MDR provides comprehensive security coverage, but many businesses require additional cloud-native incident response, deep digital forensics, or legal testimony support that falls outside the scope and capabilities of MDR. BlueVoyant offers our DFIR for MDR for Splunk.
BlueVoyant's Digital Forensics and Incident Response for MDR for Splunk Cloud and Splunk Enterprise
Highlights
DFIR raises security and response capabilities by halting a broader range of sophisticated threats that occur beyond the scope of MDR
Combining MDR with DFIR makes overall services simpler and transparent, requiring fewer resources to achieve more desired outcomes and the highest security posture available.
It helps ensure those incidents will not happen again and includes forensics, incident response, and legal and compliance support
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one contract dimension covering managed detection and response (MDR) plus digital forensics and incident response (DFIR). Pricing is based on the number of protected endpoints. You start at a 600-endpoint minimum, and this pricing tier covers up to 750 endpoints. Costs scale with the count of endpoints you enroll rather than usage or hourly metering. To protect more than 750 endpoints, you would move beyond this tier. This single bundled option combines round-the-clock threat monitoring with incident investigation and response support.
Top-of-mind questions for buyers
What counts as one endpoint for billing under this contract?
An endpoint is a monitored device the service protects, such as a server, laptop, or workstation. You are billed on the number of endpoints you enroll. This tier requires a 600-endpoint minimum and covers up to 750 endpoints.
What happens if my endpoint count exceeds 750?
This contract tier covers up to 750 endpoints. If you need to protect more than 750, you move beyond this tier's ceiling. To arrange coverage for a larger count, contact the vendor to discuss the appropriate pricing tier.
Is this priced on device count or on actual usage and hours?
Cost is based on the number of enrolled endpoints, not on usage volume or hourly metering. You commit to a tier covering a defined endpoint range. The bill stays tied to the endpoint count within that range rather than fluctuating with activity.
www.bluevoyant.com+1
Helpful?
Vendor refund policy
No Refunds
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
The official Splunk remote MCP server is built to help you unlock data potential in Splunk Cloud Platform with the AI and Agentic tools of your choice. Seamlessly integrate advanced analytics and intelligent automation to gain deeper insights, enhance operational efficiency, and drive informed decisions. Leverage a trusted, Splunk supported solution designed for optimal performance and unparalleled data utilization within your Splunk Cloud Platform environment. Rest assured, your data remains safe and secure, with robust controls honoring your existing Role Based Access Control (RBAC) policies. Maximize your data's impact with cutting edge AI and flexible agentic capabilities.
Attackers are everywhere. With Managed Threat Complete (MTC), so are you. With Rapid7 Managed Threat Complete, you have round the clock monitoring,
triage, investigation and hunts. You have command of your attack surface by
understanding what risk should be remediated first, and a team of experts on your side should a breach occur. It is the most complete MDR on the market.
Arctic Wolf Managed Detection and Response (MDR) provides 24x7 monitoring of your networks, endpoints, and cloud environments to help you detect, respond, and recover from modern cyber attacks.
Check Point Services Managed Detection and Response (MDR) for Workspace) provides 24/7 monitoring across endpoint and email environments. The service includes expert monitoring, investigation, and response support, along with broad integration capabilities that enhance visibility and operational resilience.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.