Listing Thumbnail

    Splunk Cloud

     Info
    Sold by: Splunk 
    Deployed on AWS
    If you are looking for security and operational visibility across your AWS environment including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more then Splunk Cloud is the right solution for you.
    4.2

    Overview

    If you're looking for security and operational visibility across your AWS environment - including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more - then Splunk Cloud is the right solution for you. Organizations of all sizes leverage Splunk visibility with AWS agility to rapidly troubleshoot applications, ensure security and compliance, and monitor business-critical services in real-time. Splunk Cloud makes it easy to gain end-to-end visibility across your AWS and hybrid environment. Leverage Splunk Cloud with the free Splunk App for AWS to gain critical security, operational and cost optimization insight into your AWS deployment. Whether you're managing applications, infrastructure or a security operations center in the cloud, Splunk delivers Operational Intelligence for a real-time understanding of what's happening across your business and IT so you can make informed decisions. It's easy to get started - and remember - when choosing a product option, match your location and anticipated index volume per day. Splunk Cloud is now FedRAMP authorized: Moderate

    Highlights

    • Collect and index any machine-generated data from virtually any source or location in real time. Just point Splunk Cloud at your data, and it immediately starts collecting and indexing so you can start searching and analyzing.
    • Splunk Cloud offers single-pane-of-glass visibility across on-premise Splunk Enterprise and Splunk Cloud deployments, enabling customers to deploy Splunk as software or SaaS according to their business requirements, while maintaining centralized visibility.
    • Splunk Cloud includes support for Splunk apps and other content. Splunk apps deliver a targeted user experience for different roles, use cases and enterprise technologies. These apps can help you visualize data in new ways or provide pre-defined views of leading technologies such as Linux, Windows, VMware and more.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (20)

     Info
    Dimension
    Description
    Cost/12 months
    US - 5GB/Day
    Index Volume
    $8,100.00/GB
    US - 10GB/Day
    Index Volume
    $13,800.00/GB
    US - 20GB/Day
    Index Volume
    $24,000.00/GB
    US - 50GB/Day
    Index Volume
    $50,000.00/GB
    US - 100GB/Day
    Index Volume
    $80,000.00/GB
    EMEA - 5GB/Day
    Index Volume
    $9,315.00/GB
    EMEA - 10GB/Day
    Index Volume
    $15,870.00/GB
    EMEA - 20GB/Day
    Index Volume
    $27,600.00/GB
    EMEA - 50GB/Day
    Index Volume
    $57,500.00/GB
    EMEA - 100GB/Day
    Index Volume
    $92,000.00/GB

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Splunk offers a variety of support options to help ensure your success.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Data Anonymization, Data Security and Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    7 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Real-time Data Collection and Indexing
    Collects and indexes machine-generated data from virtually any source or location in real time with immediate search and analysis capabilities.
    Multi-deployment Visibility
    Provides single-pane-of-glass visibility across on-premise and cloud deployments, enabling centralized monitoring across hybrid environments.
    AWS Service Integration
    Supports integration with AWS services including CloudTrail, Config, and VPC Flow Logs for comprehensive AWS environment monitoring.
    Pre-built Application Support
    Includes support for Splunk apps with pre-defined views for leading technologies such as Linux, Windows, and VMware.
    FedRAMP Authorization
    Maintains FedRAMP Moderate authorization for compliance with federal security standards.
    Real-time Data Collection and Indexing
    Collects and indexes machine-generated data from virtually any source or location in real time with automatic indexing upon data ingestion.
    Complex Event Correlation
    Correlates complex events spanning multiple diverse data sources using time-based correlations, transaction-based correlations, sub-searches, lookups, and joins.
    Scalable Data Processing
    Scales to collect and index tens of terabytes of data per day with distributed computing architecture.
    High Availability Clustering
    Provides clustering technology for availability and fault tolerance across distributed computing environments.
    Machine Data Search and Analysis
    Enables searching, analyzing, and visualization of machine data generated by IT systems and technology infrastructure across physical, virtual, and cloud environments.
    Data Routing and Destination Management
    Routes data to multiple destinations with capability to deliver specific data to targeted tools while archiving full fidelity data to cost-effective storage
    Data Optimization and Reduction
    Reduces data streams by up to 50% through removal of unused log and metric data
    Event Processing and Transformation
    Processes event data through centralized parsing with capabilities to route, optimize, reformat, and enrich data in flight
    Role-Based Access Control
    Implements role-based access control with support for external authentication via LDAP, Splunk, and OpenID Connect identity providers
    Real-Time Monitoring and Configuration
    Provides GUI-based configuration and testing interface with live data capture and real-time observability pipeline monitoring

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    73 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    47%
    51%
    3%
    0%
    0%
    31 AWS reviews
    |
    42 external reviews
    External reviews are from PeerSpot .
    Swatispm

    Cloud security projects have been streamlined and incident investigations gain clear visibility

    Reviewed on May 19, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have been working in cyber security for a significant period. I have completed projects in cyber security as well as IT program management. I have hands-on experience with Splunk Cloud Platform  based on my education and practical application.

    My main use case for Splunk Cloud Platform  involves completing numerous projects in cyber security and management of programs. I have utilized Splunk Cloud Platform for over two years.

    What is most valuable?

    In my opinion, the best features Splunk Cloud Platform offers are evident through the customer projects I have worked on. Over the last year, we completed major projects utilizing the platform.

    Splunk Cloud Platform has been instrumental in my projects, and both Splunk Cloud Platform and Splunk Enterprise  have powered many different kinds of projects I have completed. The features of Splunk Cloud Platform that are worth noting include investigation capabilities, data creation, data boards, and graphic generation, along with our system integration.

    Splunk Cloud Platform has positively impacted my organization in the security operation center during incident response exercises where we work as a team, functioning as both a blue team and a red team.

    What needs improvement?

    I believe Splunk Cloud Platform can be improved as this project has helped me understand how the system works.

    For how long have I used the solution?

    My main use case with Splunk Cloud Platform has been over two years.

    What other advice do I have?

    I can explain how the incident happened and how to prioritize incidents accordingly.

    On a scale of one to ten, I would rate Splunk Cloud Platform a ten out of ten because the projects are very interesting, and during this project, I found it easy to work with. Splunk Cloud Platform is the easiest solution we found; every time we worked with Splunk and other IBM solutions, it proved to be reliable.

    In my organization, Splunk Cloud Platform is easy to work with and easy to understand. It can be deployed as public cloud, private cloud, hybrid cloud, or on-premises. The cloud provider I use with Splunk Cloud Platform is easy to understand and helps identify threats.

    My impressions of the solution's visibility into multiple environments, such as cloud, on-premises, and hybrid, are that Splunk Cloud Platform offers the best option and provides multi-tenant capabilities from a multi-tenant perspective. I would rate this review a ten out of ten.

    reviewer2805510

    Unified log analytics has transformed security monitoring and cuts breach detection to minutes

    Reviewed on May 08, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Splunk Cloud Platform  is my main use case, which we sell to our channel partners within the channel community that then sell it to their customers, primarily as a cloud-based platform that collects data, analytics, and monitoring. It is mainly used for log management, security monitoring, known as SIEM , IT operations monitoring, and customers can use it for infrastructure troubleshooting and compliance reporting, but primarily for getting real-time analytics. It is a useful SaaS cloud-hosted tool that manages infrastructure, upgrades, scaling, and maintenance for customers.

    A specific example of how a customer uses Splunk Cloud Platform  in their day-to-day operations is how it collects logs from Linux, Windows servers, Azure , and AWS . Teams can run powerful searches using SPL, search processing language, to find failed logins, investigate outages, and trace application errors. It also automatically alerts the team for system failures, CPU spikes, security threats when they occur, and API slowdowns, showcasing just a couple of examples of what our customers use Splunk Cloud Platform for.

    Splunk Cloud Platform provides a complete picture regarding how customers use it. It includes capabilities around machine learning and dashboards that allow them to monitor KPIs, have a real-time operational view, and executive reporting from all the logs.

    What is most valuable?

    Splunk Cloud Platform's best features include its scalability, as it can handle terabytes of data and is probably one of the market leaders within SIEM  capability, which is very strong. In this day and age, cybersecurity products need great integration, and it has a huge ecosystem that can integrate with over 1,200 integrations and applications. Another major positive is that it is cloud-managed, which means less infrastructure management. Finally, the main feature that many people value, and our customers provide feedback on, is real-time analytics with fast detection and troubleshooting.

    Splunk Cloud Platform has positively impacted my organization by reducing the need for infrastructure management due to being a SaaS cloud platform. The main use case is detecting cyber attacks faster. For example, a large financial institution, a bank, used Splunk Cloud Platform and identified failed logins, impossible travel events, VPN anomalies, and endpoint alerts when attackers attempted credential stuffing. Without Splunk Cloud Platform, those alerts existed in multiple systems, and detection could take days, but with it, events were correlated correctly and raised a single notable event, triggering alarms immediately. This significantly improves mean time to detect and respond, reducing investigation time from hours to just 10 to 30 minutes for common incidents by providing a single pane of glass visibility for SOC teams.

    What needs improvement?

    Splunk Cloud Platform has areas for improvement, including the fact that it is obviously an enterprise tool and can be expensive, which is the biggest complaint I have noted. Costs can rise due to high data ingestion and long retention periods, along with a complex licensing structure that makes pricing difficult to predict as usage grows, especially since more systems send logs. There are also performance concerns at scale where users have reported slower searches and expensive long-term storage needs, particularly in multi-terabyte environments. Additionally, operational complexity exists as enterprises still need to do data onboarding, create dashboards, handle retention policies, access control, and performance tuning.

    These are the three key areas of improvement I have identified.

    For how long have I used the solution?

    I have been using Splunk Cloud Platform for approximately three to four years at various different places of work.

    What do I think about the stability of the solution?

    Splunk Cloud Platform is undeniably stable, which is one of its key advantages. While it may come with a high price tag and face scalability issues, its stability is commendable, enabling easy visibility into logs, effective data ingestion, and successful operations with diverse integrations and third-party platforms.

    What do I think about the scalability of the solution?

    My customers typically leverage scalability and integration features across the main cloud providers, primarily AWS , integrating with CloudWatch, CloudTrail , S3 , and Lambda for cloud security monitoring and audit logging. They also integrate with the entire Microsoft stack, including Defender for Cloud, Sentinel , Azure  ID, and Azure Monitoring, as well as Google Cloud , where GCP  integrates with Cloud Logging and Pub/Sub security command center. We also have integrations with major SIEMs including Sophos, CrowdStrike, and firewalls from Palo, Fortinet, Cisco, and Juniper, and identity management tools including Okta, Ping, and Duo. For threat intelligence, we get much of our integration from Recorded Future  as our main integration, but they are just some of the top ones we integrate with effectively.

    Splunk Cloud Platform's scalability works well, especially for smaller businesses, but can present issues for larger enterprises facing stricter regulations and greater integration requirements.

    How are customer service and support?

    Customer support with Splunk Cloud Platform is really good. The CSMs and account managers in the channel team are great, providing assistance not just with selling the product but also for implementation, deployment, and aftercare. I would rate customer support a nine on a scale of one to ten. There have been a couple of instances where issues arose, which is why it does not earn a full ten, but overall, it stands out as a really good platform and contributes to why they remain number one in the business.

    Which solution did I use previously and why did I switch?

    I have not personally switched from a different solution to Splunk Cloud Platform, but we utilize various different solutions for SIEM, including QRadar and Exabeam , alongside newer tools including DataDog and Elastic.

    How was the initial setup?

    My experience with pricing, setup costs, and licensing is that while the setup costs are straightforward and not overly burdensome, licensing for small to mid-sized enterprises is favorable. Highly regulated businesses, including financial services and banks, tend to use Splunk Cloud Platform regularly, and while it is a high-quality product, the costs can elevate significantly as scalability needs grow within larger enterprises.

    What about the implementation team?

    My partners deploy Splunk Cloud Platform in several different ways. My partners typically purchase Splunk Cloud Platform through distribution and channel partners, rather than directly.

    What was our ROI?

    I have observed a robust return on investment with Splunk Cloud Platform, particularly in how quickly it enables the detection of breaches. We see logs between 10 to 30 minutes in contrast to six hours with other platforms, marking a substantial ROI for organizations needing to prevent breaches that can cost from tens of thousands to the average ransomware cost in the UK of 3.2 million last year. Being able to resolve issues quickly not only saves money but also minimizes the need for additional security personnel, thanks to the effectiveness of its log prioritization and integration capabilities.

    Which other solutions did I evaluate?

    Before choosing Splunk Cloud Platform, the primary alternative evaluated was DataDog, although that was not my decision directly.

    What other advice do I have?

    The aforementioned examples are the best ones to highlight regarding positive outcomes about how Splunk Cloud Platform has helped my organization or my customers.

    My partners typically purchase Splunk Cloud Platform through distribution and channel partners, rather than directly. My impressions of Splunk Cloud Platform's visibility into multiple environments, including cloud, on-premises, and hybrid are very positive. It excels at monitoring across these environments and provides high capabilities, especially strong in centralizing visibility. This is facilitated by effective cloud monitoring alongside mature on-premises monitoring, all visible in a unified dashboard for SIEM use, supporting massive scales and deep forensic investigation across all these monitoring types.

    My impression of Splunk Cloud Platform's zero setup feature for AI models is mixed, as there have been a couple of problems. Data is never standardized among organizations, leading to different log formats and inconsistent field naming. Therefore, AI cannot understand the data without mapping it first. Moreover, there is a need for context rather than just raw data, and integration remains unavoidable. Splunk Cloud Platform's zero setup AI concept feels more like a marketing idea than reality, as it requires careful scrutiny in enterprise environments. The main blockers noted remain related to data integration and standardization.

    My experience with Splunk Cloud Platform's application ecosystem is that it is easy to manage for small and simple environments, as management involves just installing the application and configuring the data. However, for enterprise environments, management becomes really complex when dealing with multiple applications and teams, especially in larger organizations or heavily regulated industries including financial services and banking, where governance is stringent.

    Splunk Cloud Platform scales extremely well at enterprise and hyperscale levels with some cost and architecture considerations. It can ingest almost limitless data and scale impressively, but higher data volumes present challenges, including costs, poor data hygiene, slower searches, and operational complexities that arise even in cloud environments. Despite these challenges, Splunk Cloud Platform scales extremely well technically; however, in real-life enterprise contexts, the main scaling limitation is not infrastructure but rather cost, data volume discipline, and query efficiency.

    In comparing native models to third-party integrations within Splunk Cloud Platform's environment, I find that native Splunk scores high in integration quality and stability. However, it lacks the customization and innovation speed found with third-party options. Native  models require very low maintenance effort, which contrasts with the medium to high maintenance needed for third-party applications. Each model has its advantages: the native model excels in core SIEM engines and performance-critical workloads, while third-party models handle data ingestion for external systems and industry-specific applications effectively. Therefore, a hybrid approach, leveraging the reliability of native capabilities with the flexibility of third-party applications, is ideal.

    Splunk Cloud Platform's subscription model significantly impacts financial planning for data platform investments by being quite complex and opaque. The licensing and subscription model are tough to decipher initially, largely due to the relationship between ingestion levels, data scaling, and the associated costs that increase with usage. Customers usually find that as they scale, their expenditure rises, with no clear set cost available when they first begin using it.

    Splunk Cloud Platform is a market leader known for its strengths in enterprise-scale log analysis, advanced security monitoring, complex event correlation, and deep search capabilities. It is also highly customizable, making it an excellent choice for organizations unperturbed by cost and seeking a cloud-native design, especially if they have a SOC environment and a large IT estate. I would rate this product a nine out of ten overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2816211

    Cloud analytics has improved reporting and security visibility across hybrid environments

    Reviewed on May 06, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have been working in my current field for two years.

    My use cases for Splunk Cloud Platform  involve various applications that enhance data management and security.

    I use it to streamline operations and improve analytics.

    What is most valuable?

    What I appreciate most about Splunk Cloud Platform  is its intuitive user interface, which makes navigation and data analysis efficient.

    It has a favorite feature in its reporting capabilities, allowing me to generate insightful reports easily.

    What needs improvement?

    What I find challenging about Splunk Cloud Platform is that it occasionally has a steep learning curve for new users.

    The platform could improve by offering more comprehensive onboarding resources and tutorials.

    For how long have I used the solution?

    I have been working with Splunk Cloud Platform for six to eight months.

    What do I think about the stability of the solution?

    Regarding stability, Splunk Cloud Platform performs well with minimal lagging or crashing issues.

    What do I think about the scalability of the solution?

    Regarding scalability, I find that Splunk Cloud Platform is highly scalable, accommodating growing data needs without major issues.

    How are customer service and support?

    I have had to contact technical support for Splunk Cloud Platform before, and my experience was quite positive.

    If I were to put the technical support on a scale from one to ten, I would rate it an eight for the support.

    How was the initial setup?

    The initial deployment of Splunk Cloud Platform was somewhat challenging but manageable.

    It had complexities that required careful configuration.

    Which other solutions did I evaluate?

    As for alternatives, I have used other data analytics tools before, but none quite match the capabilities of Splunk Cloud Platform.

    I definitely prefer Splunk Cloud Platform more due to its superior features and support.

    What other advice do I have?

    I think the app ecosystem for Splunk Cloud Platform is robust, and managing updates within this app ecosystem is relatively easy.

    Splunk Cloud Platform's visibility into multiple environments offers excellent monitoring capabilities, whether I am using it in the cloud, on-premises, or in hybrid environments.

    I leverage it primarily for cloud infrastructure.

    Regarding Splunk Cloud Platform's zero-setup feature for AI models, my impression is that it is truly innovative and simplifies the integration of AI into my workflow, although I have not used it extensively.

    Regarding the pricing, I think Splunk Cloud Platform is on the higher end, but the value it provides justifies the cost.

    I would rate this product an eight overall.

    R Nandasana

    Cloud analytics has supported long-term healthcare use cases and simplifies operational management

    Reviewed on May 05, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I used Splunk Cloud Platform  for seven years. We built use cases for one of our pharma customers, Regeneron Pharmaceutical from the US. We created numerous use cases for their operations, including keeping medical records with details about medicine inventory, doctor information, and many other elements that we stored and presented.

    What is most valuable?

    I appreciate the expansion capability of Splunk Cloud Platform . We can forward any kind of data to the cloud endpoint that they provide. This allows us to forward any kind of traffic to that endpoint. There is no need for maintenance. If an error occurs or Splunk health is not good, we can raise a support case and they will handle everything. There is no need to maintain infrastructure either, as they keep the infrastructure very stable, which is a good thing.

    What needs improvement?

    If you want to make Splunk Cloud Platform more reliable, there will be some issues. For example, if you want to allow some IP or renew some certificates, you need to raise a case and it will not be immediate. It will go through the process and take three to four days. Sometimes, the technical support case persons are not sufficiently technical. I have experienced this where they are not technical enough or not understanding the issues.

    The app ecosystem is good, but if you want to upgrade any kind of apps or receive support related to the app, you mostly need to raise a support case and the Splunk team will handle it. However, if there is a problem with your custom apps that you need to deploy on an indexer, that becomes an issue. You can upload it from the search head, but sometimes there are DMC issues. DMC mostly fails sometimes, so we cannot deploy from the search head cluster or indexer. For custom apps, you need to go through all of these processes, which involves a lot of process.

    For how long have I used the solution?

    I used Splunk Cloud Platform for seven years.

    What do I think about the stability of the solution?

    Stability with Splunk Cloud Platform is very stable. Sometimes we face an issue with latency. For example, when we are ingesting 10 TB of data and there is a sudden increase, we need to increase the storage at the cloud end. Sometimes this will take time because it is not on our end but on the cloud end. That is the only issue. Everything else is good.

    What do I think about the scalability of the solution?

    Splunk Cloud Platform is very flexible in terms of scalability. If you purchase something initially and later have increased requirements, they can scale up and scale down your environment. That is one good feature. We just need to raise a simple support case, and based on that support case, they will scale up and down our environment. That is good.

    How are customer service and support?

    I reached out to technical support many times regarding operations. If you want to perform any kind of operations, you need to reach out to the technical support. They are very good and their responsiveness is fine. Everything is good. However, as I mentioned, sometimes they might not have proper knowledge or sometimes they are not sufficiently technical. They are not understanding sometimes.

    Which solution did I use previously and why did I switch?

    I used New Relic  for log collection. However, New Relic  is not a part of Splunk. It is a very limited scope product, not widely used like Splunk. There is no competitor to Splunk in the current market right now.

    How was the initial setup?

    I do not think we need to do anything for initial setup. We just need to request the cloud team, and they will prepare an instance and everything for us, and they will give us a URL to access the cloud. After that, you need to allow firewall access based on what is in your company. That is all. Then you can access the environment. It is very simple and we do not need to configure anything.

    What about the implementation team?

    Maintenance is not required at all in the cloud. A team of four or five people is more than enough to handle the full cloud infrastructure. I managed the cloud around 10 TB ingestion per day with only four or five people. That is more than enough because we do not need to take care of hardware and other components. However, if you have on-premises, then you need more than 30 people to maintain all of the parts.

    What was our ROI?

    Splunk Cloud Platform pricing is very costly. If we did it on-premises, it would be cheaper because we would just need to purchase a license. However, Splunk Cloud Platform is very costly. But if you use it properly, then you can get value from it. Maintaining an infrastructure on-premises would be expensive as well.

    What's my experience with pricing, setup cost, and licensing?

    Splunk Cloud Platform pricing is very costly. If we did it on-premises, it would be cheaper because we would just need to purchase a license. However, Splunk Cloud Platform is very costly. But if you use it properly, then you can get value from it. Maintaining an infrastructure on-premises would be expensive as well.

    What other advice do I have?

    Visibility with Splunk Cloud Platform is very good. We do not use only cloud because we have a heavy forwarder at our end that will forward the data. This is a hybrid deployment on our end. If you have on-premises only, then everything is on you. With on-premises, we have full visibility of the environment, including what is indexer and what is search head. However, in the cloud, we do not know where this is deploying. They are saying that they are deploying only on AWS . If something goes wrong with AWS , then our full Splunk Cloud Platform goes down. For enterprise on-premises, we have full visibility and can see what is affected and other details. Visibility is less in cloud and more in on-premises. I have not tried that feature. My overall rating for this product is 9.

    Andrzej Nienaltowski

    Training lab has improved threat hunting and now speeds up investigations with built-in visuals

    Reviewed on Apr 29, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use Splunk Cloud Platform  for both IT alerting and incident management in my training.

    I use it to find threats and strange behavior of applications or networking. I mostly use it for networking, strange processes, and behaviors. I use the alerting mechanism.

    What is most valuable?

    I appreciate the syntax that Splunk Cloud Platform  uses because it is not KQL.

    The whole product is really good, and I did not have much difficulty using it. The alerting mechanism is good to have, but in my personal training, I did not use it much because I did not need it that much.

    The visualization feature in Splunk Cloud Platform is a pretty good feature because I did not need to go to any other vendors, for example, any.run or VirusTotal . This speeds the whole investigation up.

    What needs improvement?

    It is worth reconsidering the syntax language and changing it to KQL. The company would benefit from using the KQL language in queries. Pricing would be better.

    For how long have I used the solution?

    My experience with Splunk Cloud Platform is three months.

    What do I think about the stability of the solution?

    I have not heard a lot of problems or disconnections, so I think nine is correct. That is also nine.

    How are customer service and support?

    From what I heard, the technical support is pretty decent, so eight is okay.

    Which solution did I use previously and why did I switch?

    I have tried Elastic, Sentinel , and I think that is all.

    How was the initial setup?

    I cannot tell if the deployment is easy or complex. I cannot tell how long it took to deploy because I did not deploy it. I just started the session, and everything was already prepared for me.

    I had some tasks to find, such as some strange processes. That was one big task to perform on Splunk Cloud Platform system. There were several of these tasks, but that was an example.

    What other advice do I have?

    I have not tried the machine learning tools yet. I did not integrate Splunk Cloud Platform with any tools. In my case, it is just me using the solution, but I know the whole platform because I am using Cyber Defender platform for learning. The whole platform has a lot of people, but in my case, it is only me.

    I cannot tell if it requires any maintenance, but I do not think it is really rough to do it.

    My overall review rating for Splunk Cloud Platform is eight.

    View all reviews