We use Splunk Cloud Platform for IT operations, IT security, and business value.
Senior InfoSec Manager at a pharma/biotech company with 5,001-10,000 employees
Has improved uptime and helped us improve performance in areas where our network or servers were not performing well
Pros and Cons
- "Splunk Cloud Platform's most valuable features are enterprise security and ticketing integration."
- "From an enterprise standpoint, we are more limited in terms of what data we can export and how we can present it."
What is our primary use case?
How has it helped my organization?
We implemented Splunk Cloud Platform to resolve our IT security issues.
The federated search feature is a valuable tool that can be used effectively in the right architecture. However, the extent it is utilized will vary depending on the customer's needs. In my experience, more advanced customers tend to use this feature more heavily.
Splunk Cloud Platform provides good visibility into multiple environments, including cloud, on-premises, and hybrid.
Splunk Cloud Platform is the best tool for a reason. It is a high-functioning solution with high integration for getting data in and out, and it is customizable.
The most significant benefit of using Splunk Cloud Platform is the freedom of data. The security team can see the data that's relevant to them, IT Ops can see the data that's relevant to them, and the business can see the data that's relevant to them. Sometimes, the same data is applicable to all three groups. Sometimes, it's not. But everyone has access to the data, and it's immutable. It can't be changed or deleted. The ability of all of these departments to leverage the same data is how Splunk Cloud Platform has benefited our company the most.
Splunk Cloud Platform has helped us make key decisions, such as cost-saving decisions related to licensing. It has also improved uptime and helped us improve performance in areas where our network or servers were not performing well. Additionally, it has helped us make better business and IT decisions and has supported our planned growth.
Splunk Cloud Platform helps us access data for compliance and privacy regulations. It currently has the features to mask data, perform the least privileged access, and provide only certain commands and functions within the platform.
We are the best in the industry because of Splunk Cloud Platform. Splunk Cloud Platform fills the SIEM role for our organization, and without the best SIEM, we would be no better than our competitors.
Splunk's extensibility is one of its best features. It offers a wide variety of ways to ingest data, generate reports, and create dashboards. Its integrations with other systems are also very impressive.
What is most valuable?
Splunk Cloud Platform's most valuable features are enterprise security and ticketing integration.
What needs improvement?
The reporting provided by Splunk Cloud Platform is often good, but it only provides the data and not the flash, whereas the other platforms provide both. From an enterprise standpoint, we are more limited in terms of what data we can export and how we can present it.
Navigating the solution can be more user-friendly.
The documentation has room for improvement and the price is high and can be improved.
Buyer's Guide
Splunk Cloud Platform
August 2026
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,564 professionals have used our research since 2012.
For how long have I used the solution?
I have been using the Splunk Cloud Platform for over five years.
What do I think about the stability of the solution?
When architected properly and maintained to an optimum level, Splunk Cloud Platform is unbelievably stable.
What do I think about the scalability of the solution?
One of Splunk Cloud Platform's key selling points is its ability to scale to petabytes and beyond.
How are customer service and support?
Base-level support is suboptimal. Enterprise customers need the premium support package. Responses are often delayed, and resolution is slow.
Which solution did I use previously and why did I switch?
Over the past 25 years, I have used several different solutions. In the past, I preferred using a terminal interface rather than a web interface. Splunk has an API and a mobile app, but ultimately, Splunk users are confined to their browsers. This is one thing I would like to change, as I would prefer to be able to use Splunk outside of a browser. However, this is also one of Splunk's biggest advantages, as it is a universal platform.
We used Splunk Enterprise before migrating to Splunk Cloud Platform.
How was the initial setup?
My knowledge of Splunk has since grown exponentially, but the first time I deployed Splunk Enterprise eight years ago, it was unbelievably hard. There were so many moving parts and things to consider. It was too much for one person to figure out, and I didn't have the budget to get help from the Splunk team.
What's my experience with pricing, setup cost, and licensing?
The cost of using Splunk Cloud Platform is high, but the value it provides is worth the investment.
What other advice do I have?
I give Splunk Cloud Platform a nine out of ten.
Monitoring multiple cloud environments is never easy. We are looking forward to new features from our cloud partners, such as AWS Security Data Lake, Google, and Microsoft. These features will make it easier to integrate our cloud environments. Splunk Cloud Platform is currently the best solution for collecting data from multiple cloud environments. AWS has five million different ways to export data, and we need to use all of them to collect all of the security and IT-related data. Splunk supports all of these data sources.
A year ago, I would have said that Splunk needed automated response, an easy-to-detect, easy-to-run, and manage business analytics platform, a user and entity-based business analytics platform that is integrated within the product, threat intelligence, and a current dashboarding tool. Splunk now has all of these features. A year ago, Splunk's competitors had these features, but Splunk did not. Splunk has since acquired or developed these features in-house. Very little in Splunk's product is not tightly integrated into the current releases. If someone is starting from scratch, meaning they are just rolling out a new security solution, and they do not choose Splunk, they are making a mistake. Splunk provides so much of everything that it is the best choice for most organizations.
We perform daily maintenance on the solution.
I advise new users to find someone who knows Splunk. Even a good technical person will not be able to do this on their own. They are not going to train them on day one. Good technical people who know Splunk are valuable assets, so they should seek them out and get them on the project.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Monitoring Administrator at a financial services firm with 1,001-5,000 employees
Manages indexes and brings value, but the security connection should have a seamless integration
Pros and Cons
- "Index manager is most valuable because we do not have to bother about internal storage. It is all managed by the Splunk team."
- "The security connection should have a seamless integration. Other than that, the way we are using it, so far, it seems quite good."
What is our primary use case?
We are primarily using it for InfoSec, cybersecurity intelligence, information gathering, and forensics. We also do a little bit of application performance monitoring for some appliances that can only be monitored through log ingestion.
How has it helped my organization?
We are starting to monitor multiple cloud environments. We have our internal cloud, and we are migrating to AWS. We are engaged in that path. In terms of monitoring, it is more or less the same because we are using the same integration pattern, which is to use Ivy folders and gather logs. We use it at its minimum, but the way I see it at the Splunk conference, we can go further. Will we go further? That is a million-dollar question.
It has end-to-end visibility into our cloud-native environment. For sure, it is important for operation and application support, but we need to embark our staff and management for that. They are the ones who are committing big dollars to that.
It has not reduced our mean time to resolve because we are using other tools as well. We are aiming to go on that path in the coming months.
It specifically has not improved our organization's resilience. There are a myriad of modern tools that we are implementing. Splunk is one of them. It is one of them helping us.
What is most valuable?
Index Manager is most valuable because we do not have to bother about internal storage. It is all managed by the Splunk team.
What needs improvement?
The security connection should have a seamless integration. Other than that, the way we are using it, so far, it seems quite good.
For how long have I used the solution?
We have owned Splunk Cloud Platform for the last year and a half.
What do I think about the stability of the solution?
The stability of the solution is quite good.
What do I think about the scalability of the solution?
We had challenges with the sizing of the cloud tenant that we purchased, but that was based on past decisions, so we are stuck with that until our next move. That should come in the next year. At that time, we will resize the tenant in a more efficient way, so scalability does not apply because the tenant we bought is a closed one. There is no scalability on either side. I learned that after the fact, so I am not impressed because we did not buy it. I guess people who buy that type can have good feedback on scalability.
Which solution did I use previously and why did I switch?
We migrated from an on-premise solution that we had for about three years. We saw cost efficiency when we went from on-premise to the cloud, but I do not manage the budget.
We are using Dynatrace in parallel. We used Splunk as a cybersecurity tool, and we embraced Dynatrace a few years ago. So far, Dynatrace does a great job. Splunk is closing the gap. With today's announcement at the Splunk Conference, they are catching up. We are also using Microsoft SCOM, so it is a trio. It helps us do a better job.
How was the initial setup?
I was not involved with the setup of the on-prem one, but I was involved with the migration to the cloud. My experience was interesting because I started from zero, but with the help of Splunk's professional teams, we could achieve our project. On a personal side, it helped me to gather the knowledge that brought me here at the Splunk conference.
The setup is always challenging. We had four or five people involved in the migration. We also involved a lot of key players in application migration. We had 20 to 30 people involved at some point in the migration path.
What about the implementation team?
We used professional services.
What was our ROI?
We have, for sure, seen an ROI with Splunk. Our DevOps team is able to gather faster answers to their questions. Obviously, it brings value, whether it is Splunk or any other tool.
We could see the ROI in a few months. We gave time to our DevOps specialists to embrace the solution and get used to it. From there, as they made their own usage and use cases of the tool, it gave them speed to achieve what they were looking for.
What other advice do I have?
I would rate Splunk Cloud Platform a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Cloud Platform
August 2026
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,564 professionals have used our research since 2012.
Splunk Administrator at a government with 11-50 employees
We have good visibility and we don't have to maintain the infrastructure
Pros and Cons
- "I like the fact that we do not have to maintain all the cloud infrastructure. That is probably the main thing about the Splunk Cloud Platform."
- "When one of my customers needs an app, and I am able to find that app on the Splunk base, I have to create a ticket and wait for five days for them to download the app into the cloud environment. That is probably one of the main things. It is painful because I have to wait to get that app in the cloud."
What is our primary use case?
We collect almost everything that we log and push it into the Splunk Cloud Platform. That is pretty much our use case. It is mostly for our cyber monitoring tool, firewalls, normal cyber logs, Windows event logs, etc.
How has it helped my organization?
Splunk Cloud Platform has helped improve our organization's business resilience a little bit. It is a big organization, and I am just a little part of it. Its impact on the whole business has been a little bit.
We use ES for correlation, incident handling, and things like that. It reduces the mean time to resolve a little bit as compared to the other SIEMs that we were using. We are not using SOAR right now, but that is where we want to be.
What is most valuable?
I like the fact that we do not have to maintain all the cloud infrastructure. That is probably the main thing about the Splunk Cloud Platform. We do not have to worry about maintaining the infrastructure that is out there. We just push things up and maintain our infrastructure on-premises. This is important for us because we just do not have the manpower and resources to manage all the infrastructure.
We used to use another SIEM with which we constantly had to replace hardware and things like that, so it is a good benefit to have that cloud infrastructure there whether it is coming from a SaaS environment or we just build it in the cloud.
What needs improvement?
One thing that is a stickler for us is the ability to download apps. I guess it depends on what kind of license you have. It allows some of them if I want, but this is something that we need on a day-to-day basis. When one of my customers needs an app, and I am able to find that app on the Splunk base, I have to create a ticket and wait for five days for them to download the app into the cloud environment. That is probably one of the main things. It is painful because I have to wait to get that app in the cloud.
Another issue is that if I build my own app to some configuration, I cannot load it up there myself. They have to vet it, which is important but it takes a long time to do all that.
For how long have I used the solution?
We have been using this solution for a little less than one year.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
Scalability does not apply to our environment. Because it is a cloud, scalability is relative to how much you can afford. It scales itself if your data increases because it is a cloud environment.
How are customer service and support?
Splunk's support is very good, but because the cloud environment was pretty new, I ran into a couple of stumbling blocks with the support for the Splunk Cloud Platform. However, it started to get a lot better. Currently, it is a lot better than when I first started. At that time, a lot of the support staff was probably new to the whole cloud environment, and I realized that. We were the first DOD department to go into the cloud, so it was tough in the beginning with their support. I would rate them a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We were using ArcSight. The decision to switch to Splunk did not come from me. It was the decision of the company itself. It was a requirement. We could not track the up/down status with the other SIEM. Splunk can do that better. That was one thing.
Another thing was the way Splunk can put things like MITRE ATT&CK into their platform. The way it handles rules and things like that makes it a lot better with the processing power. Splunk is search-based, whereas ArcSight is real-time. It fires the minute an event comes up, whereas Splunk has a separate way of doing it. They run a search every hour or so. It is not resource intensive. A lot of times, I can only turn on a minimum amount of rules, especially correlation rules, in ArcSight. I used to have about 300 or so in ArcSight. I probably have about 400 or 500 in Splunk, so the hardware processing power is a lot better.
How was the initial setup?
I was involved in its deployment. Its complexity level was 50/50, but that was expected because of the lack of training initially. We had an awesome team from Splunk that helped us out. They were there for us for at least a month. They helped us and then trained us on the environment. By the time they left, we were good to go.
What was our ROI?
The return on investment is not in a monetary sense. Things are a lot less stressful in our environment. We are able to see things that we were not able to see before. It gives us a little calm because we know if something is up or down. We are able to see things that we could not see before in other SIEMs. So, there is a reduction in the stress level.
We have seen a time to value. I can do plenty of things a lot faster than I could previously.
Which other solutions did I evaluate?
We evaluated Sentinel, QRadar, and LogRhythm. All of them were very good SIEMs, but we had a lot of challenges when it came to getting them certified on government L5. IBM has its own private cloud. They do not use AWS. We did not have that issue with Sentinel, but it is not as robust. Even though it is at a high level in terms of industry-level SIEM, it could not meet our requirements. It is still a challenge. Sentinel is the only one that is a competition to Splunk if you talk about cloud, not on-premises. It is native to the cloud.
What other advice do I have?
It is awesome. I love it. Anything is possible in Splunk. I have gone through a lot of challenges with use cases. When I needed to figure something out, I got it resolved sooner or later. I either got Splunk support or I went to the community and looked it up. I have never run into anything that I could not do with Splunk. It is very good.
Overall, I would rate the Splunk Cloud Platform a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Automation Developer at TNS
Reduces infrastructure overhead, but the process for custom apps can be streamlined
Pros and Cons
- "Not having to manage Splunk Cloud's infrastructure is valuable."
- "They can streamline the process of creating custom apps."
What is our primary use case?
On Splunk Cloud, I mainly look for errors in applications or issues that come up with our internal applications. I have also used it to create dashboards and display customer data to customers in an effective way so that they have insights into their data.
How has it helped my organization?
There is less overhead now for infrastructure management. There are fewer issues that we have to worry about on the infrastructure side. This has freed up more of our resources' time to work toward initiatives on the Splunk platform itself. It is hard to measure the time savings. If one resource was working on it, that resource could save anywhere between 15 to 20 hours a week.
It must have reduced our MTTR, but I have been with Splunk for as long as I have been in my current environment, so I do not have anything to compare it with.
It helped improve our organization’s business resilience. The solution helps us find where errors are and potentially where threats are a lot faster. We can more effectively push out alerts not only to our team but also to the teams across the enterprise. It is nice to have on hand.
It is quite effective at helping us identify problems very quickly. We do not participate in real-time searches within our Splunk environment, but close to real-time is possible, and it is quite effective.
What is most valuable?
Not having to manage Splunk Cloud's infrastructure is valuable. Being able to deploy within the cloud and not having to manually manage our configs on the infrastructure side and set up our own architectures has been the biggest help.
Other than that, the new Dashboard Studio has been a pretty big win, but I do not know whether that is more cloud-specific or not. Dashboard Studio has a cleaner look for customers that want to see their data but not necessarily search. For the customers that want to see their data, having an easy and effective way to drag and drop to see where things are going to be if they want to change them has been pretty beneficial.
What needs improvement?
They can streamline the process of creating custom apps. I do not have a lot of experience with it. It was not very difficult for me to do so, but there is probably a better way to present the ability for people to push their own custom apps to the platform and go through Splunk's manual and automatic reviewing process.
For how long have I used the solution?
I have been using this solution for about three years.
What do I think about the stability of the solution?
I have not seen any downsides when it comes to uptime and availability. Being in the cloud reduces downtime, especially compared to being on-prem where if something goes wrong, you will have to go in and fix that infrastructure yourself. I have not necessarily seen significant downtime with Splunk Cloud or on-prem at this time.
What do I think about the scalability of the solution?
I quite enjoy the fact that if we need more indexes or search heads, it is very easy to plug and play with Splunk Cloud. With the infrastructure model that we had before, we would have to go in, set up a new search head out to the cluster, and add a new indexer to the cluster if we needed it. It will have more benefits going forward as we move more and more into the cloud.
How are customer service and support?
I have worked with Splunk support, and I would rate them an eight out of ten. It depends on where you are and what project you are working on at the time. It would be quite beneficial to work with them if you have a specific project that you are working on, and they have some insight into it. I do not work with support too often myself. Usually, one of our Splunk Infrastructure managers works with them, but there is always room for improvement. Availability in terms of making the time to gain insight into specific projects and problems that we are having is an area that can be improved.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
My company has been with Splunk for quite some time now. We are well integrated at this point, and we are in the process of migrating over to Splunk Cloud specifically. We used Splunk on-prem for a while. We are currently in a hybrid situation, and we are making our way toward being completely on the cloud.
How was the initial setup?
I help from time to time with the migration process, but I am not necessarily in charge of the total migration functions that we currently have today. The most I have done in terms of deploying to the cloud was creating a custom alert action for the cloud environment, which is one of my biggest contributions so far. I am not completely in charge of it, but from time to time, I will assist in the migration process. It is a bit of a learning curve, but once you get more and more familiarized with the cloud and how to benefit from it by using features like federated search, it becomes easier. It is somewhere in between in terms of complexity.
What was our ROI?
We would have seen an ROI. I do not have a specific number, but assuming that we did not have Splunk Cloud, we would have to manage our own infrastructure. Not having to manage nearly as much infrastructure and not having to have the personnel to manage that infrastructure on a regular basis, frees up that time for them to do what they are really designed to do. This has definitely added value.
What's my experience with pricing, setup cost, and licensing?
I am a little bit familiar with the pricing and licensing model. I am not sure about the particular pieces of the actual price that we have, but I do like the idea of going towards a more CPU-based approach rather than the ingesting approach. This CPU-based approach gives us the ability to ingest more data if we need it.
What other advice do I have?
The biggest value that I get from attending Splunk conferences is the insights from everybody here. You have people from many different companies doing very different things and deploying very different models within their different Splunk instances. You get an idea of where everybody lands and maybe grab some ideas that you would not necessarily have thought of by looking at it from the inside of someone who is in a completely different field than you are.
There is definitely a big difference between Splunk Cloud and on-prem. For me, one of Splunk on-prem's biggest features is being able to deploy my own custom applications internally, which is something that is a bit of a process with Splunk Cloud. So, given the information that I have, I would rate it a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Infrastructure Admin at a healthcare company with 10,001+ employees
Has end-to-end visibility in our native environments
Pros and Cons
- "It's made searching for data easier. Users like it. We're still in the migration process, but overall, it's a lot easier to use."
- "The administration could use improvement. We have to rely on support more often than we're used to."
What is our primary use case?
We're migrating our on-prem environment to Splunk Cloud Platform. We're consolidating two separate Spark clusters because of a merger. Our primary use case is for unifying all of that data into one place.
How has it helped my organization?
It's made searching for data easier. Users like it. We're still in the migration process, but overall, it's a lot easier to use.
What is most valuable?
It's important to use that Splunk has end-to-end visibility in our native environments. We have to have that visibility because we manage multiple app applications that rely on it.
Splunk helped to improve our organization's business resilience. That's very important to us. Our users rely on Splunk heavily for the health of their applications. It helps them to get ahead of issues, and if there is an outage, it enables them to resolve them faster.
Splunk gives the different application owners the ability to configure alerting specific to their needs so they can customize it however they want. If they know their applications better than you know, admins, I'll give them that flexibility.
What needs improvement?
The administration could use improvement. We have to rely on support more often than we're used to.
For how long have I used the solution?
We have been using Splunk Cloud Platform for nine months.
What do I think about the stability of the solution?
Stability has so far been good. We haven't had any issues.
How are customer service and support?
Their support is great, especially the agent that we have now. They're very responsive, willing to help out, and give suggestions.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Splunk Enterprise. We switched to Cloud Platform because we wanted to consolidate a couple of instances to one place and we're moving our security team to the cloud.
How was the initial setup?
I wasn't involved in the setup directly but I was aware of what they were doing. The setup is a little complex. We had some issues we had to deal with. Bringing both environments together and getting the different environments to communicate with Splunk Cloud was complex. We have a lot of data. Getting a handle on that before we were able to start sending data to the cloud was complex.
What's my experience with pricing, setup cost, and licensing?
It's expensive. We're still trying to figure out Cloud licensing.
What other advice do I have?
It's not so easy to monitor multi-cloud environments using Splunk. We have some difficulties, but we have some things in place, but it's not easy.
I would rate Splunk Cloud Platform an eight out of ten. There's a lot we haven't tapped into yet, so the rating can go up.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager Cloud Operations at a computer software company with 201-500 employees
Makes searching for issues very easy
Pros and Cons
- "Splunk helped reduce our mean time to resolve by around 60%."
- "Support is the bigger issue when we have a problem. When we need their help, it takes weeks or months to actually get resolved."
What is our primary use case?
My primary use cases are for troubleshooting, monitoring, and anomaly detection.
How has it helped my organization?
Splunk helped reduce our mean time to resolve by around 60%. We have realized these savings through it solving problems and the proactive monitoring. But it comes with a huge cost. We have to evaluate other products that are comparable to Splunk in the market and see if they offer the same value.
It improved our business resilience.
Splunk has improved my organization by troubleshooting issues. When we have an issue, if we didn't have Splunk, it could take hours or days to figure out where the problem is. With Splunk, it only takes hours or minutes sometimes.
It saves us money by changing our product or process to work in a better way. Splunk is great. It has a lot of value ads and features. But overall, Splunk Cloud is expensive compared to other products in the market.
What is most valuable?
The most valuable feature is the search options. Our infrastructure is huge so if an issue happens, it's hard to find where it is. That's where Splunk comes in handy. You just go to their user interface and do a Google-type search. Just put in a keyword, search it, and you'll figure out where it is. If you have thousands of servers, it's very hard to see where the issue is and where the transaction is logged. Splunk makes it very easy. That's the best part of Splunk.
I would rate Splunk's ability to provide business resilience by empowering oneself a seven out of ten. Whenever we have an issue, Splunk is handy. We have a lot of monitoring in place so if an issue happens, our monitoring helps proactively figure out the issue, and in that way, we can make sure that our environment and infrastructure are up and running, and our customers don't have any issues.
What needs improvement?
It's improved a lot since we began using it. We have been seeing issues, but they get resolved by working with the support. It's just getting expensive with time.
Support is the bigger issue when we have a problem. When we need their help, it takes weeks or months to actually get resolved. To date, we have cases open for two or three months without a resolution. Support is the worst part.
For how long have I used the solution?
I have been using Splunk Cloud Platform for four years.
What do I think about the stability of the solution?
It's stable and highly available. We had issues, but all of these types of platforms have.
What do I think about the scalability of the solution?
Scalability depends on what kind of license you have. If you have ingest-based licenses and you hit your cap, I think they still let you ingest more, but then you have to work with your account team and buy more licenses so you don't lose data. It's scalable, but not automated because it has its own license limitations.
How are customer service and support?
I would rate support a four out of ten. The reason is that they are not proactive, they are reactive. If we notify them about an issue, they are supposed to monitor their infrastructure and tell us that there is an issue and that they are working on it. But rather than doing that, we have to do that, and after doing that, it takes time for them to work on it and solve the problem.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
My company previously used a custom, on-premises solution. Splunk was already implemented when I started at my company.
We're asking ourselves now why we use Splunk. Our next step is to go out and evaluate other products in the market that may be not as costly and offer the same feature set.
How was the initial setup?
It's a cloud, it's all managed service. The only thing we had to do is onboard our applications, which is something I do every day.
It's very straightforward and very easy. You only need to configure and get data and you can be onboarded within minutes. We don't have to go through a lot of configurations, manual steps, or training.
What other advice do I have?
Its ability to predict, identify and solve problems in real time is looking promising. We're looking into it now.
I would rate Splunk an eight out of ten. It has a lot of features and enables us to focus only on our applications and logs. I don't need to worry about the infrastructure behind it.
The best value I get from attending Splunk conferences is getting experts' help for specific use cases.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Systems Operations Senior Specialist at a financial services firm with 5,001-10,000 employees
Shows us valuable information in an easy-to-understand way
Pros and Cons
- "Splunk reduced our mean time to resolve by 30%. If an application starts misbehaving, we send logs to Splunk and check to see what's going on and see what's happening."
- "Since I work on data collection from external sources and send them into Splunk, I miss its ability to collect that data through REST API applications."
What is our primary use case?
My role is in observability.
Some of our internal systems send data into Splunk Cloud. We had dashboards for our team's KPIs. We can check to see how fast the team reacts to events. Those reaction times a recordreed and sent to Splunk. From there, we can draw some dashboards. We can check to see who is doing well and who needs to improve. The power Splunk admins started moving into the Cloud.
The primary use cases are for team KPIs, log analytics, and error search. We would look for the relation of different events and draw dashboards to see how bad things were veering off from the timeline that we wanted to see.
How has it helped my organization?
Splunk helped us shape the picture of our team and enabled management to see who should be rewarded and who should be coached. It helped outline where KPIs were not being met. We could sit down and discuss what happened, and why it did not go as planned, and then we could make improvements in the processes. It helped us draw a broader picture of the entire team's capabilities.
With Splunk, everything is centralized, everything is in one place. We don't have to scramble and approach Splunk admins where to look.
In terms of networking, we managed to build good dashboards. We have a lot of firewalls and rules. If a new service comes up, if they don't have a firewall and nothing works, we can look at the Splunk dashboard and see the particular network flow and see if firewalls are blocking traffic. This is a Splunk function that people are happy and excited about. It shows us valuable information in an easy-to-understand way.
What is most valuable?
It's very important for us that Cloud Platform offers end-to-end visibility into our cloud-native environment. More and more functions are moving to the cloud, so it's not only for observability to see the system, but it's also for management and senior management to see that all of their applications are running as intended. If we try to spread out applications through multiple vendors, multiple regions, access groups, and whatnot, it becomes pretty important. It may become a challenge because of that spread. It brings resilience, but it also makes it more difficult to look after everything.
We want to achieve having everything in a single view. Senior management wants to make sure that everything is running well. The application team's developers want to have a granular review.
Splunk reduced our mean time to resolve by 30%. If an application starts misbehaving, we send logs to Splunk and check to see what's going on and see what's happening.
The dashboards are the most valuable feature. It's all of the information in one place. We can build it ourselves, so we can make it the way we like.
What needs improvement?
Since I work on data collection from external sources and send them into Splunk, I miss its ability to collect that data through REST API applications. I would like the ability to configure an endpoint, set it on Splunk, and set a schedule for it to pull information every ten minutes, and pull this endpoint information. I could search through it, look for keywords, restructure the data that's brought back to me, and then store it in the Splunk index. This is not available and if it is available, it is bare bones. I would like Splunk to have this function by default.
For how long have I used the solution?
We started using Splunk seven years ago. We started with Splunk on-prem and then moved to Splunk Cloud.
What do I think about the stability of the solution?
I never had any stability issues.
How are customer service and support?
I use support rarely but so far, it's been fine.
I would rate it an eight out of ten. My cases weren't that critical so it took a little longer to solve.
How would you rate customer service and support?
Positive
What's my experience with pricing, setup cost, and licensing?
We have not achieved cost efficiencies by switching to Splunk. There will be some cost discussions in cost optimization.
We log a lot of data which may have impacted our licensing cost.
Which other solutions did I evaluate?
We also looked at Datadog but it wasn't cost-efficient to log with two tools.
What other advice do I have?
We monitor multiple cloud environments. I heard that it's more straightforward to monitor multiple cloud environments with AWS. Azure doesn't work as intended, there were some issues collecting data from it.
I would rate Splunk Cloud Platform seven out of ten. I really miss REST API abilities.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CYBERSECURITY ANALYST at a tech services company with 1-10 employees
Good visibility and speed with reasonable pricing
Pros and Cons
- "We only buy the services we need. We don't have to pay for other things we don't."
- "They need to provide more training options."
What is our primary use case?
Splunk Cloud helps us to combine all our environments. For example, multiple business units can be combined into one even if they are in different geographic locations.
What is most valuable?
It helps us with hosting from different geographical locations.
The speed of the cloud environment is great.
We only buy the services we need. We don't have to pay for other things we don't. It makes the pricing very economical.
We use the solution's federated search feature. It's easy for us to use. It helps us search logs, analyze, and manage data.
We are able to monitor multiple cloud environments using our Splunk Cloud dashboards. It makes the process very simple. We just have to maintain different teams for different environments.
The solution is great within hybrid environments. It gives us good visibility across everything.
It works well for sizable environments.
The product integrates well with other systems and applications in our environment. We haven't had any issues with integration at all. However, if we ran into issues, we could call Splunk support. Having an issue would be a very rare event.
Reporting is very good. It's the same for all Splunk solutions. Having multi-cloud instances in one place is great.
We have multiple business units and easily integrate them into the cloud, as well as different infrastructures from different areas. We can deploy a Splunk agent on any cloud - AWS, Google, etc.
The company can access data easily for compliance and privacy regulations. The privacy aspect has been very good.
Having resilience has been very helpful in our organization.
What needs improvement?
Training should be free of cost. They need to provide more training options.
There are no missing features at this time.
For how long have I used the solution?
I've been using the solution for two and a half years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
We have 30 people using the solution in our organization. The product is scalable.
How are customer service and support?
Technical support has been good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did also use LogRhythm. It has a very good UI in comparison to Splunk, yet it doesn't have as many capabilities and does have a few more restrictions. That said, it's a good product for creating use cases and automation, which is easier than Splunk. We moved to Splunk as LogRhythm did have some restrictions.
How was the initial setup?
I have previously done deployments of Splunk. The setup is pretty straightforward.
Were a system integrator of Splunk. We help clients set up the solution.
We've had six or seven people setting up the solution.
The maintenance is pretty manageable. I'd rate maintenance needs seven out of ten.
What was our ROI?
I'm not sure if we have noted any ROI while using Splunk.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. They provide good options for licensing.
Which other solutions did I evaluate?
I did not evaluate any other options.
What other advice do I have?
We are integrators and also users of Splunk.
We have multiple solutions we use for security, of which Splunk is one of them. So far, it's been very good from a security perspective, although we don't solely rely on it.
I'd recommend users work with Splunk in the cloud environment. I'd recommend the product in general to others.
I would rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Analyst at a computer software company with 11-50 employees
It's a good solution that can index a large amount of data in a short time.
Pros and Cons
- "The Splunk search is powerful compared to similar solutions, and we get millions of data points within seconds."
- "The Splunk interface is on-premises, so we have limited access to Splunk Cloud. Splunk support is not so good on Splunk Cloud. The Splunk side of the Splunk Cloud should also be more customizable. Integrating Splunk UBA, Splunk Phantom, and Splunk Cloud is also a bit difficult."
- "Splunk support isn't so great. It takes a lot of time for them to respond."
What is most valuable?
The Splunk search is powerful compared to similar solutions. We get millions of data points within seconds.
What needs improvement?
The Splunk interface is on-premises, so we have limited access to Splunk Cloud. Splunk support is not so good on Splunk Cloud. The Splunk side of the Splunk Cloud should also be more customizable. Integrating Splunk UBA, Splunk Phantom, and Splunk Cloud is also a bit difficult.
For how long have I used the solution?
I've been using Splunk Cloud for about four years.
What do I think about the stability of the solution?
Splunk Cloud is reliable.
What do I think about the scalability of the solution?
Splunk Cloud's scalability is pretty good.
How are customer service and support?
Splunk support isn't so great. It takes a lot of time for them to respond.
How was the initial setup?
The initial setup is straightforward.
What about the implementation team?
We deployed Splunk in-house.
What's my experience with pricing, setup cost, and licensing?
The license costs around 100,000-150,000 rupees. Splunk Cloud is the basic version. It costs extra if you need Splunk interface or Splunk ICSA. Those are premium additions. There are additional costs if you want to use the other premium aspects of Splunk.
What other advice do I have?
I rate Splunk Cloud eight out of 10. It's a good solution that can index data in a short time. That's one advantage of Splunk over other solutions. However, the support isn't good, and you can't customize the Splunk interface.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Director - Application Services, DevOps(Application Support, Build/Deployment), Environment Support at a financial services firm with 10,001+ employees
Centralized security, useful data usage, but lacking templates
Pros and Cons
- "Splunk Cloud's most valuable features are log aggregations, dashboarding, business management, reporting, and business controls. Additionally, it has awesome indexing and the solution is always improving"
- "Splunk Cloud could improve by having pre-defined templates. It has very good design views, but there is no predefined template. You have to define your own. If they could add predefined templates for different use cases."
What is our primary use case?
We are using Splunk Cloud as a log aggregator. All our application logs come to one place, and we do the aggregation, troubleshooting, and investigation. It has many different kinds of production troubleshooting.
How has it helped my organization?
We went from a manually reviewing logs to an automated time-series base with Splunk Cloud. It has helped our organization a lot.
What is most valuable?
Splunk Cloud's most valuable features are log aggregations, dashboarding, business management, reporting, and business controls. Additionally, it has awesome indexing and the solution is always improving
What needs improvement?
Splunk Cloud could improve by having pre-defined templates. It has very good design views, but there is no predefined template. You have to define your own. If they could add predefined templates for different use cases.
For how long have I used the solution?
I have been using Splunk Cloud for approximately three years.
What do I think about the stability of the solution?
Splunk Cloud is highly stable. However, we had minor issues but we were about to fix them. We needed more capacity. The search capacity had to be increased as we looked at it because our logs move a minute of latency, it is almost in real-time
What do I think about the scalability of the solution?
Splunk Cloud is scalable. If we want to expand we only need to add new hardware. it is much easier having the solution be cloud.
We use the solution every day. All the production support analysts are using the solution. There are approximately 50 people using it in my area.
How are customer service and support?
I have not needed to use the support.
Which solution did I use previously and why did I switch?
We have not used another solution previously.
How was the initial setup?
The initial setup of Splunk Cloud was complex because we have a lot of logs. We had a lot of architectural setup discussions but we were able to do it. The level of difficulty for the implementation is in the medium range. It took us approximately 25 minutes.
It's an agent-based system, and you only have to enable it. There is an access control setup to control what to send, and what not to send. The deployment was quick. The adaptation or the implementation takes time because you've got to go through all the infrastructure setup
I rate the initial setup of Splunk Cloud a four out of five.
What about the implementation team?
We did the implementation of Splunk Cloud in-house and using two contractors. After the solution is implemented we do not need someone to manage it very often.
What's my experience with pricing, setup cost, and licensing?
There are additional features that you would need to purchase depending on your use case.
What other advice do I have?
I rate Splunk Cloud a seven out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Popular Comparisons
Tableau Enterprise
SAP BusinessObjects Business Intelligence
Qlik Sense
PagerDuty Operations Cloud
Salesforce Service Cloud
Splunk ITSI (IT Service Intelligence)
Apache Superset
Splunk Enterprise Platform
Google Cloud Datalab
OnSolve Platform for Critical Event Management
Splunk Security Essentials
Buyer's Guide
Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What's your experience or opinion about Spotfire vs. Tableau vs. Qlik?
- A journalist is writing a story about which Data Visualization software product to choose. Can you help him?
- What enterprise data analytics platform has the most powerful data visualization capabilities?
- When evaluating Data Visualization, what aspect do you think is the most important to look for?
- What are the best self-service and Excel-like filtering / display tools?
- What data visualization tool/s do you find to be the best?
- Why is Data Visualization important for companies?
- Which Data Visualization tools are good at collaboration and support the tracking of insight actions?
- How many users on average are licensed users of Data Visualization software in a company?














