No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2899428 - PeerSpot reviewer
Observably Architect at a manufacturing company with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Improved uptime and incident response has enabled rapid root cause analysis across cloud hosts
Pros and Cons
  • "Splunk Observability Cloud has positively impacted my organization by allowing us to have visibility into the environment."

    What is our primary use case?

    My main use case for Splunk Observability Cloud is infrastructure monitoring in the cloud.

    An example of how I use Splunk Observability Cloud for infrastructure monitoring is mainly infrastructure alerts, in particular virtual machines, when there is a degradation in the system or an alert or event. Splunk Observability Cloud actually surfaces those.

    What is most valuable?

    The best features Splunk Observability Cloud offers include the ability to see all the various hosts, not only private cloud but also cloud services as well.

    Having visibility across both private cloud and cloud services with Splunk Observability Cloud has benefited my work significantly, especially when trying to tell the story around particular incidents or issues and when they happen. In particular, anytime there is an adverse event that impacts the company, whether it is an infrastructure issue or a cloud issue, being able to get to root cause as quickly as possible has been extremely helpful.

    Splunk Observability Cloud has positively impacted my organization by allowing us to have visibility into the environment. Historically, that has not always been the case. Once we implemented Splunk Observability Cloud, it definitely allowed us to get to meantime to identify and meantime to detect as quickly as possible.

    Splunk Observability Cloud has helped improve my operational performance and my company's resilience. The biggest improvement is really improving uptime and reliability of the systems, getting to root cause as quickly as possible, minimizing impact as it relates to outages, and then being able to recover from those as quickly as possible.

    What needs improvement?

    I think the biggest improvement in Splunk Observability Cloud that Splunk is currently working on is just unification across all their products, not just Splunk Observability Cloud, but a single pane of glass to allow the engineers and operators to stay in one location.

    For how long have I used the solution?

    I have been using Splunk Observability Cloud for approximately four years.

    Buyer's Guide
    Splunk Observability Cloud
    August 2026
    Learn what your peers think about Splunk Observability Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
    913,924 professionals have used our research since 2012.

    What do I think about the stability of the solution?

    Splunk Observability Cloud is stable.

    What do I think about the scalability of the solution?

    Splunk Observability Cloud has been able to meet all my use cases, so from a scale standpoint, I have not encountered any problems or issues.

    How are customer service and support?

    Customer support has been great with Splunk Observability Cloud. The Splunk system team has always been there whenever there is an issue or problem. They have actually been very helpful in resolving those issues.

    I would rate the customer support for Splunk Observability Cloud a 10.

    Which solution did I use previously and why did I switch?

    I did previously use a different solution, which I believe was a custom-made solution built in-house. The reason for switching was mainly due to cost, and not only cost, but additional resources we had to add in order to customize that solution.

    How was the initial setup?

    I cannot say whether I had a return on investment. The return on investment is probably mostly tied to operational efficiencies that I discussed before. I cannot say I have seen a reduction in employees needed. I do have to have added additional resources to actually help support observability and Splunk Observability Cloud, but most of my efficiencies have come in being able to identify and detect issues when they happen.

    What about the implementation team?

    I do not get involved with pricing; my procurement organization deals with that. As it relates to setup, procurement actually gets involved and negotiates that. So I am not as intricately involved with that as my procurement colleagues.

    What was our ROI?

    I cannot say whether I had a return on investment. The return on investment is probably mostly tied to operational efficiencies that I discussed before. I cannot say I have seen a reduction in employees needed. I do have to have added additional resources to actually help support observability and Splunk Observability Cloud, but most of my efficiencies have come in being able to identify and detect issues when they happen.

    Which other solutions did I evaluate?

    I did evaluate other options along with Splunk Observability Cloud, with ScienceLogic being one of those. ScienceLogic and Splunk Observability Cloud were the two that were evaluated.

    What other advice do I have?

    My advice to others looking into using Splunk Observability Cloud is to clearly define your use cases and your intent, and then gradually work towards those. I would recommend not trying to take on too much at one time. Instead, take on small use cases at a time and then build on those. Then probably the last thing is to continue to go back and check to make sure Splunk Observability Cloud is actually meeting its intent and its need and actually capturing the right signals for your organization. I would rate this product a 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    Head of Observability at a financial services firm with 5,001-10,000 employees
    Real User
    Top 5
    Sep 19, 2026
    Full-stack observability has provided deep insights into cloud-native workloads and SRE operations
    Pros and Cons
    • "My impression of Splunk Observability Cloud's out-of-the-box dashboards and detectors is that the visualization looks excellent, and the implementation is straightforward."
    • "At this moment, Splunk Observability Cloud has not helped improve my operational performance or my company's resilience. I have not yet seen a return on investment from Splunk Observability Cloud."

    What is our primary use case?

    I started using Splunk Observability Cloud approximately one to two months ago. My main use case for Splunk Observability Cloud is for cloud-native workloads and OpenTelemetry. I am using Splunk Observability Cloud for Kubernetes workloads, and with OpenTelemetry, I want to determine if I can have the open source enabled.

    What is most valuable?

    The best features Splunk Observability Cloud offers are agent observability and the AI SRE agent, which appears promising. With agent observability, I can have the agent application observe with a full-stack view, and with the SRE agent, I can perform automatic root cause analysis and deep dives. I am about to start with Splunk Observability Cloud through a proof of concept, and it looks good.

    What needs improvement?

    The faster I adapt and implement all the changes in Splunk Observability Cloud would be helpful. I believe it is still in the early days of using Splunk Observability Cloud, so I need to see how the product works. I need to test the accuracy and reliability of output from Splunk Observability Cloud after the proof of concept. Overall, Splunk Observability Cloud needs to cover all native and legacy monitoring, and all the gaps I have seen with existing platforms need to be embedded along with business observability to help my organization scale.

    For how long have I used the solution?

    I started using Splunk Observability Cloud approximately one to two months ago.

    What do I think about the stability of the solution?

    Splunk Observability Cloud is stable.

    What do I think about the scalability of the solution?

    I will automate Splunk Observability Cloud through the CI/CD pipeline, so it should be fine in terms of scalability.

    How are customer service and support?

    The customer support for Splunk Observability Cloud is excellent. I would rate the customer support of Splunk Observability Cloud a nine on a scale of one to ten.

    Which solution did I use previously and why did I switch?

    I had been using AppDynamics before choosing Splunk Observability Cloud.

    How was the initial setup?

    Splunk Observability Cloud is still being deployed in my organization in a public cloud.

    What about the implementation team?

    I did not purchase Splunk Observability Cloud through the AWS Marketplace; I bought it through the vendor.

    What was our ROI?

    At this moment, Splunk Observability Cloud has not helped improve my operational performance or my company's resilience. I have not yet seen a return on investment from Splunk Observability Cloud.

    What's my experience with pricing, setup cost, and licensing?

    The pricing for Splunk Observability Cloud looks fine, and I believe the overall proposal that was provided looks great.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Splunk Observability Cloud.

    What other advice do I have?

    My advice to others looking into using Splunk Observability Cloud is that the tool appears promising, so I recommend pursuing it. Splunk Observability Cloud is still in its early days, and I need to see how it works over time. I am positioning Splunk Observability Cloud to be one of the bigger drivers for full-stack observability, and it is very important for my organization that it has end-to-end visibility into my cloud-native environments. My impression of Splunk Observability Cloud's out-of-the-box dashboards and detectors is that the visualization looks excellent, and the implementation is straightforward. I would give this product a rating of nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 19, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Splunk Observability Cloud
    August 2026
    Learn what your peers think about Splunk Observability Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
    913,924 professionals have used our research since 2012.
    Nishith Joshi - PeerSpot reviewer
    Dev Ops Engineer at Data Elicit Solutions Pvt. Ltd.
    Real User
    Top 5
    Mar 30, 2026
    Real-time monitoring has improved performance tracking and has simplified analyzing complex metrics
    Pros and Cons
    • "Splunk Observability Cloud has optimized our solutions and helped us understand the metrics."
    • "The learning curve for understanding all features should be improved, and the cost can increase."

    What is our primary use case?

    I work in data analytics with experience in monitoring systems and working with large-scale data. I have used Splunk Observability Cloud in the context of real-time monitoring and performance tracking.

    Splunk Observability Cloud works well alongside Splunk Enterprise for logs and integrates with cloud platforms and monitoring tools. It is often used together with other observability solutions. The tracking metrics such as latency, error, and throughput are easily visible. I can also build dashboards for real-time visibility.

    We use Splunk Observability Cloud to track latency metrics and identify where slowdowns are happening. We have visualized response time trends and quickly detected performance degradation. We have also used it for infrastructure monitoring. Over the past six months, we have been monitoring metrics such as CPU usage and memory. If there is unusual usage, we identify it quickly using this tool and take action before it impacts our performance.

    What is most valuable?

    Splunk Observability Cloud has optimized our solutions and helped us understand the metrics. The AI-powered guidance in Splunk Observability Cloud helps us identify patterns and anomalies in system performance data. Instead of manually going through a large volume of metrics, it highlights unusual behavior and potential issues automatically. This makes it easier to detect problems early and understand where to focus, especially in complex systems.

    There is definitely log analysis and dashboards. Log monitoring and dashboards have been better using Splunk. Splunk Observability Cloud is the best tool for log monitoring and dashboards. Splunk Observability Cloud feels more focused on real-time metrics and performance tracking compared to some other traditional log-based tools.

    What needs improvement?

    The learning curve for understanding all features should be improved, and the cost can increase. Splunk Observability Cloud is very costly. Cost is one of the drawbacks.

    Sometimes too many alerts, if not configured properly, is a major drawback that could be improved.

    The prices are quite high. As I have mentioned earlier, we are Splunk partners, so this has been handled by my other team. However, for other companies and small startups, the prices are very high for them to use Splunk Observability Cloud. Price is a concern.

    For how long have I used the solution?

    I have been working with Splunk Observability Cloud for the past six to eight months.

    What do I think about the scalability of the solution?

    We have expanded our team and usage. We are scaling up right now from ten people to twenty-five or thirty. Over time, I expanded my usage by going through basic monitoring and exploring things like setting up custom dashboards. We have gradually expanded our usage from setting up dashboards and alerts.

    How are customer service and support?

    For customer service, I would rate them eight out of ten because whenever we raise a support case, they are always available for us.

    For Splunk real user monitoring, implementation took time because our engineers tried very hard. In case of support, there should be more engineers specifically for this case.

    Which solution did I use previously and why did I switch?

    We have used different products like Palo Alto and Cribl before moving to Splunk Observability Cloud. As we got a partnership, we have shifted to Splunk Observability Cloud.

    What was our ROI?

    The information is confidential and I cannot share specific details. However, I can tell you in percentage that fifty to sixty percent of our work has been easy to identify in terms of performance metrics and performance using Splunk Observability Cloud.

    It has saved us thirty to forty percent in cost because we used some other tools before that were more costly. As we are Splunk partners, we obtained Splunk Observability Cloud, and our costs have been reduced by thirty to forty percent using this solution.

    What other advice do I have?

    My overall impression of using Splunk Observability Cloud is that it is a strong tool for real-time monitoring. It does take some time to get fully comfortable with all the features. We have not explored everything right now, but in the future, we are looking forward to using more features.

    A part of the implementation has been handled by my other team. I have explored using custom metrics to enrich observability data, mainly by adding application layer or business-related metrics alongside system metrics. I have used custom metrics in a limited way to add more context to monitoring, such as tracking application-specific metrics alongside system data.

    Dashboard customization in Splunk Observability Cloud is quite flexible. We care about metrics in different types of visualization, and it helps us organize them in a way that makes sense for monitoring. It allows us to build dashboards tailored to specific use cases. This makes it easier to monitor system performance and quickly identify issues without going through unnecessary data.

    The integration in real user monitoring from Splunk Observability Cloud is actually better than from some other tools. If you are looking for the best SIM tool, then Splunk Observability Cloud is for you. If you have funds and capability for the cost, then Splunk Observability Cloud is definitely the best tool you can use.

    I have given this review an overall rating of nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
    Last updated: Mar 30, 2026
    Flag as inappropriate
    PeerSpot user
    Senior Associate at a consultancy with 10,001+ employees
    Real User
    Top 5
    Jan 29, 2026
    Monitoring has become more proactive and cloud operations are managed with real-time insights
    Pros and Cons
    • "The solution has significantly helped improve my operational performance and my company's resilience by providing real-time insights."

      What is our primary use case?

      My use case for Splunk Observability Cloud is primarily for monitoring and cloud management, and it serves us well.

      What is most valuable?

      The best features in Splunk Observability Cloud that I appreciate the most include its comprehensive monitoring capabilities and its user-friendly interface.

      The solution has significantly helped improve my operational performance and my company's resilience by providing real-time insights. The enhancements to my operational performance and resilience are noticeable.

      It has saved me a considerable amount of time and resources by streamlining our monitoring processes.

      My impression of the AI-powered analytics and guidance provided by Splunk Observability Cloud is that they are very effective and enhance our decision-making.

      I do use the no-sample tracing feature to eliminate blind spots in data collection, and it is quite helpful.

      My team has effectively utilized the ability to enrich data with custom metrics to improve our analytical capabilities.

      The out-of-the-box customizable dashboards are effective, and they help showcase IT performance to business leaders quite effectively.

      What needs improvement?

      In Splunk Observability Cloud, the areas that have room for improvement include usability enhancements to make it even better.

      For how long have I used the solution?

      I have been using Splunk Observability Cloud for a considerable time, and I can share my experience with it.

      What do I think about the stability of the solution?

      Regarding stability, I would rate the stability of Splunk Observability Cloud as a 9, indicating it is very reliable. Splunk Observability Cloud performs exceptionally in terms of stability under varying conditions.

      How are customer service and support?

      From 1 to 10, I would rate the technical support as an 8 since it is generally responsive and helpful.

      How would you rate customer service and support?

      Positive

      What about the implementation team?

      The solution was purchased through a partner, and my experience with the partner has been generally positive. My experience with the partner has been satisfactory as they provided the needed support throughout the process.

      What was our ROI?

      My experience with lowering the cost of unplanned digital downtime has been positive as it has indeed reduced downtime.

      What's my experience with pricing, setup cost, and licensing?

      Regarding the pricing of Splunk Observability Cloud, while I believe it can be improved, I would rate it around 7, leaning towards being expensive.

      Which other solutions did I evaluate?

      I would compare Splunk Observability Cloud with other solutions as more feature-rich and user-friendly based on my concerns.

      What other advice do I have?

      For others looking into this product, I would recommend trying it out with a proof of concept to see its benefits firsthand.

      Approximately 50 users in my company use Splunk Observability Cloud to leverage its capabilities effectively.

      The solution does require some maintenance, but it is quite straightforward in managing it.

      In terms of my company's relationship with Splunk, we are currently a customer making the most of their offerings.

      I would rate Splunk Observability Cloud a solid 8 from 1 to 10 based on my experience and satisfaction with its performance.

      Which deployment model are you using for this solution?

      Hybrid Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Jan 29, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2787105 - PeerSpot reviewer
      Manager - Production Database Administration at a tech vendor with 10,001+ employees
      Real User
      Top 5Leaderboard
      Dec 17, 2025
      Log insights have boosted uptime and now drive automated remediation and pattern-based alerts
      Pros and Cons
      • "After moving to Splunk Observability Cloud, it is almost zero downtime."
      • "The feedback is that Splunk Observability Cloud is forcing me to modify my logs that I am ingesting in Splunk Observability Cloud in a specific format."

      What is our primary use case?

      I am using Splunk Observability Cloud as a log-based monitoring tool for my databases. We have ingested our database logs and OS system logs into Splunk Observability Cloud and are creating dashboards and alerting features over those alerts. One of my major use cases is that all kinds of databases I am currently working with have database logs that capture all information, warnings, and error messages. These database logs are moving to Splunk Observability Cloud. The first use case is that I no longer need to maintain a long list of flat files on my server for all those logs. Those can be directly ingested into Splunk Observability Cloud. The benefit I am seeing from here is that I can get pattern-based analysis of what kind of errors I am commonly getting and what the date patterns of those errors are. I can get dashboards over that and I can also create alerts. I can also incorporate those alerts with some back-end Git workflow for automatic remediation. This is one of the solutions.

      Another use case for Splunk Observability Cloud that we are seeing is that there are multiple times when there is a requirement to publish some kind of data. So instead of publishing an alert if those data breaches occur or if some kind of dashboard needs to be created, instead of sending data directly to the users, if that data is not PII, we are also ingesting that into Splunk Observability Cloud in a JSON format and then again, dashboards and other alerting can be created. These two are the main major use cases for which I am using Splunk Observability Cloud.

      How has it helped my organization?

      With the help of the alerting and observability mechanism, resiliency, and automatic automation of issue remediation based on alerts and workflows, it actually reduces the cost and increases the uptime of my system and customer satisfaction. There are multiple indirect benefits I am getting when using Splunk Observability Cloud.

      Currently, with the growth of the organization, I am seeing an increasing use of Splunk Observability Cloud in a more dynamic way. We are continuously creating new dashboards, ingesting logs in JSON, and trying to bring the best value out of it. I am seeing a dynamic and drastic increase in the use of Splunk logs and the Splunk data we are ingesting.

      There are two aspects to expanding the usage. Organic growth of the environment actually puts new systems into Splunk Observability Cloud, and exploring new opportunities for what all can also be ingested into Splunk Observability Cloud. Previously, I can see that memory dumps are there. We are also looking at whether we can ingest memory dumps so that if the system is about to crash, those memory dumps can be captured into Splunk Observability Cloud so that it can create alerts over that and I can also perform analysis. I can also see if any other system is facing the same kind of memory dump issues. So that maybe it is one alert for one system for me, but for the complete farm, there may be different servers with different teams or business units facing the same issues. When I have Splunk Observability Cloud on all systems, I can actually create a consolidated report and see that this is the pattern which particular farms are having this kind of issues, and maybe something is broken. This is the way the plan is to increase the availability or the usage of Splunk Observability Cloud.

      What is most valuable?

      The performance and speed are valuable. Previously when Splunk offered the enterprise solution, I needed to install Splunk and maintain my local server. There was a limitation that only a certain number of servers could be supported in one instance and I would need to have multiple instances if I was in an enterprise system setup. When I am in the cloud, a single instance can support N number of systems. It is pretty fast, no matter how much data is there. Dashboards are pretty good with multiple functions available. The alignment or integration that can trigger automatic solutions with the workflow for automatic remediation of the alerts is the best thing. These three or four things are the best Splunk Observability Cloud features that I am seeing.

      The point in time alerting, the point in time data capture, and automatic remediation with the integration of good workflows or Ansible workflows is definitely the key to any resiliency and increasing the uptime of any system.

      After moving to Splunk Observability Cloud, it is almost zero downtime. We never face downtime because when I was in the enterprise setup, I needed to maintain my servers and maintain hygiene of vulnerabilities, patches, and all. Now when I am in the cloud, everything is automatic. Almost zero downtime plus the perfect alerting feature and log-based analysis are available. Metrics alerting is also there in Splunk Observability Cloud through queries. This is one of the features that keeps me updated with the current health of my system and helps me to keep my system up and running fine and available for my customers.

      Splunk Observability Cloud incorporated a new AI agent feature that is really good. Sometimes I need to create queries and Splunk queries for filtering the data and some pattern-based analysis. This agent is really good in helping me and suggesting the queries. This means I do not need to have a Splunk expert or Splunk query expert. I can just ask that agent that I need pattern-based analysis or I need to create this kind of filters for this kind of data and it can suggest to me. Once it suggests a sample query to me, I can do the tweaking and I can have my data ready. It actually reduces my time to perform my analysis and to reach the conclusion about what exactly is causing issues in my system and what are the repetitive issues in my system. This AI feature really helps for newcomers to Splunk Observability Cloud to perform deep diving analysis with the data captured by it.

      Custom metrics are valuable. In Splunk Observability Cloud, some infra-level metrics are not available, but through custom metrics, I can achieve it. This is an add-on feature that Splunk Observability Cloud is providing and without any additional monitoring tool. If that feature was not there, then I would need to plan some other monitoring tool for metrics-based alerting, but this custom one helps me to achieve it in the same monitoring tool. The consolidation and integration of metrics-based alerting and log-based alerting in a single tool is actually the lovable feature. I do not need to worry about or look for multiple tools. I can have my own data and own health available in a single tool, in a single view.

      What needs improvement?

      The dashboards are good, but the only limitation I see currently is that they need particular formats only to create a dashboard. They need to have a particular JSON format or time series format. This sometimes creates additional work for me so that when I am ingesting logs in Splunk Observability Cloud, it should be in a specific format. Either Splunk Observability Cloud should have multiple formats available or multiple dashboards available for different kinds of formats. At least Splunk Observability Cloud has everything available at a Splunk level. They can do some kind of analysis and see what are the major top ten or top twenty types of logs they are getting and they can have dashboards according to those logs. Instead of forcing customers to design their logs in the way of Splunk Observability Cloud, Splunk Observability Cloud can create dashboards based on the customer requirement. This will actually ease things up for the end users.

      The current dashboards are good. The feedback is that Splunk Observability Cloud is forcing me to modify my logs that I am ingesting in Splunk Observability Cloud in a specific format. If Splunk Observability Cloud can leverage it and make it open for any format, that would be great. If that is not feasible, at least the top ten or top twenty logs that Splunk Observability Cloud is getting should be readable by Splunk Observability Cloud without any changes. That actually is one of the major feedback items I can provide which can actually ease the life of the end users or any layman. As a newcomer to Splunk Observability Cloud, I may not know JSON. I now need to hire someone or I need to look for someone who knows JSON and who can convert my logs into JSON format and then I will ingest them into the logs if I want to create a dashboard. If I do not want to create a dashboard, that is okay. On the other hand, Splunk Observability Cloud is giving me a usability and easy to go interface, but for a dashboard, I need to have an understanding of JSON so that I can ingest the log in JSON format. That is a dilemma that they have and they should work on.

      Currently, Splunk Observability Cloud is not the only solution which any organization is using. There is also Grafana and PagerDuty. If Splunk Observability Cloud can plan some kind of integration with PagerDuty and Grafana, then those things can be controlled from a single position and if something else is happening at one location, it can update things at all levels. That can also bring great value to the users. Currently, I have to maintain three systems separately, but if some kind of integrations can be developed with these three vendors, then that can be a great thing because all these three have now become the industry pillars or industry standards for observability and resiliency.

      For how long have I used the solution?

      I have been working with it for the last two years. Before that, it was an enterprise solution. Now it is cloud-based.

      What do I think about the stability of the solution?

      I cannot relate any stability issues to my experience with Splunk Observability Cloud.

      What do I think about the scalability of the solution?

      Scalability is pretty smooth. I just need to deploy the Splunk forwarder and the config file that specifies which servers it should connect to and it will get connected. My data will start populating. It is pretty straightforward. I do not see any challenges there, even when it was in enterprise and now when it is in the cloud. The deployment and onboarding of new servers and ingesting the logs is pretty straightforward. Anybody can learn it within a day without having any prior knowledge.

      How are customer service and support?

      We have raised multiple questions when we face any issues. Our support is prompt and usually within a day, I will get my answers.

      Which solution did I use previously and why did I switch?

      Previously I was on Splunk Enterprise. I have been using Splunk for seven to eight years before we moved to the cloud in the last eighteen months.

      How was the initial setup?

      The initial setup is pretty smooth. I just need to deploy the Splunk forwarder and the config file that specifies which servers it should connect to and it will get connected. My data will start populating. It is pretty straightforward. I do not see any challenges there, even when it was in enterprise and now when it is in the cloud. The deployment and onboarding of new servers and ingesting the logs is pretty straightforward. Anybody can learn it within a day without having any prior knowledge.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
      PeerSpot user
      reviewer2756085 - PeerSpot reviewer
      Software Developer And Engineer at a retailer with 5,001-10,000 employees
      Real User
      Top 20
      Sep 11, 2025
      Has improved performance by enabling better troubleshooting and infrastructure visibility, but interface and deployment challenges remain
      Pros and Cons
      • "Customer service and technical support respond very quickly."
      • "The RUM part of Splunk Observability Cloud can be improved significantly."

      What is our primary use case?

      Our main use cases for Splunk Observability Cloud are to observe our application, our websites, and our infrastructure metrics.

      What is most valuable?

      What I appreciate the most about Splunk Observability Cloud is the APM part and the log analytics part. These features can help us with troubleshooting our problems between multiple systems. 

      Distributed tracing is very useful to us, and the infrastructure part can help us identify problems with the infrastructure. Splunk Observability Cloud has helped improve our operational performance and our company's resilience on the path of adopting it, and I expect more improvements in the future.

      What needs improvement?

      The RUM part of Splunk Observability Cloud can be improved significantly. We are currently struggling to use it since our application is mixed mobile and non-mobile. Some AI features in the search functionality could be beneficial in the next release of Splunk Observability Cloud.

      In GCP, Cloud Run is not natively supported by Splunk, and we are challenged with bringing data from Cloud Run to Splunk. Native support of it in the future would be great for us.

      For how long have I used the solution?

      We started using Splunk Observability Cloud one year ago.

      What do I think about the stability of the solution?

      I would assess Splunk Observability Cloud as quite reliable. The only problem is the graphical interface, which sometimes is buggy. It crashes, doesn't display data, and requires reloading the browser. I have experienced downtime with Splunk Observability Cloud only once, which lasted one hour due to issues that prevented us from logging into the platform.

      What do I think about the scalability of the solution?

      Splunk Observability Cloud scales with the growing needs of our organization quite efficiently. I have expanded the usage of Splunk Observability Cloud, and the process of expanding usage was smooth apart from one part.

      How are customer service and support?

      Customer service and technical support respond very quickly. That said, sometimes the solutions take too long to implement.

      How would you rate customer service and support?

      Neutral

      Which solution did I use previously and why did I switch?

      Before adopting Splunk Observability Cloud, we used DataDog, and before that, we had no solution. The factors that led me to consider the change were mainly because my company has different IT offices. My IT office used DataDog, another IT office used New Relic, and others used different tools. We needed to adopt Splunk across the group to have something standard in my company.

      How was the initial setup?

      My experience with deploying Splunk Observability Cloud was quite good, mainly since we almost have everything on cloud and that makes deployment quite easy.

      What other advice do I have?

      My advice to other organizations considering Splunk Observability Cloud is to adopt it if you don't have anything else as it's a very good tool, and having something for observability is very good. Not only for the observability part but for all the Splunk platform, that's great. 

      On a scale of one to ten, I rate Splunk Observability Cloud a seven out of ten.

      Which deployment model are you using for this solution?

      Hybrid Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Google
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Jack Weekly - PeerSpot reviewer
      Security Eng at Nebraska Medicine
      Real User
      Top 5
      Sep 11, 2025
      Custom dashboards and detailed searches have improved operational visibility
      Pros and Cons
      • "Splunk Observability Cloud scales with the growing needs of my organization effectively."
      • "Splunk Observability Cloud has helped improve my operational performance; previously, we used Elastic for similar purposes, and this has allowed us much more visibility into what we're working on with usable dashboards and metrics, which has been awesome."
      • "The only strain point we've encountered with Splunk Observability Cloud is that the search times can be lengthy for some things. We have a large environment, so that's expected."

      What is our primary use case?

      I use Splunk Observability Cloud for network logging analysis.

      What is most valuable?

      I prefer the dashboard building and search features of Splunk Observability Cloud the most. Splunk Observability Cloud has helped improve my operational performance. 

      Previously, we used Elastic for similar purposes as Splunk Observability Cloud, and this has allowed us much more visibility into what we're working on with usable dashboards and metrics, which has been awesome.

      What needs improvement?

      The only strain point we've encountered with Splunk Observability Cloud is that the search times can be lengthy for some things. We have a large environment, so that's expected. That's the only complaint I've had so far.

      For how long have I used the solution?

      I have been using Splunk Observability Cloud for approximately three months.

      What do I think about the stability of the solution?

      I experience slow searches occasionally with Splunk Observability Cloud, but there are no outages or anything in that regard, so it is pretty stable and reliable.

      What do I think about the scalability of the solution?

      Splunk Observability Cloud scales with the growing needs of my organization effectively. As a large organization, we find it impressive that our volume has been handled with only occasional slow searches.

      How are customer service and support?

      I haven't worked with customer service and technical support directly, however, another engineer on the team has shared positive feedback about their experiences.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      Prior to adopting Splunk Observability Cloud, I was using Elastic. Support was a significant factor that led to switching to Splunk Observability Cloud. The previous solution wasn't fully supported by their team, and there weren't adequate integrations or visibility needed for some of our applications. Additionally, it was a legacy installation set up by former employees, so this was an opportunity to start fresh with people who are actively involved.

      What was our ROI?

      We haven't had Splunk Observability Cloud long enough for me to make substantial comments on its effectiveness in improving digital resilience within my organization.

      What's my experience with pricing, setup cost, and licensing?

      I wasn't involved in the licensing. 

      What other advice do I have?

      We haven't used the no-sample tracing feature in Splunk Observability Cloud specifically for eliminating blind spots in data collection. We haven't implemented the AI-powered analytics and guidance features provided by Splunk Observability Cloud either.

      Our main security architect has done extensive work utilizing the ability to enrich data with custom metrics in Splunk Observability Cloud by setting up specialized dashboards and searches for our various integrated apps, including ISE and Palo firewall logging.

      I haven't extensively used the out-of-the-box customizable dashboards provided by Splunk Observability Cloud as we're still using our custom ones. I wasn't involved in the pricing, setup, cost, and licensing. I enjoy using Splunk Observability Cloud, but I'm not familiar with the cost aspects.

      Access to Splunk Observability Cloud has been reliable for all users. On a scale of one to ten, I rate Splunk Observability Cloud an eight. 

      I recommend spending time working on your own dashboards and searches to fit your business needs, as that's where you'll get the most value out of Splunk Observability Cloud.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Jeremy Fields - PeerSpot reviewer
      Senior Platform Engineer at a tech vendor with 11-50 employees
      Real User
      Top 20
      Sep 14, 2026
      Monitoring microservices has provided end-to-end visibility and now improves issue resolution
      Pros and Cons
      • "Splunk Observability Cloud has allowed us to consider piping in data from the companies we have acquired as well to get the single pane of glass situation as we continue to build and grow the company."
      • "There is a pretty steep learning curve with Splunk Observability Cloud."

      What is our primary use case?

      My main use case for Splunk Observability Cloud at my current company is monitoring apps. We have a lot of microservices because we sell different SaaS solutions to businesses, so monitoring, tracing, and everything related to that is essential given our microservices architecture.

      We have traces and a service map set up where currently we only have two of the apps onboarded. The goal is to get the other four or five apps onboarded so we can have a single pane of glass view of how all of our apps work, how they're all connected, and how the traffic flows through them.

      What is most valuable?

      The best features Splunk Observability Cloud offers include in-depth capabilities. From going over it at the boot camp these last two days, there is definitely a learning curve, which could be a positive or negative. It's a positive thing because there are so many features, and it definitely takes a little time to get ramped up, but it is feature-rich with any feature one could think of, whether it's monitoring backends, frontends, or RUM metrics.

      Regarding the RUM metrics feature, I'm not entirely sure yet, but we definitely have users of our SaaS solutions, so I can see it being useful to see how our apps load for users, how they are liking them, and what their sessions are like so we can research what it's from our end users' point of view.

      I'm still relatively new, but I consider pricing one of the positives of how Splunk Observability Cloud has impacted my organization. From what I hear, they were using DataDog, and the pricing was very obscure, so they made a pivot to Splunk for pricing reasons. That combined with giving us clearer insights into the apps has been beneficial.

      Clear insights are important because we host in AWS using ECS Fargate. It's difficult to rely on CloudWatch alone to trace everything that's going on with the apps running in the containers.

      What needs improvement?

      There is a pretty steep learning curve with Splunk Observability Cloud. There is a lot going on, which has pros and cons. The pros include the abundance of offerings in Splunk Observability Cloud, but the cons are that there is so much to learn that you need full-day boot camps just to really understand it.

      I feel there is a lot going on, and I think some things could be simplified for certain, particularly the menus and how to accomplish things. Additionally, my understanding is that it is expensive to get infrastructure data into it, though I'm not sure if that's AWS's fault or Splunk's. My opinions may change since I just started using the product.

      For how long have I used the solution?

      I've just started using Splunk Observability Cloud as I'm new at this company. I previously worked at Choice Hotels for practically my entire tech career. I started at this new company about a month and a half ago, and they use Splunk. I'm at the annual Splunk conference doing a three-day boot camp to learn Splunk Observability Cloud because we use it at this new company. I've been using it for approximately a month at this point.

      What do I think about the stability of the solution?

      Splunk Observability Cloud is stable.

      What do I think about the scalability of the solution?

      Splunk Observability Cloud's scalability appears to be infinite from my understanding since it's a SaaS solution, so Splunk will ingest as many logs as we can send. I have heard that there are some limits on things, but I imagine if we pay for it, we can scale as large as we want.

      How are customer service and support?

      I have not used customer support, but the people I've interacted with here today at the conference have been great, so I can imagine it's more of the same.

      Which solution did I use previously and why did I switch?

      At this company they used DataDog, but at my previous company, we used OpenSearch.

      How was the initial setup?

      I wasn't here when the setup, pricing, and licensing happened. However, I have heard that it was cheaper than DataDog, which is why we switched.

      What was our ROI?

      I have seen a return on investment in terms of time saved. I don't have hard numbers, but using the MCP server has saved me a ton of time. I'm able to multitask and do some work on the side while querying Claude to pull data and traces, which comes back to me rather than me having to manually do it and have that take my full attention.

      What other advice do I have?

      Splunk Observability Cloud has helped improve my operational performance. I'm quite new, but I would definitely say it has improved operationally. I already got Claude hooked up to Splunk Observability Cloud and the regular Splunk Cloud MCP servers, which has helped me tremendously to be able to track down issues and traces, which could have taken me much longer to do manually.

      It's really important for my organization that Splunk Observability Cloud has end-to-end visibility into our cloud-native environment. Otherwise, we're flying blind, especially because some of these new products we're about to release in an early release program require us to know what we're doing and to hit it out of the park to make it a success.

      To help our organization scale, we only have two apps piped into it so far. We have acquired a couple of other companies, so Splunk Observability Cloud has allowed us to consider piping in that data as well to get the single pane of glass situation as we continue to build and grow the company.

      I haven't noticed any specific outcomes or improvements in lowering the cost of unplanned digital downtime using Splunk Observability Cloud yet. I haven't done a traditional on-call role yet because I'm new to this company. We are beginning our on-call rotation, and I will definitely be leaning on Splunk Observability Cloud more heavily as I am on call and handling outages and after-hours calls. The solution's out-of-the-box dashboards and detectors are great. I'm doing the boot camp at the conference, and creating dashboards and filtering was probably my favorite part. Learning the roll-ups and the functions and how all of that works was excellent. The detectors seem very easy to create, and I appreciate how it creates a border on a chart when that chart is in the alert state.

      I haven't really looked into the AI capabilities too much. I have used the AI tool that can help me write SPL, but that's about it. I typically use the MCP server for it and plug it into Claude, which has been my main way to interact with it from an AI perspective.

      Regarding the accuracy and reliability of output from Splunk Observability Cloud's AI capabilities, I haven't used it too much beyond creating SPL, and so far there are no issues to report.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 14, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2756127 - PeerSpot reviewer
      Avp at a financial services firm with 5,001-10,000 employees
      Real User
      Top 10
      Sep 13, 2025
      Supports end-to-end monitoring and improves reliability through core metric insights
      Pros and Cons
      • "We utilize the APM and auto-detectors, as the core metrics and core alerts are available for us, which are the features of Splunk Observability Cloud that I appreciate the most."
      • "The integrations need to be improved for Splunk Observability Cloud."
      • "There's a lot of talk about AI-powered analytics and guidance in Splunk Observability Cloud. I didn't get a great sense of how much of it is actually working; there are a lot of AI hallucinations."

      What is our primary use case?

      My main use case is end-to-end monitoring for the application.

      What is most valuable?

      We utilize the APM and auto-detectors, as the core metrics and core alerts are available for us, which are the features of Splunk Observability Cloud that I appreciate the most.

      We lead the SRE, so our job is to ensure reliability, stability, and uptime, and without good observability monitoring, there is no way we can accomplish that. This is the main tool that we would use.

      I would evaluate the effectiveness of Splunk Observability Cloud in improving digital resilience by saying that the idea is to minimize incidents. If any incident happens, the first thing I would do is go back to see why Splunk Observability Cloud did not detect that. I will take it back, do the reverse engineering to find out where it was missed out, and then work with the team to ensure these things are identified.

      I have yet to experience the No-Sample Tracing feature in Splunk Observability Cloud, however, I am only in conversation with the teams where distributed tracing is required, and we want to provide the traces. My teams utilize the ability to enrich data with custom metrics in Splunk Observability Cloud, and I appreciate the feature supported within the Observability Cloud. Custom metrics could also be introduced from within the microservices, so I am yet to explore the OTEL library. I gave this feedback to the Splunk team that they should have their dedicated .NET library that customers can embed and start using; I do not think that is there today.

      We are the first project within the company for a fully cloud-native application, so we will set the ground for the rest of the teams to get motivated. Therefore, I expect that I will have the best experience to become an example for others.

      What needs improvement?

      The integrations need to be improved for Splunk Observability Cloud. Currently, they do not have great support for Azure. We are on Azure, and I know they invested a lot of time in AWS yet not in Azure.

      I had given feedback to the teams here, as the integration from Azure Cloud, how we supply the logs and the metrics, is not clearly documented yet, which was acknowledged by the team. For example, the OTEL collector has a thousand parameters, and we need a very specific use case with 10 parameters required for our integration. We can't go through the thousand parameters; we can, however, that is basically why I think some integrations need to get better for Azure.

      There's a lot of talk about AI-powered analytics and guidance in Splunk Observability Cloud. I didn't get a great sense of how much of it is actually working; there are a lot of AI hallucinations. I think it probably needs much more improvement to contextualize it so that it is very clear and precise about what it randomly thinks, but it needs to match the context better.

      Customer service and technical support need some improvement. We had issues with technical support, and the professional services were struggling as well.

      For how long have I used the solution?

      I've been using Splunk Observability Cloud for six months.

      What do I think about the stability of the solution?

      I would assess the stability and reliability of Splunk Observability Cloud by saying no crashes or performance issues have been experienced.

      How are customer service and support?

      On a scale of one to ten, I would rate customer service as eight.

      How would you rate customer service and support?

      Positive

      How was the initial setup?

      My experience with deployment has been good. It's just the routing, the matrices, and the integration is where we were struggling a little bit. That said, having the cloud as observed to provision was never a problem.

      What was our ROI?

      I hope to see a return on investment with Splunk Observability Cloud. I have not applied this for production. That said, we already use Splunk Cloud for production, and we are good with that, so I see the value.

      What's my experience with pricing, setup cost, and licensing?

      The cost is fine, and we are good with what is given. It's a centralized tool for my organization, so at the org level, a lot of things were decided, but we are actually happy with the cost we received because I know I have to approve my budget, and it's within our range, so we are okay with it.

      What other advice do I have?

      My advice to Splunk is to mix Splunk Cloud and Splunk Observability Cloud into one. Don't make oObservability only needed in Splunk Cloud, too. You don't want to have two products competing with each other; you want to compete with someone outside your organization. Combine this, as there's a lot of confusion. Even in different classes and training sessions meant only for Splunk Cloud, they were not for Splunk Observability Cloud, and they are different today. The acquisition of SignalFx, which is not its own, adds to the confusion. So, to the customer, provide one interface, and combine them.

      On a scale of one to ten, I rate Splunk Observability Cloud an eight overall.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Microsoft Azure
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Solution Architect at a tech vendor with 10,001+ employees
      Real User
      Top 20
      Sep 16, 2026
      Observability has enabled precise AI token tracking and has reduced incident resolution time
      Pros and Cons
      • "A problem that previously took four to five hours is now completed automatically through Splunk Observability Cloud and DevOps SRE agent integration in just a couple of minutes."

        What is our primary use case?

        My main use case for Splunk Observability Cloud is tracking details for AI agent spending that has been occurring in recent days. My goal is to break down these spends and understand where tokens go, who consumes them, and how to maximize this usage.

        Splunk Observability Cloud helps me track and break down AI agent spending through a framework I have built where I map all LLM calls to OTel collectors and then send them to Splunk Observability Cloud, adding team names, team tags, environment, and related information. This helps us track how much work has been completed, how it is being used, and if there is any possibility of an agent going out of control, we can detect it and stop it.

        I am looking forward to more releases for Splunk Observability Cloud for AI agents through this conference.

        What is most valuable?

        The best features Splunk Observability Cloud offers are the dashboards where I can view all metrics and telemetry. What I value most about the dashboards is both the visualization and customization capabilities along with the depth of data I can access from what we have gathered. I can drill down into exact details and view graphs and charts.

        Although I have not used Splunk Observability Cloud in my own organization, I use it to help my customers leverage Splunk Observability Cloud. It has been helpful for them as they transition from different platforms to Splunk, and I am able to assist them in porting to Splunk Observability Cloud and support them in making these decisions.

        My customers have benefited from moving to Splunk Observability Cloud through specific integrations with AI agents and MCP gateways, allowing them to correlate any incident directly from Splunk Observability Cloud to their DevOps agent and take action on it. A problem that previously took four to five hours is now completed automatically through Splunk Observability Cloud and DevOps SRE agent integration in just a couple of minutes.

        The metrics and outcomes from this improvement include significant reductions in incident time and mean time to resolution has decreased, freeing up engineering hours that were previously required, allowing teams to focus on other priorities.

        What needs improvement?

        I would like to see Splunk Observability Cloud move more into the AI agent space and help shape the future of AI spending and how tokens are being consumed. A breakdown between input, output, and cache tokens would be helpful.

        I would also like to see integration with some existing open source platforms, which would be valuable for integrating with not just large platforms but also smaller ones that might become open-source in the future. I think Splunk already does this effectively with the OTel collector.

        For how long have I used the solution?

        For the past one year.

        What do I think about the stability of the solution?

        Splunk Observability Cloud is stable.

        What do I think about the scalability of the solution?

        Splunk Observability Cloud's scalability is very good.

        Which solution did I use previously and why did I switch?

        My customers previously used DataDog before switching to Splunk Observability Cloud due to a company mandate that led to their transition.

        How was the initial setup?

        My experience with pricing, setup cost, and licensing through AWS Marketplace is that it is straightforward.

        What about the implementation team?

        I am both a partner and reseller with this vendor.

        What's my experience with pricing, setup cost, and licensing?

        My customers did not purchase Splunk Observability Cloud through AWS Marketplace.

        What other advice do I have?

        Splunk Observability Cloud has helped reduce mean time to detect (MTTD) and mean time to resolution (MTTR) has decreased from hours to minutes because of the integration available with other AI agents as an MCP.

        It is very important for my customers that Splunk Observability Cloud provides end-to-end visibility into their cloud native environments. Having this visibility helps them avoid relying on multiple third-party products and maintain a comprehensive product portfolio.

        I assess Splunk Observability Cloud as an effective solution for helping organizations scale and it provides better support through various levels.

        My advice for others considering Splunk Observability Cloud is to look at the full suite of products, not just Splunk Observability Cloud itself. Splunk offers many other solutions including security, SIEM, and other capabilities, so it is worth exploring the complete portfolio. I would rate this solution an eight out of ten.

        Which deployment model are you using for this solution?

        Public Cloud

        If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

        Disclosure: My company has a business relationship with this vendor other than being a customer. Partner, Reseller
        Last updated: Sep 16, 2026
        Flag as inappropriate
        PeerSpot user
        Buyer's Guide
        Download our free Splunk Observability Cloud Report and get advice and tips from experienced pros sharing their opinions.
        Updated: August 2026
        Buyer's Guide
        Download our free Splunk Observability Cloud Report and get advice and tips from experienced pros sharing their opinions.