Listing Thumbnail

    Splunk Enterprise

     Info
    Sold by: Splunk 
    Deployed on AWS
    AWS Free Tier
    The Splunk Enterprise AMI accelerates the speed at which organizations deploy Splunk Enterprise in AWS..
    4.3

    Overview

    The Splunk Enterprise AMI accelerates the speed at which organizations deploy Splunk Enterprise in AWS. Splunk Enterprise is the leading platform for Operational Intelligence, delivering an easy, fast, and secure way to search, analyze and visualize the massive streams of machine data generated by your IT systems and technology infrastructure - physical, virtual and in the cloud. Use this AMI to take Splunk for a test drive, or as the basis for your Enterprise-level deployment. The Splunk Enterprise AMI ships with a fully-featured trial license that is valid for 60 days after launch. After the trial expires, your deployment will default to Splunk Free.

    Highlights

    • Collect and index any machine-generated data from virtually any source or location in real time. Just point Splunk Enterprise at your data, and it immediately starts collecting and indexing--so you can start searching and analyzing.
    • With Splunk Enterprise, you can correlate complex events spanning many diverse data sources across your environment. Types of correlations include time-based correlations, transaction-based correlations, sub-searches, lookups, and joins.
    • Splunk Enterprise scales to collect and index tens of terabytes of data per day. And because the insights from your data are mission critical, Splunk Enterprise's clustering technology provides the availability you need, even as you scale out your low-cost, distributed computing environment.

    Details

    Sold by

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    AmazonLinux 2023

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Splunk Enterprise

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    Refunds are not available

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    To learn what's new in Enterprise 10.4.3, please visit https://docs.splunk.com/Documentation/Splunk/10.4.3/ReleaseNotes/MeetSplunk 

    Additional details

    Usage instructions

    Get started with Splunk Web:

    • In your EC2 Management Console, find your instance running Splunk Enterprise.
    • Copy its public IP.
    • Paste the public IP into a new browser tab (do not hit enter yet).
    • Append :8000 to the end of the IP.
    • Hit enter.
    • Log into Splunk for the first time with the following credentials: ** username: admin ** password for Enterprise 7.2.5 and above: SPLUNK-$instance-id$ ** password for Enterprise 7.2.0 and below: $instance-id$

    Please modify the security groups to allow and disallow certain IP addresses per your requirements. The default is open to all IP addresses.

    Read more about the Splunk Enterprise AMI here: https://docs.splunk.com/Documentation/Splunk/latest/Admin/AbouttheSplunkAMI 

    Upgrade Instructions: http://docs.splunk.com/Documentation/Splunk/latest/Installation/HowtoupgradeSplunk 

    Resources

    Support

    Vendor support

    Options available

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Migration
    Top
    10
    In Data Anonymization, Data Security and Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Real-time Data Collection and Indexing
    Collects and indexes machine-generated data from virtually any source or location in real time with automatic indexing upon data ingestion
    Complex Event Correlation
    Correlates complex events spanning multiple diverse data sources using time-based correlations, transaction-based correlations, sub-searches, lookups, and joins
    High-Volume Data Processing
    Scales to collect and index tens of terabytes of data per day
    Clustering and High Availability
    Provides clustering technology for availability and fault tolerance across distributed computing environments
    Machine Data Search and Analysis
    Enables searching, analyzing, and visualizing machine-generated data streams from IT systems and technology infrastructure
    Real-time Data Collection and Indexing
    Collects and indexes machine-generated data from virtually any source or location in real time with automatic indexing upon data ingestion.
    Complex Event Correlation
    Correlates complex events spanning multiple diverse data sources using time-based correlations, transaction-based correlations, sub-searches, lookups, and joins.
    Scalable Data Processing
    Scales to collect and index tens of terabytes of data per day with distributed computing architecture.
    High Availability Clustering
    Provides clustering technology for availability and fault tolerance across distributed low-cost computing environments.
    Search and Analysis Capabilities
    Enables searching and analyzing of indexed machine data with visualization capabilities for operational intelligence.
    Data Routing and Destination Management
    Routes data to multiple destinations with capability to deliver specific data to targeted tools while archiving full fidelity data to cost-effective storage
    Data Optimization and Reduction
    Reduces data streams by up to 50% through removal of unused log and metric data
    Event Processing and Transformation
    Processes event data through centralized parsing with capabilities to route, optimize, reformat, and enrich data in flight
    Role-Based Access Control
    Implements role-based access control with support for external authentication via LDAP, Splunk, and OpenID Connect identity providers
    Real-Time Monitoring and Configuration
    Provides GUI-based configuration and testing interface with real-time capture and monitoring of observability pipeline

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.3
    533 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    57%
    36%
    5%
    1%
    1%
    37 AWS reviews
    |
    496 external reviews
    External reviews are from G2  and PeerSpot .
    Justim C

    Monitoring has reduced outages and provides live insight into video on demand success rates

    Reviewed on Sep 16, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Splunk Enterprise Platform is to monitor the video on demand success rate for our video platform.

    A specific example of how I use Splunk Enterprise Platform for monitoring the video on demand success rate is that we monitor the success rate of video on demand plays on different markets where customers will order a video on demand program that will play on their set-top box. We collect a lot of log data for that and if a video on demand session fails, it logs an alarm code that will be monitored through our Splunk Enterprise Platform dashboards. It allows us to show the successful setup rate. It gives us information on the user, their MAC address, so we can see if all of the failed attempts are from the same user or different users. It also shows us different markets and allows us to narrow in on what device it might have failed in on based on what alarm ID it flags.

    What is most valuable?

    The best features Splunk Enterprise Platform offers include the customization because the way we have our dashboards set up helps us identify anomalies or if we have something that is happening or if an issue is cleared or not.

    Regarding the customization aspect, we have it set up to graph the success rate over time, and the way the graph shows not only the success rate but failures on the same graph makes it easy to identify those anomalies. It will have a success rate line and then if there is a failure and the success rate line goes down, there is another line on the same graph that will show how many failures there were at that time.

    Splunk Enterprise Platform has positively impacted my organization by helping us reduce our outages through monitoring.

    Monitoring with Splunk Enterprise Platform has reduced outages for us because it is live data and that has allowed us to see trends in an area and anticipate if something is going to happen in a market that we need to get on top of.

    What needs improvement?

    I do not have any suggestions on how Splunk Enterprise Platform can be improved because I am happy with it.

    If I had to think of one area where Splunk Enterprise Platform could be better or easier to use, helpful hints maybe could be added where you hover over something and it gives you some ideas of what you can do for that feature.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for approximately five years.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is stable.

    What do I think about the scalability of the solution?

    Its scalability is easy.

    How are customer service and support?

    I have no complaints concerning customer support for Splunk Enterprise Platform.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution before Splunk Enterprise Platform in my department.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing is great; I just log in. I was given a login and that is how I worked it. I do not think my department dealt with any of that; that is a whole other department within our organization.

    What was our ROI?

    I would say we probably do benefit from having Splunk Enterprise Platform because we use it every day and they have expanded our use of it and they have even decided to migrate it into the cloud versus trying to use other open platform systems. We continue to use it, which would tell me that it has been beneficial.

    Which other solutions did I evaluate?

    Before choosing Splunk Enterprise Platform, I did not evaluate other options.

    What other advice do I have?

    My advice to others looking into using Splunk Enterprise Platform is to research the product and utilize all the support that Splunk provides. I have rated this review a ten out of ten.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2900028

    Centralized logs have transformed user behavior analysis and now speed up daily investigations

    Reviewed on Sep 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Splunk Enterprise Platform is as a log consolidation tool.

    In my day-to-day work, we receive email logs, web logs, and any kind of user activity logs, and we investigate based on anomalies in user activity.

    We initiated user behavior analysis, so we're looking for variations from a known baseline.

    What is most valuable?

    Splunk Enterprise Platform's best features include the ability to ingest data from any source without having to spend too much time getting the data into a set format.

    The flexibility in data ingestion makes ingesting new data sources very easy and very quick for our team, allowing us to have new data sources online within a couple of days.

    Splunk Enterprise Platform has positively impacted our organization by giving us insights into user behavior that we didn't have before, enabling us to track and monitor user activity that would otherwise have been missed.

    It has led to faster investigations, as typically, we can go from query to resolution within a day.

    What needs improvement?

    The ability to delete data is something I would suggest for improvement, as at the moment, you can delete data from search, but you can't delete data permanently, which is an issue sometimes.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for 15 years.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is stable.

    What do I think about the scalability of the solution?

    For our scale, Splunk Enterprise Platform's scalability is fine, as we have a relatively small license.

    How are customer service and support?

    Customer support for Splunk Enterprise Platform is good, but technical support is variable.

    I would rate customer support an eight on a scale of one to ten.

    Which solution did I use previously and why did I switch?

    We did not use a different solution before Splunk Enterprise Platform; this was our first.

    How was the initial setup?

    I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive.

    What was our ROI?

    I can't share any exact figures regarding return on investment, but we've had Splunk Enterprise Platform for 15 years, so I would say they're happy with their ROI.

    What's my experience with pricing, setup cost, and licensing?

    I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive.

    Which other solutions did I evaluate?

    I evaluated other options before choosing Splunk Enterprise Platform; I can't remember them all, but I think Elasticsearch was one of them.

    What other advice do I have?

    My advice to others looking into using Splunk Enterprise Platform is to make sure you have a defined use case you can measure against.

    Splunk Enterprise Platform is deployed on-premises in our organization.

    We don't have it at that scale, but I'm sure Splunk Enterprise Platform would work very well for managing data sovereignty at a petabyte scale within our environment.

    We don't use the trusted control plane, so I don't have experiences in maintaining granular control over data using it.

    We won't be using Splunk Enterprise Platform with any AI because of the client data we hold, which affects how we manage access to our operational data.

    My impression of Splunk Enterprise Platform's approach to managing governance within a private network environment is very good.

    The cost of it keeps it from being a perfect ten for me.

    For manual searches, we are very happy with the outputs of Splunk Enterprise Platform.

    I would rate this product an overall nine out of ten.

    reviewer2900010

    Centralized monitoring has improved cloud VM insights and supports proactive CPU management

    Reviewed on Sep 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Splunk Enterprise Platform is used primarily for our SOC and ingesting all metrics and data from all the virtual machines that we're running in our cloud environment.

    A specific example of how I use Splunk Enterprise Platform in my daily work is monitoring CPU usage for VMs, and if CPU credits run out on a burstable instance, we know to add more credits or reconsider how we're using that VM.

    What is most valuable?

    The latest best feature Splunk Enterprise Platform offers is probably MCP server, where people in the organization don't need to have knowledge of SPL and syntax; they can just query Splunk Enterprise Platform directly.

    MCP server has changed the way my team works and collaborates by democratizing the use of Splunk Enterprise Platform so we don't have to go to someone that knows how to use it; anybody can spin up the co-pilot agent and start querying.

    Splunk Enterprise Platform has positively impacted our organization by providing insight into our environment in a centralized manner so that we don't have to set up alerts in a bunch of different places; we just have to look at one place to get what we need.

    Splunk Enterprise Platform helped save time; we've had a few issues where VMs stopped responding and we had trouble figuring out what was going on, but we just went on Splunk Enterprise Platform and it was easy to see the data there.

    What needs improvement?

    Splunk Enterprise Platform can improve by taking more positive steps towards user-friendliness so that more people can access it without having to go through a bunch of training to learn how to use it.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for about a year and a half.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is stable.

    What do I think about the scalability of the solution?

    Splunk Enterprise Platform's scalability is very good; we can just start plugging in indexes as we need.

    How are customer service and support?

    The customer support has been acceptable; we had an issue that we thought should be easily solvable or something that works out of the box, but it didn't.

    Which solution did I use previously and why did I switch?

    I previously used Microsoft Sentinel and switched because we had more places we needed to ingest data from.

    What was our ROI?

    I have not seen a return on investment and think we have some internal issues; we really just got Splunk Enterprise Platform for our SOC.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing has been fairly straightforward; the partner we had to help us set up was pretty good.

    What other advice do I have?

    I cannot comment on Splunk Enterprise Platform's capability to manage data sovereignty at a petabyte scale within my environment because we're not at that level.

    We haven't been using Splunk Enterprise Platform's federated search for querying data in place, so there hasn't been much evolution or primary drivers for either expanding or limiting its use.

    I have no experience in maintaining granular control over data using the trusted control plane within Splunk Enterprise Platform; we don't use it much.

    I learned a lot at this conference about how we can manage access to our operational data through Splunk Enterprise Platform; we're not quite at that level, but once we are, then I'll have more feedback.

    I don't think we use the feature to track specific metrics to evaluate the success of reducing TCO with Splunk Enterprise Platform's non-indexing analytics approach.

    My advice to others looking into using Splunk Enterprise Platform is to start small; ingest a little bit of data that you can start to see returns on right away, and then expand from there as you learn how it works. My overall review rating for Splunk Enterprise Platform is eight out of ten.

    reviewer2899623

    Log investigations have become faster and data now clearly supports executive decisions

    Reviewed on Sep 16, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I use Splunk Enterprise Platform for log aggregation, data validation, sifting through network connections, building out dashboards, using the dashboards and putting them in Excel to then present to executive people who may not understand the granular details of network connectivity or log ingestion.

    In one example, I was investigating some traffic where we were getting hit on one of our servers and we were trying to see where it was coming from and if our managed rule set was working properly as we configured it. Navigating to Splunk Enterprise Platform, I was able to query for all the traffic coming from the nefarious IPs and also grab the locations of where they were going, where they were coming from, and if they were blocked or not. From that, I exported that data into an Excel sheet and used that to build bar charts or pie charts to present to executive leadership on what was going on.

    I think it is a great additive to being in the cloud. As I mentioned, we are an AWS shop. Having Splunk Enterprise Platform has made our lives easier because outside of being engineers, we are all still the analysts as well. We still do all of the investigative work and log analysis. Splunk Enterprise Platform makes it very easy for us to parse and grab data that we would need in a given investigation. I am really happy with the product.

    What is most valuable?

    The best features for me include recently starting to mess with creating bar charts and pie charts within Splunk Enterprise Platform console versus exporting the data and then doing it in Excel. That has been very beneficial to me, having a one-stop shop for things of that nature.

    It has given us, from an engineering perspective, the ability and the scalability to move at haste when it is time to investigate different alerts that we need to triage. Things that may be false positive or true positive, we are able to delineate really fast, and also gather important data for those C-suite folks who may need the type of data to support KPIs and things of that nature.

    What needs improvement?

    Perhaps the interface could be improved. The console has been the same since I first started using it. The dashboard could be changed around and features could be upgraded, but as far as the functionality and the usability of Splunk Enterprise Platform in general, I do not have any negative things to say about it.

    For how long have I used the solution?

    I have been using it for about six years at this point.

    What other advice do I have?

    I think there are always challenges to some things that you learn to build out. It was not anything technical, it was just learning how to manipulate the dashboards and manipulate the data to perform or show how you wanted it to show. Once you figure that out, you can make it as expansive as you would want to.

    I would say around AI, everyone needs to improve their governance and security. As great as AI is, it is also scary. While I as the engineer do enjoy having an agentic friend helping me out and making things more efficient, guardrails are still needed to be implemented as we move further into this agentic space.

    I think they are pretty accurate. I have not had any issues at this point, but as we go and continue to do our research and due diligence, I am sure things will get better.

    Continue doing the homework, continue researching, continue using the tool to the best of its capabilities, and building out your data sets as you see fit. I would rate this product a nine out of ten.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Carlos Ciscaoor

    Centralized monitoring has provided full visibility and simplified audits for our on-premise network

    Reviewed on Sep 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Splunk Enterprise Platform is gaining insights, visibility, and maintenance for on-premise infrastructure.

    For insights, visibility, or maintenance, we have a Splunk forwarder on all of our Windows servers, desktop endpoints, Linux servers, and we collect Cisco switch IOS data. For our CCRI, we are required to collect logs from all those devices. Thanks to Splunk Enterprise Platform and SPL, I was able to write queries that would prove that all of our devices were online, checking in, and reporting. I was also able to show us what is actively online at any given time.

    What is most valuable?

    The best features Splunk Enterprise Platform offers include a robust environment and platform for all the various devices on the network, an easy ability to update, a great support team from Splunk, which helps us stay on track and expand our functionality, and an ecosystem with so many options to improve visibility of durability and everything else.

    The feature I rely on the most or find the most valuable in my day-to-day work is the ability to keep eyes and ears on our network and be able to search for any events that need attention and make sure the network and all the devices are online.

    Splunk Enterprise Platform positively impacts my organization by helping us keep all of our devices online and healthy and helped us prove we meet the requirements for the CCRI audit.

    What needs improvement?

    When we had a consultant come on site, they installed a bunch of apps, and some of those did not work. In order to go back and clean everything up, we have to go into the back end. It would be helpful if there were a way to look into the installed apps, which ones are being used, and which ones are not being used.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for two years.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform has experienced stability issues.

    What do I think about the scalability of the solution?

    Splunk Enterprise Platform's scalability for my needs is very good. It scales extremely easily because of our distributed environment and our deployment server, we can expand as needed very easily.

    How are customer service and support?

    The customer support is second to none. It is some of the best customer support I have experienced in the IT world in 20 years.

    What about the implementation team?

    Because Splunk Enterprise Platform is such a solid product, we only have two admins. One of them is a Linux administrator, which manages the back end, and then there is me, which is the Splunk admin, which is responsible for searches, dashboards, and setting up alerts. We have been able to keep a small team of only two people and have complete oversight over our network and all of our devices.

    What was our ROI?

    Because Splunk Enterprise Platform is such a solid product, we only have two admins. One of them is a Linux administrator, which manages the back end, and then there is me, which is the Splunk admin, which is responsible for searches, dashboards, and setting up alerts. We have been able to keep a small team of only two people and have complete oversight over our network and all of our devices.

    What other advice do I have?

    Regarding Splunk Enterprise Platform's AI capabilities, we have not used it because it is on classified systems, which are air-gapped networks.

    I have not used Federated Search.

    In maintaining granular control over data using the Trusted Control Plane within Splunk Enterprise Platform, we have a few users from cybersecurity who have everything under the Power User role, and then we have admins. That is all.

    Regarding Splunk Enterprise Platform's approach to managing governance within a private network environment, we use mostly business process as opposed to the technology, so we have not explored that yet, and I would be actually interested in learning about it.

    The advice I would give to others looking into using Splunk Enterprise Platform is to understand that it is closer to a marathon than a sprint. If you are new to Splunk Enterprise Platform, it will take a little time to wrap your head around it and understand it. The value is there and your skills will grow over time, and you should contribute time every day or every week to learning and expanding your knowledge in Splunk Enterprise Platform. It is an excellent product.

    The people in the Splunk world have been awesome. The conference is awesome. Splunk Enterprise Platform is awesome, and the value is awesome. I would rate this review a 9.

    View all reviews