takes to update anything, and the UI and how easy it is. I am confident and happy with these metrics.
I would rate the scalability level of Splunk Cloud Platform at about an eight.
I have not used the zero-setup feature for AI models in Splunk Cloud Platform. We have not really integrated that feature at all.
I decided to go with Splunk Cloud Platform because it is an industry widely used platform. It was vetted by the US government as a right to use, and that compliance is needed for the work I do. It's a vetted, trusted platform to move and organize very sensitive data.
I believe there was some Splunk training through a link. I'm not sure if it was on the website, training, documentation, and videos and things on just best use cases and features. That was a little while ago, though.
The materials I felt were surface level, good-to-know information. They were helpful, but very basic.
It was a while ago, and that was just my impression of it back then. I'm not exactly sure if I would want them to provide more detailed information at this stage.
I don't deal with the pricing side of it. I wouldn't know how the subscription model impacts my financial planning for data platform investments.
I prefer native models in Splunk's environment. I prefer it because it keeps me in control more and keeps the data local.
This preference influences my data strategy because it'll allow us to be within our own environment, not have to obfuscate or change the way we would use a model that wasn't local to us. Instead of having to navigate around or omit or change details, we can upload what we need to and know that the data won't go past our service.
My overall rating for Splunk Cloud Platform is an eight out of ten.
Unified log monitoring has reduced troubleshooting time and improves operational visibility
What is our primary use case?
The main use case is for logs monitoring to get a clear vision about all the products and all the services that we have. We are giving multiple APIs to multiple platforms, and we have multiple services to maintain everything. We have created multiple logs to identify what is the root cause, which is taking much higher CPU usage and everything.
What is most valuable?
The favorite feature of Splunk Cloud Platform is the infrastructure that has been provided to us, and the pricing that has been given to us is very low and very fit within our budget where we were looking at that point. The main feature is the reduction in time and manpower.
My thoughts about the overall app ecosystem in Splunk Cloud Platform are that it is very good. We don't have to think about where the error has occurred or where we have to solve it; we don't have to spend two to three hours just to find where the error is. It is very easy to get out of it.
What needs improvement?
The dislike about Splunk Cloud Platform is the learning resources and the learning materials that they have. In the starting of my phase with Splunk Cloud Platform, I was very new to this, and I was not able to understand each and everything. We don't have much of a resource from where we can learn things about Splunk Cloud Platform, but if there is a specific platform from where we can learn things from, it would be great if we get a platform to learn how we have to use it.
I would like to see better training material or something like that for Splunk Cloud Platform.
For how long have I used the solution?
I have been involved in Splunk Cloud Platform for the last six months, but our company has been using it for eight to nine months.
What do I think about the stability of the solution?
My thoughts on the stability of Splunk Cloud Platform, regarding lagging, crashing, and downtime, are that earlier we faced this issue on a very large scale of logs. However, because we were very new at that time, we didn't know much about things, but now we do. The things are not too tough for us anymore.
What do I think about the scalability of the solution?
Splunk Cloud Platform is very scalable. We are scaling right now in our multiple applications, and it is very scalable.
How are customer service and support?
We have contacted the technical support for Splunk Cloud Platform many times to get out of issues and have raised many issues with them. If I were to put the support of Splunk Cloud Platform on the scale from one to ten, I would give it a nine, because every time we are getting very decent support from them that is very reliable and very good.
Which solution did I use previously and why did I switch?
Earlier, we were using a 24/7 monitoring solution as an alternative to Splunk Cloud Platform. We had built our own dashboards with Python scripts and everything to manage each platform, with each platform having their individual platform in their domain with Python, and we created all that, but it was very messy to handle in the end.
How was the initial setup?
The initial deployment of Splunk Cloud Platform is difficult. It was difficult because we were very new to Splunk Cloud Platform and everything. Earlier we were thinking to buy DataDog, but then we skipped that and had an eye on Splunk Cloud Platform. It was tough to get to know about things at first, but now we are good at this and know more about it.
What about the implementation team?
Splunk Cloud Platform does not require any maintenance on my end. We have four applications where we have integrated this platform, and the last time I maintained it was around two to three months back. Once everything has been set in any particular area, we don't have to maintain it every time; it is very reliable.
What was our ROI?
The return on investment from Splunk Cloud Platform is substantial. I don't know how much investment is being put into it, but the return is very high and very good.
What's my experience with pricing, setup cost, and licensing?
I don't know much about the pricing of Splunk Cloud Platform, but I know that it is very less as compared to what we thought to manage this platform. It is very less, but I don't know the exact number; that is on the management side.
What other advice do I have?
In Splunk Cloud Platform, the updates and everything are very easy. We don't have to worry about any other things, so it is not that difficult; it is easy. Splunk Cloud Platform can handle their own problems.
Regarding AI models in Splunk Cloud Platform, I think we are not using any specific ones.
We have used the zero setup feature for AI models in Splunk Cloud Platform. Splunk Cloud Platform is giving us a Machine Learning Toolkit, MLTK, and we are now learning about it. We are also evolving our things on it, and it is good to know that it is helpful very much.
We are just a customer of Splunk Cloud Platform, not in any partnerships.
I would give Splunk Cloud Platform an overall score of 8.5 out of 10.