We use Splunk Cloud Platform to ingest data from on-prem environments. Most people have Splunk Enterprise Security running on a server, but Splunk developed the Splunk Cloud Platform to ingest the data into the cloud. It works like Splunk Enterprise, but you must download apps to get some features. Our clients are mostly large enterprises in the financial industry.
System engineer at Agile Cloud Ltd
It improves our visibility and decision-making while helping us meet compliance standards
Pros and Cons
- "The Cloud Platform interface is cleaner than Splunk Enterprise's monitoring console. You can easily understand what's happening with your indexes. It's more refined than Splunk Enterprise's console, but they have the same feel and function."
- "The only disadvantage of Splunk Cloud compared to Splunk Enterprise Security is that you only have two options for long-term storage: AWS S3 Buckets and GCP."
What is our primary use case?
How has it helped my organization?
Splunk Cloud Platform improves our visibility and decision-making. Splunk helps us meet compliance standards. It's certified for multiple standards, such as PCI, GDPR, and HIPAA.
What is most valuable?
The Cloud Platform interface is cleaner than Splunk Enterprise's monitoring console. You can easily understand what's happening with your indexes. It's more refined than Splunk Enterprise's console, but they have the same feel and function.
It's easy to monitor multiple cloud environments because you can create custom dashboards for any use case you may have. It offers good visibility because it integrates with the ITSI app, providing a clear overview of your environment.
Integrating Splunk with other components on the cloud and network resources is effortless because it can collect data from various sources, including stored data from long-term storage.
Splunk's reporting offers a good visualization of your data. You can visualize the statistics based on your searches. It produces some helpful graphs that enable you to easily compare what's happening in your search. It's very comprehensive.
What needs improvement?
The only disadvantage of Splunk Cloud compared to Splunk Enterprise Security is that you only have two options for long-term storage: AWS S3 Buckets and GCP.
Buyer's Guide
Splunk Cloud Platform
August 2026
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,564 professionals have used our research since 2012.
For how long have I used the solution?
We started using Splunk Cloud Platform in January 2024, so it has only been a few months.
What do I think about the stability of the solution?
I rate Splunk Cloud 10 out of 10 for stability. Okay. Splunk is trying to push more people to the cloud, so they've made it really stable.
What do I think about the scalability of the solution?
I rate Splunk 10 out of 10 for scalability. Scalability depends on whether your on-prem deployment is stable and deployed properly, as the Splunk Cloud Platform is an extension of Splunk Enterprise Security. It's easy to build another use case. or add servers, so I feel it's highly scalable.
How are customer service and support?
I rate Splunk support nine out of 10. We provide frontline support to our clients, but we periodically pass them on to the vendor.
Which solution did I use previously and why did I switch?
We previously used IBM and Fortinet. We prefer Splunk because of its integration. You can integrate multiple solutions and customize it for your environment depending on your use case.
How was the initial setup?
Deploying Splunk Cloud Platform is pretty straightforward once you have the enterprise environment set up on-prem. You download the cloud app and extension. The deployment time depends on the size of your environment. It takes about a day for a small environment. A large-scale deployment can take up to a week if you have multiple tiers and a disaster-recovery site.
After deployment, the product requires continuous engagement with the Splunk team. You must continue to fine-tune it to ensure everything runs smoothly. However, there isn't much maintenance once it is tuned and deployed properly.
What's my experience with pricing, setup cost, and licensing?
Splunk is a bit more expensive than some solutions, but customers can derive more value from it due to the features it has.
What other advice do I have?
I rate Splunk Cloud Platform nine out of 10. I recommend ingesting data into the cloud if possible. Even if you have an on-prem environment, it still helps to ingest data into the cloud.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Project Engineer at Wipro Limited
Offers alert scheduling, dashboard creation, and log monitoring
Pros and Cons
- "It is a stable product."
What is our primary use case?
My primary use case is for monitoring security logs and system logs. Apart from that, we create monitoring alerts and dashboards.
We also use it for Splunk application configuration, troubleshooting, and server patching. We have many other operations.
How has it helped my organization?
Integration with other systems and applications in the environment is easy. For example, we have Fortinet analyzer. We have to pull the logs from network devices into Splunk. We use Cribl pipeline.
For Cribl pipeline, we get that data to the Splunk syslog servers. From Splunk syslog servers, we're getting it into the indexes.
According to the license, suppose we have to onboard thousands of servers. Suppose a scenario, for thousands of servers, the user or client requires only specific events. So for that, we use props and cons and regex for specific events. And only specific events will be calculated in the license. That will consume the license also.
What is most valuable?
The incident response time depends on the query and alert configuration, and also on the environment and how the logs are streamed. By analyzing these factors, it takes a maximum of one to two days for one incident.
Alert scheduling, dashboard creation, and log monitoring are the most valuable features.
Federated search depends on the data we pull. We have three types of searches. We use federated search for long-running queries.
We have, like, 20% of MacBook Cloud environment. It is easy to monitor multiple cloud environments, but there are some onboarding challenges. We are onboarding from the back end and also using Hacktoken. Apart from that, we get data to Splunk using Cripple pipelines from Syslog servers.
Reporting is like this: if critical data is used by the client, we send it to the data user according to the schedule.
For log monitoring, we can definitely suggest Splunk is a good tool. And it helps with decision making processes.
For monitoring security logs, it's the best tool.
For how long have I used the solution?
I use Splunk Cloud. Previously, I used Splunk Enterprise, but after that, we migrated to Splunk Cloud.
I have been using Splunk Cloud for more than three years.
What do I think about the stability of the solution?
It is a stable product. Right now, we are migrating from Datadog to Splunk, so I guess that's why Splunk is better than other tools.
How was the initial setup?
It's deployed across multiple locations.
It does require maintenance. It depends on what Splunk vendor is being used.
What's my experience with pricing, setup cost, and licensing?
The pricing depends on the logs and how many logs we monitor. On a daily basis, it depends on the events. Those licenses will be calculated in Splunk Cloud.
What other advice do I have?
Overall, I would rate the solution a seven out of ten, with ten being best.
All the features for log monitoring, security, alerting, indexing of the data, parsing of the data are good. That feature makes sense and is helpful to everyone.
I would recommend it to others.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Cloud Platform
August 2026
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,564 professionals have used our research since 2012.
Data Engineering Senior Analyst at Accenture
Speeds up our response and reduces the time we spend manually monitoring any logs for ticketing tools or servers
Pros and Cons
- "Splunk has sped up our response and reduced the time we spend manually monitoring any logs for ticketing tools or servers. It saves us around two hours daily."
- "Every time they launch new versions, we experience a few bugs. The most recent version had a couple of bugs in the databases. We contacted the vendor and got assistance solving these bugs, so the environment is more stable."
What is our primary use case?
We use Splunk Cloud for monitoring various ticketing tools, servers, applications, URLs, and client transactions. We're monitoring the transactions and data flow.
How has it helped my organization?
Splunk has sped up our response and reduced the time we spend manually monitoring any logs for ticketing tools or servers. It saves us around 2 hours daily.
What is most valuable?
We can onboard multiple data types for monitoring from various ports and use Splunk to monitor laptops or other devices directly. If everything is stored in our database, we can also monitor that and see who is logging in and when. You can monitor which files are being used most and which ones aren't. We can also check for any fraudulent activity in the system. The reporting is highly detailed.
Splunk is best when used for real-time monitoring. We can use AI and machine learning, too. Splunk plans to launch new observability features soon. The federated search feature has helped us eliminate redundancy in data servers and discontinue servers that aren't being used much. We can remove those servers from the environment to cut costs.
We can use Splunk to monitor multiple environments. The ease of monitoring depends on the source, application, or cloud environment size.
What needs improvement?
Sometimes, integrating with other systems is difficult, and it isn't feasible to connect with other applications, but it's easy most of the time. I rate Splunk 7 out of 10 for its ability to integrate with other systems.
Every time they launch new versions, we experience a few bugs. The most recent version had a couple of bugs in the databases. We contacted the vendor and got assistance solving these bugs, so the environment is more stable.
For how long have I used the solution?
I have used Splunk Cloud for 4 years.
What do I think about the stability of the solution?
I rate Splunk 8 out of 10 for stability. It has some bugs, but that is common in any product. At least, Splunk resolves bugs quickly.
What do I think about the scalability of the solution?
Splunk's scalability is nice.
How are customer service and support?
I rate Splunk's technical support 9 out of 10.
How would you rate customer service and support?
Positive
How was the initial setup?
Splunk is easy to deploy. We have it deployed across data centers at multiple locations. Splunk requires some maintenance after deployment.
What's my experience with pricing, setup cost, and licensing?
Splunk is a bit pricey, but it's reasonable for the features offered.
What other advice do I have?
I rate Splunk Cloud Platform 8 out of 10. I would definitely recommend Splunk to others.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner/customer
Senior Manager Ict & Innovations at Bangalore International Airport Limited
Boosts performance and helps simplify monitoring across platforms and data management
Pros and Cons
- "The data management and instant search features are the most valuable ones for us, as they allow us to instantly retrieve information needed for reports and security compliance."
- "Splunk should increase the frequency of new feature releases, particularly those related to real-time operational flow monitoring and analytics reporting."
What is our primary use case?
We leverage the Splunk Cloud Platform to effectively manage the vast amounts of machine-generated data, thereby ensuring application management security compliance.
We implemented the Splunk Cloud Platform to enhance our customer experience and optimize the data storage costs. We can convert the log data into numerical data points when requested.
How has it helped my organization?
The Federated search helps retrieve data in a better way.
Splunk Cloud Platform simplifies monitoring across multiple cloud environments, providing real-time insights into operational flow. It also streamlines data conversion, reducing the data-driven process for the company.
Splunk Cloud Platform's machine learning and AI capabilities simplify data management and provide clear visibility into multiple environments.
The AI makes it easy to integrate with other systems and applications in our environment.
The Splunk Cloud Platform reporting provides good insight.
Splunk Cloud Platform significantly boosted our performance and cost-effectively optimized data sets, delivering immediate benefits.
Thanks to the Splunk Cloud Platform we can make decisions within the organization much faster.
Splunk Cloud Platform empowers our organization to access data efficiently, ensuring compliance with privacy and regulations through actionable insights.
Splunk Cloud Platform strengthens our security, particularly in handling complex processes.
What is most valuable?
The data management and instant search features are the most valuable ones for us, as they allow us to instantly retrieve information needed for reports and security compliance.
What needs improvement?
Splunk should increase the frequency of new feature releases, particularly those related to real-time operational flow monitoring and analytics reporting. It has been over a year since any significant updates were added to the Splunk Cloud Platform.
For how long have I used the solution?
I have been using the Splunk Cloud Platform for one year.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Splunk Cloud Platform is scalable.
Splunk Cloud Platform's resilience is good.
How was the initial setup?
The initial deployment was straightforward. The deployment took around four hours and required two people.
Which other solutions did I evaluate?
We evaluated Victoria Experience but it was not suitable for our environment.
What other advice do I have?
I would rate Splunk Cloud Platform an eight out of ten.
We have around 150 users.
No maintenance is required from our end.
I recommend Splunk Cloud Platform. It helps monitor all the respective functions.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Delivery Manager at a tech services company with 1,001-5,000 employees
A stable solution that can be used for security log monitoring and compliance
Pros and Cons
- "The most valuable feature of Splunk Cloud Platform is its flexibility and readiness because it's already prebuilt, and everything is click-to-go."
- "Splunk Cloud Platform should improve its integrations and consider multiple integrations or direct integration with other platforms like Microsoft Azure, Google Cloud, or AWS."
What is our primary use case?
The primary use cases of Splunk Cloud Platform are security log monitoring and compliance.
What is most valuable?
The most valuable feature of Splunk Cloud Platform is its flexibility and readiness because it's already prebuilt, and everything is click-to-go. Splunk has multiple features, but the cloud feature comes with that. It is built for a smaller organization, but that's how organizations grow. The solution is good for a new budding organizational group.
What needs improvement?
Splunk Cloud Platform should improve its integrations and consider multiple integrations or direct integration with other platforms like Microsoft Azure, Google Cloud, or AWS.
I would like to see more integrations because integration is related to bringing in more data. More integrations would increase the visibility and customer's point of scope. Customers are initially tied to one platform and stick to it because of its feasibility. Integration becomes a major challenge when they want to bring in different solutions.
Once they have different integrations from Splunk, they need not worry about security, things to monitor, or what compliance they must meet. Everything will be physical, and integration will bring in a lot of things.
For how long have I used the solution?
I have been working with Splunk Cloud Platform for one and a half years.
What do I think about the stability of the solution?
Splunk Cloud Platform is a stable solution.
How are customer service and support?
Splunk Cloud Platform's technical support is good. The support's technical capabilities are always great because everyone who is capable joins in and contributes. However, at a high level, we understand there is always a gap in automation. We have process automation that can be resolved or detected by customers.
The flaws in our cloud can be fixed. We can send an integration update to the customer and tell them that you must fix this so everything works fine. For a download-compatible system, you can update an older heavy forwarder version to a newer version to grasp the maximum out of it.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have worked with a lot of other products, but not as a cloud solution. I have designed cloud solutions for other products like what Splunk currently has. I have worked with IBM, which has its own cloud platform, cloud monitoring solutions, and security solutions. Similarly, we have other market solutions that will act as a security solution, but they are in different behaviors. We have designed one for other customers, which monitors other cloud and hybrid solutions.
Splunk is currently at the top rating because I haven't explored other ones. I started exploring Microsoft Sentinel, which is a good competition for the Splunk Cloud Platform, and it's a healthy competition. I would like to see a very light-flavored source solution integrated with the Splunk Cloud. Once people start tasting source solutions, they will surely explore them more because that's how hunger is created. Other solutions already have the source solution in them. For example, Sentinel has its own source solution, which they give as an integrated part.
How was the initial setup?
Splunk Cloud Platform’s initial setup was quite easy.
What about the implementation team?
The Splunk team was involved in the solution's deployment.
What's my experience with pricing, setup cost, and licensing?
Splunk Cloud Platform's pricing is a little on the higher end. When smaller organizations start their journey of onboarding log sources or security solutions, they think Splunk is quite worth it. But when they start growing, they feel it's quite eating up their budget on security. So, it is fine for smaller organizations. It all depends on how the discounts are provided.
What other advice do I have?
Splunk Cloud Platform is used in our customer's company. The solution is deployed on the Spunk Cloud in our organization.
Splunk Cloud Platform is a very good product in the market, and you can use it wisely. Compared to other products for the cloud solution, you can use Splunk Cloud Platform for a wide range of tools. Splunk Cloud Platform is the best product to onboard for a new startup or a working good industry with a very small number of people. You don't have to sit in an office and work. You can work it from anywhere and integrate the log sources. That's how easy it is.
The cloud is not for a bigger organization. The one which is sitting in the environment can be used. For example, if you have one terabyte of ingestion per day, that is not what we expect a bigger organization to ingest on a cloud. It would become quite expensive to store, manage, and process.
It is good for smaller organizations because they have around 25, 30, or 100 GB of ingestion per day. If you want to grow bigger and bigger, you can use a hybrid model. If that model is available, that would be great for bigger organizations. For example, the cloud is integrated into the cloud, and on-premise is integrated into data centers. That should work fine.
Splunk does the solution's maintenance. From our side, the local integration material has to be maintained as per the cloud instance. It all depends on the customer. If the customer is fully on the cloud, it should not be a problem. We still have to upgrade heavy forwarders, universal forwarders, and deployment servers. However, the rest is taken care of by Splunk itself.
Our customers monitor multiple cloud environments, which are distinguished in their environment. It is integrated in a different format and not directly integrated. Monitoring multiple cloud environments using the Splunk Cloud Platform’s dashboards is quite easy and reliable.
It's a standard thing. I don't know about other comparative tools, but the first time I used Splunk Cloud Platform, it was quite good enough and can be used for the current organization.
I rate Splunk Cloud Platform's integration with other systems and applications in our environment a seven to eight. This is an average rating where you can see that the growth still has to be achieved. Splunk Cloud Platform should work on its integration with third-party products.
Splunk Cloud Platform has different types of formats, and those are enough. The rest of the reporting, like the presentation, should be done by itself. No one gives those. The reporting that Splunk Cloud Platform currently provides is enough.
It depends on the industry, but for financial or banking industries, Splunk Cloud Platform plays a major role in decision-making. If I want to rate it, you have to consider ten out of ten as Splunk or any other tool before they make any decision. If they have Splunk already, they should consider Splunk as a major partner to integrate and bring in more services apart from bringing any other solutions. That will create a multiple-glass observation, which will not be an easy decision. If one of our customers has Splunk, they must consider it a priority before bringing in any other solution.
Splunk Cloud Platform helps our organization access data for compliance and privacy regulations. Right now, Splunk is so feasible that it can integrate with any tool, anytime, and in any data format. So, it should not be a problem. Anyone brings in data in any format, Splunk Cloud Platform will surely meet it. The only thing is they need a good engineer to design it properly so that it brings in data properly.
An organization that does not have a security posture review is considered a zero, not a negative. We don't know when it becomes negative. The day they bring Splunk into the environment, it will obviously increase their visibility. Every time the security posture increases, they get to know the flaws.
Their observation of 24/7 monitoring, compliance, log monitoring, and forensics will come into the picture. They can enable everything in a single solution or product.
Splunk Cloud Platform is a resilient model. SIEM tools can perform post-detection. SIEM is not an EDR tool because it doesn't automatically detect something. A SIEM tool is used for compliance and audit. It is helpful for future investigation because it can record logs and keep them aside.
However, a SIEM tool does not have an automatic detection module. Although it has a prediction model, it does not have an auto-detection or blocking model. It cannot be a resilient tool, but it can be a vigilant tool.
Overall, I rate Splunk Cloud Platform a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr Manager at a financial services firm with 10,001+ employees
Reduces troubleshooting time and improves customer experience
Pros and Cons
- "It has end-to-end visibility into our cloud-native environment, which is pretty important for us. About 80% of our infrastructure is on AWS."
- "They can offer more self-service capability to their customers. Currently, most of the things happen behind the Splunk Cloud Platform. As a customer, I do not have an opportunity to see my platform. If they can offer more self-service to see the health of my endpoints and stack, it would be appreciated."
What is our primary use case?
We use it for security monitoring and application monitoring.
How has it helped my organization?
We monitor multiple cloud environments. We monitor AWS and Oracle Cloud. It is easy to get all the data into Splunk from our AWS and Oracle Cloud. The integration is comparatively easy when it comes to on-prem versus Splunk Cloud.
It has end-to-end visibility into our cloud-native environment, which is pretty important for us. About 80% of our infrastructure is on AWS. It is pretty important for our digital resiliency to monitor our AWS and Oracle Cloud platforms end to end.
It definitely reduces our mean time to resolve, but I am not sure exactly how much time it has reduced because as a Splunk Cloud customer, we provide our platform to our application teams.
What is most valuable?
We have Splunk Enterprise Security and our regular Splunk Enterprise. We use Splunk Enterprise Security for monitoring all our security use cases and our regular Splunk Enterprise for application monitoring. We have our own custom digital apps that we monitor on the enterprise cloud, and all our enterprise security monitoring happens on the Splunk Enterprise Security app. There are so many custom applications that we currently support.
We do digital transaction monitoring, so when a customer sends some money to a different customer, we monitor the end-to-end transaction of that customer when it happens on the digital platform. It is pretty important for our L1 and L2 teams to monitor that end-to-end transaction.
With Splunk in place, we can identify the bottlenecks where transactions are getting held and immediately take necessary actions to release the transaction and reach the customer. That improves the transaction time frame. There is improvement in terms of how many analysts are monitoring how many transactions and how fast transactions are happening from end to end. It improves our performance and customer experience. It is also easy to monitor end to end transactions.
What needs improvement?
They can offer more self-service capability to their customers. Currently, most of the things happen behind the Splunk Cloud Platform. As a customer, I do not have an opportunity to see my platform. If they can offer more self-service to see the health of my endpoints and stack, it would be appreciated.
Their support also needs improvement. I have had issues with the support team. When I run into issues, it is always hard to get hold of them and get things done with the support team. Other than that, product-wise, it is very good.
For how long have I used the solution?
I have been using the Splunk Cloud Platform for more than four years.
What do I think about the stability of the solution?
Its stability is 99.5%, but I have had pretty bad incidents in the last couple of years. Last month, we had an outage for the whole day. Support-wise, I am not happy.
What do I think about the scalability of the solution?
In typical cloud infrastructure, you can add your EC2 on demand based on the load of your customers, but with the Splunk Cloud, that is not the case. They assign a fixed number of searches and indexes. They have named it as a cloud, but it is still an on-prem instance sitting in their cloud, so in terms of scalability, I do not see much advantage with Splunk Cloud because, at the end of the day, you get approval from your Splunk account team or a management team to add a new instance into your cluster.
How are customer service and support?
The support that we get from Splunk is not always great. Whenever we have issues, we have to chase them to get the answers. When we have an incident, identifying the root cause of that incident with the Splunk Cloud support team is always a pain. The Splunk team should improve their customer support experience. I love the product, but the only issue is getting support. I would rate them a three out of ten.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
We had IBM QRadar, and we moved from IBM QRadar to Splunk Cloud. Cost-wise, Splunk is a premium solution. We pay more, but we get a better experience with Splunk Cloud Platform. It is easy to manage. There is a better user experience. When it comes to identifying issues, it is pretty easy with Splunk. Cost-wise, we have not saved much, but in terms of resiliency and digital experience, we get a lot from Splunk.
We get a lot of capabilities with Splunk Cloud and Splunk Enterprise Security. We also do application monitoring, and we wanted to embed both solutions into one. That is the whole reason we got Splunk.
We have a bunch of tools, not just Splunk, in our ecosystem. Splunk is one of our tools for monitoring purposes. We have other tools for alert management, global alert repository, etc. In our ecosystem, Splunk serves the main purpose of detecting and bringing the issues to our analysts to resolve them. Splunk plays a vital role.
How was the initial setup?
I was initially involved in the whole migration process. We used to have the Splunk on-prem instance, and only application teams were utilizing it. We bought the Splunk Cloud Platform, and we merged both the application and security into the Splunk Cloud Platform.
Cloud deployment is pretty easy because you do not have to manage any of your infrastructure. They take care of that.
What was our ROI?
We could see its time to value in roughly one year to sixteen months. We started the migration and moved to the cloud, and in a year to sixteen months, we could see a return on investment.
The ROI is in terms of the mean time to resolve the issues. We could do all of our security monitoring and enterprise security. We integrated security monitoring with our SOAR platform. We have so many L1 and L2 teams using Splunk day in and day out to monitor the transactions. They definitely have more visibility and reduced mean time to resolve the issues. They can identify an issue pretty fast.
What's my experience with pricing, setup cost, and licensing?
Currently, we have the ingest-based license. They are offering SVC-based licenses as well, but I am not a fan of SVC-based licensing. At the end of the day, I want to predict my budget and how much I am going to pay to the vendor so that I can plan my yearly budget.
I would always suggest going with the ingest-based license because you can control how much you want to ingest. It feels like you will be paying less when you switch to SVC-based licensing, but this is not true because you cannot control your users and what kind of searches they want to run. If you go for that, you will need a whole lot of manual effort to control your users.
Which other solutions did I evaluate?
We evaluated Elasticsearch. We evaluated Exabeam. We evaluated one more solution. Among all the solutions in the market, Splunk is the best.
The good thing with Splunk is that you can search your data across all the indexes pretty fast. The way the processing language works with Splunk is awesome. Most of my analysts can search the data as quickly as possible, whereas, with the other solution, there was always a lag while searching for data. With Elasticsearch, you have very limited capability to search across the whole platform. It is very easy with Splunk. The secret sauce of Splunk is the way they index the data. That is the main difference between Splunk and its competitors.
What other advice do I have?
I would rate the Splunk Cloud Platform a nine out of ten. The product is good. The only issue is the support.
The primary benefit that I get from attending the Splunk Conference is to be able to see all the new features that Splunk is releasing and how to use them and implement them in my infrastructure, platform, or ecosystem. I also get to know how other organizations are using Splunk to solve their use cases. Another thing is that we have so many vendors utilizing Splunk as their base and building so many new products. I visited one of the booths, and I was very impressed with their booth. They are doing all the content validation, security validation, and simulation of attacks. They are using their tool, and they have integrated it with Splunk. They are bringing all the data into Splunk to showcase how to maintain the hygiene of the content. That impressed me a lot. When I attend Splunk conferences, I get to see how others are utilizing Splunk as their base and building new tools out of that. It gives me some ideas of how to implement it in our organization. Of course, we cannot implement everything, but at least we can see the best fit for our platform.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Engineer Observability at a financial services firm with 10,001+ employees
Make staff's jobs better for resiliency purposes, reporting, and whatever they need to do
Pros and Cons
- "It has definitely improved our organization by virtue of reducing the amount of overhead we would have had for those environments. Having to implement, maintain, or even update the existing stuff would have been extremely time-consuming. Splunk Cloud handles all of that for us. So it's definitely been helpful from that perspective. It's allowed them to maintain upgrades for far further than they are. Some of the hosts of that environment were still on version 7 so they could get upgraded feature parity."
- "Some of the implementation is challenging. They're not very proxy-aware."
What is our primary use case?
We're looking to migrate an acquisition into the Splunk environment. We acquired a company and their Splunk environment was small and separate. We didn't want to have to maintain old Windows environments in unique use cases so we wanted to migrate it to the cloud as a proof of concept.
In their case, they had global data domicile requirements. We didn't have the same global deployment for our other larger environment that they did. So it made sense for us to migrate them to a bunch of small cloud stacks that were globally positioned rather than deploy a bunch of tiny enterprise environments to do the same thing.
The solutions are segregated at the moment. We're currently migrating the ACS environment. We have our own Splunk Enterprise implementation that we still use for Azure currently. It's fine, it doesn't drop.
How has it helped my organization?
It has definitely improved our organization by virtue of reducing the amount of overhead we would have had for those environments. Having to implement, maintain, or even update the existing stuff would have been extremely time-consuming. Splunk Cloud handles all of that for us. So it's definitely been helpful from that perspective. It's allowed them to maintain upgrades for far further than they are. Some of the hosts of that environment were still on version 7 so they could get upgraded feature parity.
They do well at empowering staff by providing business resilience. Users have the capability to utilize Splunk in ways to make their jobs better for resiliency purposes, reporting, and whatever it is that they need to do. Splunk is a very powerful platform in that way.
What is most valuable?
In their case, they had global data domicile requirements. We didn't have the same global deployment for our other larger environment that they did. So it made sense for us to migrate them to a bunch of small cloud stacks that were globally positioned rather than deploy a bunch of tiny enterprise environments to do the same thing.
It's pretty important to us that Splunk has end-to-end visibility to our native cloud environment. We need to be able to figure out where the points of failure are. Knowing whether it's a forward, on our end, an index, the cloud environment, a firewall, or something else entirely is important to troubleshooting that kind of process.
Splunk has helped to reduce our mean time to resolve. For the specific use case, the ability to bring in more Splunk data and market makes work consistently accessible.
I think that Splunk's ability to predict, identify and solve problems in real time is better than what we use it for. Our observability journey is still pretty early so we haven't done a lot of predictive detection that is possible to do with Splunk. It looks like it can do the things that we needed to do in a pretty effective way. We just haven't done that yet.
What needs improvement?
Some of the implementation is challenging. They're not very proxy-aware. Their recommendation is to set up an intermediate forward in a DMZ environment or something like that. That's not always the most convenient way to do things. It would be better if we could use an HTTP proxy, send data out via HEC, HTTP, or in a way that is proxy-aware.
For how long have I used the solution?
We did the POC six months to a year ago. We've been in the process of migrating some smaller use cases over the last three or four months.
What do I think about the stability of the solution?
We haven't used it a lot but it's been pretty stable.
How are customer service and support?
Splunk support is pretty good. There's some work to be done. When I provide them with a bunch of data, they don't need to ask me some of the initial questions. But otherwise, they're pretty good.
How would you rate customer service and support?
Positive
What was our ROI?
I have seen ROI. The adoption of the company has increased dramatically. We have hundreds of alerts, hundreds of reports, and hundreds of dashboards that people use for their business cases, whether it's deliverables, resiliency, or troubleshooting.
What's my experience with pricing, setup cost, and licensing?
Splunk is expensive. We have had some challenges in ensuring that all data is available in Splunk due to its cost. It has definitely proven its value in the data that we have brought in. From a resiliency and reporting perspective, those things are all very valuable. But it's certainly not the most cost-effective product in the world.
It is a valuable product, but it is certainly challenging at times to be able to bring in as much data as I would want due to the cost of the product.
What other advice do I have?
I would rate Splunk Cloud Platform an eight out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Manager, SOC, NOC, and Corporate Security at a computer software company with 1,001-5,000 employees
Can integrate easily with other tools and allow businesses to expand their use cases
Pros and Cons
- "The product's deployment phase was easy."
- "I think the tool has some scalability issues, especially when used in larger organizations."
What is our primary use case?
I use the solution in my company, and its primary use cases have been related to the log correlation engine. Splunk Cloud Platform can be considered a central ingest point for gathering logs from all over our company's network, after which it is used to take and create reports. Security, detection, dashboards, and similar features are some of the use cases that can be associated with the tool.
How has it helped my organization?
The benefits my company has seen from using the tool would be that it gives you more of a single place to look at rather than having to jump from a bunch of different screens to look at current logs, as well as the ability to correlate data amongst different log sources.
What is most valuable?
Regarding the solution's most valuable features, I think that since many of our company's applications are Splunk-based, they can integrate with other tools within our tech stack, which allows us to expand our use cases.
In our organization, Splunk Cloud Platform provides end-to-end visibility into our cloud-native environment, and it is a very important area where we need visibility within our environment. It is one of the main tools I use for end-to-end visibility.
Splunk Cloud Platform has helped reduce the mean time to resolve. It helps find issues, which can lead to a better mean time to resolve overall. Depending on the detection type, it reduces the mean time to resolve by anywhere from 20 to 50 percent.
My company saw time to value using Splunk Cloud Platform pretty quickly, and we continue to see the value, specifically when we add in new sources and tune-up. In general, it has been pretty quick.
Splunk's unified platform helps consolidate networking, security, and IT observability tools since it gives our company a single platform where we can collect logs from all different sources.
What needs improvement?
I think the tool has some scalability issues, especially when used in larger organizations. I feel the searching part gets really slow, which is based on one's resources.
For how long have I used the solution?
I have been using Splunk Cloud Platform for about six years. In general, I have been a Splunk customer for eight years.
What do I think about the stability of the solution?
I think the stability is pretty good. I haven't noticed any outages.
What do I think about the scalability of the solution?
I think the scalability could be a little bit better because our company runs into some resource constraints that slow down our searches.
How are customer service and support?
When it comes to the solution's technical support, I would say it all depends on what the request is or who is actually responding to our company's queries. We have had some people who have been great, but we have also had times where we had to escalate some issues to get our tickets looked at by someone from the support team. I rate the technical support a five or six out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I think the tool has some scalability issues, especially when used in larger organizations. I feel the searching part gets really slow, which is based on one's resources.
How was the initial setup?
The product's initial setup phase was fairly expensive since my company had to get some professional services to help us with the set up of everything. Overall, the tool freed up some manpower, resources, and hours from our personnel and management, so having the tool in our company made sense. Yeah.
The product's deployment phase was easy.
The solution is deployed using the cloud services offered by AWS.
What about the implementation team?
My company had to get some professional services from a reseller named Resultant to help us with the setup of the tool.
Which other solutions did I evaluate?
I don't remember whether my company had evaluated other products against Splunk Cloud Platform. In the environment where our company made the switch over, I can say that we are happy with our Splunk usage in general. We just wanted a tool that was more resilient and didn't have to worry about the management on the back end.
What other advice do I have?
My organization monitors one cloud environment with the help of Splunk Cloud Platform. The ease or difficulty of monitoring multiple cloud environments is not something that is applicable to my company.
In terms of Splunk Cloud Platform's ability to help improve our organization's business resilience and predict, identify, and solve problems in real time, I would say it is not possible in real-time. The solution gives our company the ability to do more of a retrospective analysis, which helps us with the current backup.
There are not any cost efficiencies I can think of that I have experienced after switching to Splunk Cloud Platform.
I think Splunk Cloud Platform is still probably one of the best tools out there in the market for enterprise organizations.
I rate the tool a seven to eight out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior analyst in investigations at GlaxoSmithKline
Helpful in dealing with malware investigations and anomalies
Pros and Cons
- "In terms of the benefits of the product, I would say it is my go-to tool."
- "The expensive nature of the product is an area of concern that needs to be considered for improvement."
What is our primary use case?
I work on corporate investigations and incident response. I use Splunk Cloud Platform to investigate user frauds, cases related to malware investigations, and anomalies.
How has it helped my organization?
In terms of the benefits of the product, I would say it is my go-to tool. Regarding getting all the data from Windows event logs, and considering the other reporting tools we have in our company like Forcepoint, Proofpoint Email Protection, Office 365, or Microsoft Defender, we have to search and get all the data in one place and to do so, Splunk Cloud Platform is super valuable.
What is most valuable?
The solution's most valuable features are search, reporting, and dashboards.
Splunk Cloud Platform is useful in our organization's monitoring of multiple cloud environments involving cloud services like AWS. I cannot speak about the ease or difficulty of using the tool to monitor multiple cloud environments since I am not on the administration side.
Considering the product's ease of use, the tool offers me the ability to search all the data and get it in a format before giving it to an investigator so that they can get it in a format they can understand.
What needs improvement?
The expensive nature of the product is an area of concern that needs to be considered for improvement.
For how long have I used the solution?
I have been using Splunk Cloud Platform for twelve to fourteen months.
What do I think about the stability of the solution?
The product has been pretty stable for me. I have never seen any outages in the tool, and it has been a pretty solid solution.
How are customer service and support?
I have no experience with the solution's technical support team.
Which solution did I use previously and why did I switch?
I was not using any other solution in the past.
How was the initial setup?
I don't know anything about the product's deployment phase.
What's my experience with pricing, setup cost, and licensing?
I know that Splunk Cloud Platform is an expensive product.
What other advice do I have?
I rate the tool a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Infrastructure Manager at a educational organization with 1,001-5,000 employees
Has good analysis and visualization features and saves costs and time
Pros and Cons
- "We use Splunk Cloud primarily as a troubleshooting tool, so the most valuable features are the analysis and visualization."
- "I want to have the ability to process the ingestion before it is sent to the back end and Splunk just announced that the feature is coming, so now it just needs to be released."
What is our primary use case?
We use the Splunk Cloud Platform to log all the network devices, whether it's switches, routers, firewalls, wireless controllers, wireless access points, and applications such as MuleSoft or Adobe AEM.
How has it helped my organization?
The team I manage is small and we don't have much time to maintain the on-prem infrastructure with patches and updates. With Splunk Cloud, we don't have to worry about patches or upgrades. It's always up to date with the latest and greatest features. That's the biggest benefit for us so far. It saves us time and headaches that come along with all the upgrades, patching, and administration of the Platform in general.
Splunk Cloud Platform has more features than the on-premise Splunk Enterprise version that we previously used. My team seems to like the GUI better.
Splunk Cloud Platform's ability to provide end-to-end visibility into our cloud-native environment is extremely important because we don't have any tool that has that feature.
It has sped up our mean time to resolve by 40 to 50 percent compared to the on-premise version of Splunk.
Our on-premises setup used an outdated Splunk version on aging Red Hat seven hardware. Upgrading would have required new Red Hat eight systems and consultant deployment expertise. By going to the cloud, we don't have to worry about hiring consultants or upgrades. That saved us time and money. The pricing that we were given was the same as renewing our maintenance and support for our on-prem version. So it was a no-brainer decision.
As soon as we migrated, my team liked the GUI because it made them more efficient. There are more functions and features that are not available with the on-premise version of Splunk.
What is most valuable?
We use Splunk Cloud primarily as a troubleshooting tool, so the most valuable features are the analysis and visualization.
What needs improvement?
Areas of improvement for Splunk Cloud Platform are difficult to say because we're still learning about the platform. I want to have the ability to process the ingestion before it is sent to the back end and Splunk just announced that the feature is coming, so now it just needs to be released.
For how long have I used the solution?
I have been using the Splunk Cloud Platform for three months.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Splunk Cloud Platform is easily scaled on the cloud.
How are customer service and support?
The few times we reached out to technical support, they were helpful and able to address the issues.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Splunk Enterprise and wanted to stick with Splunk because we feel it is the best product. So switching to the Splunk Cloud Platform was an easy decision for us.
How was the initial setup?
The deployment was not difficult. We had consultants helping us. We thought it was going to take three weeks to migrate from on-premises to the Cloud, and it took half that time. It was a lot easier than we anticipated. And we were able to do most of the work ourselves without using the consultants.
What about the implementation team?
We used Bitzios Consulting to help us with the implementation.
What was our ROI?
By moving to the Splunk Cloud Platform we saved on having to hire consultants to build a new environment and install it on-premises.
What's my experience with pricing, setup cost, and licensing?
The price for Splunk Cloud Platform is the same as our maintenance costs for Splunk Enterprise on-premises.
What other advice do I have?
I would rate Splunk Cloud Platform nine out of ten. Splunk Cloud offers several advantages in terms of ease of use. Since it's cloud-based, there's no need to worry about infrastructure maintenance, availability, or scalability. New features are automatically available, eliminating the need for manual upgrades and potential downtime that can occur with on-premise installations.
We have AWS and GCP but are using the Splunk Cloud Platform to monitor only the AWS for now.
While we currently use Splunk Cloud, we don't have Splunk security. We plan on implementing Splunk security and that's also going to integrate with all of our Cisco equipment. For now, I can't say that Splunk's unified platform has helped consolidate networking, security, and IT observability, but soon, it will because we'll be able to have one source, one point of reference for all of our logging and security information instead of managing separate tools for different tasks. Once we implement Splunk Security, it will be one single pane of glass where we will have everything.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Popular Comparisons
Tableau Enterprise
SAP BusinessObjects Business Intelligence
Qlik Sense
PagerDuty Operations Cloud
Salesforce Service Cloud
Splunk ITSI (IT Service Intelligence)
Apache Superset
Splunk Enterprise Platform
Google Cloud Datalab
OnSolve Platform for Critical Event Management
Splunk Security Essentials
Buyer's Guide
Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What's your experience or opinion about Spotfire vs. Tableau vs. Qlik?
- A journalist is writing a story about which Data Visualization software product to choose. Can you help him?
- What enterprise data analytics platform has the most powerful data visualization capabilities?
- When evaluating Data Visualization, what aspect do you think is the most important to look for?
- What are the best self-service and Excel-like filtering / display tools?
- What data visualization tool/s do you find to be the best?
- Why is Data Visualization important for companies?
- Which Data Visualization tools are good at collaboration and support the tracking of insight actions?
- How many users on average are licensed users of Data Visualization software in a company?


















