The Splunk Cloud platform is for anyone who wants to save money and doesn't want to manage an on-prem infrastructure. I like the Cloud platform because we don't have to handle any maintenance. Any server downtime, upgrades, or patches are no longer our responsibility, which is great. That's the biggest advantage of Splunk Cloud.
Consultant at a tech services company with 201-500 employees
Allows app and add-on installations without worrying about accidental breakdowns
Pros and Cons
- "I like the idea of being able to list the IPs that we want without having to open up a ticket to get it done so that way if anything changes we can add a new IP."
- "Splunk Cloud's SVC licensing model lacks transparency."
What is our primary use case?
How has it helped my organization?
Before COVID-19, the Splunk Cloud platform was much more difficult to manage. I've heard it causes a lot of frustration. Thankfully, it's come a long way since then. Now, it's user-friendly and allows app and add-on installations without worrying about accidental breakdowns.
I wouldn't have released Splunk Cloud myself when they did but the shift to remote work during COVID-19 drove everyone to the cloud, making the Splunk Cloud platform a great solution. While the updates focus on features, patches, and maintenance, there's nothing about the Splunk Cloud platform itself that I love other than the fact that we can use it in the cloud without the hassle of any on-prem requirements.
The importance of having one cloud platform depends on an organization's data goals, but at the end of the day, we onboarded the data because it's important. So as long as we have a use case, it's high up there.
Splunk Cloud Platform has improved our mean time to resolve incidents 100 percent. The cloud eliminates the need for upgrades to multi-cluster environments and the risk of errors during configuration, which can cause major problems. While we are not responsible for any Cloud maintenance, Splunk's support is helpful for escalations. Their clear communication about maintenance minimizes the need for their involvement.
While I can't speak to personal cost savings, moving to Splunk Cloud likely saves on storage costs compared to on-premises setups. This is especially valuable because many organizations use Splunk alongside other security products for specific needs. However, some competitors offer better data storage and faster results as add-ons for Splunk. Overall, the biggest cost savings come from eliminating the need for in-house server maintenance, storage management, and future data migrations. This reduces headaches and frees up IT resources, even if the migration itself wasn't a major issue.
What is most valuable?
I like the idea of being able to list the IPs that we want without having to open up a ticket to get it done so that way if anything changes we can add a new IP. The platform itself is the most valuable because if we're using the product, we're paying a lot for it. So we're searching our data and doing the triage we need to with the events. In reality, our biggest benefit of the Splunk Cloud Platform is not having the hassle on-prem.
What needs improvement?
Splunk Cloud's SVC licensing model lacks transparency. Customers are unsure of how SVC consumption translates to costs, and there's no easy way to identify what's driving SVC usage within the platform. While some external applications provide limited insight, Splunk Cloud itself doesn't offer a clear view into SVC consumption. This lack of clarity makes it difficult to explain cost spikes to customers, as the cause could be anything within the platform.
Buyer's Guide
Splunk Cloud Platform
January 2026
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
For how long have I used the solution?
I have been using the Splunk Cloud Platform for four years.
What do I think about the stability of the solution?
The Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
I have some concerns about the SVC licensing model for deployments under 1 terabyte, and it's separate from Splunk Cloud. The bigger challenge customers face is managing the surge of data and historical information they ingest. This can lead to situations like an admin setting up numerous queries and then leaving, making users hesitant to disable them for fear of breaking something. While this can happen with any product with unchecked admin access, Splunk and Splunk Cloud themselves function as intended for large-scale environments. Ultimately, it's up to the customer to manage their Splunk instance effectively.
How are customer service and support?
Many people complain about back-and-forth interactions with Splunk support. It feels like a repetitive loop of explaining the problem, being asked for information and questioning why it's needed. There's frustration on both sides: support needs details to diagnose the issue, while users might feel it's a simple problem and supplying extra information is unnecessary. This can be true for any customer support experience.
How was the initial setup?
Splunk Cloud deployment complexity varies by use case. Starting fresh is simple: install, configure, and point data to the cloud. However, migrating from on-premises to the cloud with existing data can be complex. Deciding what data to migrate and the migration process itself adds significant challenges, although these are likely to become easier over time.
What was our ROI?
Splunk Cloud's value is clear: it eliminates maintenance headaches and simplifies connection, offering a hassle-free experience.
What's my experience with pricing, setup cost, and licensing?
The lack of transparency around the SVC licensing makes it difficult to explain the costs to our clients.
What other advice do I have?
I would rate the Splunk Cloud Platform nine out of ten. The rating is not because of customer service. I am strictly looking at the product. I've worked with it for seven years. I've been on over 70 engagements with other customers over those years, and I rarely find a use case that a customer can't solve when it comes to an architect-type scenario, which is great. It's the same thing for data. For the most part, if you know you have data and can get it written down to a file, you can adjust it, which is phenomenal. The on-prem infrastructure consists of only 12 CPUs and 12 RAM if it's hardware, and then you double it if it's virtual. Overall that's very inexpensive to stand up major components. I'm not including storage or any other sizing that can get more complicated. Overall, it doesn't ask much from actual servers if you want to host it on-prem. Even managing it yourself on-prem, is not terrible. The commands are still there, the resources are there to do it yourself. You have community groups out there that help you with questions. There are tons of providers out there that can get you from point A to point B.
I have always used Splunk but I am open to learning Chronicle soon depending on industry trends. While I believe Splunk remains the top SIEM tool. According to Gartner, competitors like Azure and Oracle are emerging. However, I have not needed to look for other solutions.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Consultant
Principal, Cybersecty and Infra at a energy/utilities company with 1,001-5,000 employees
Improves availability and makes infrastructure administration easy
Pros and Cons
- "There is definitely the ease of the infrastructure administration. It frees up a lot of time."
- "I would love to be able to manage my own apps."
What is our primary use case?
We are onboarding everything on it. We have infrastructure, applications, and network-related things on it.
How has it helped my organization?
The availability has improved. There is the ease of upgrades. We are able to show value quicker with some of our add-ons and things like that because of the stability in the base.
It is extremely important to me that Splunk Cloud Platform has end-to-end visibility into our cloud-native environment.
Splunk Cloud Platform has definitely helped reduce our mean time to resolve. It is a little hard to measure. It has at least saved 3% of our time.
Splunk's unified platform has helped consolidate networking, security, and IT observability tools. There is ease on resources.
What is most valuable?
There is definitely the ease of the infrastructure administration. It frees up a lot of time.
What needs improvement?
I would love to be able to manage my own apps.
For how long have I used the solution?
I have been using Splunk Cloud Platform for two years.
What do I think about the stability of the solution?
Stability and scalability have been the main benefits of this solution.
How are customer service and support?
We have had some confusion around some of our requests, but I understand. We have to work through and get proper responses.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We were using on-prem Splunk.
How was the initial setup?
There was a professional service involved. I came into the team right at the time of the cutover. They were pushed into the cloud because things had gotten so out of control on-prem, so we had to clean that up first, and then finish the migration. It was kind of bumpy, but we got through.
We are using AWS. It is managed by Splunk.
What about the implementation team?
We had Aquila as our partner for help with implementation.
What was our ROI?
We are definitely starting to see an ROI. We have been focused on metrics because we are trying to get very comprehensive and overall monitoring of the environment both from the security standpoint and the infrastructure standpoint.
We have not yet seen any cost efficiencies by switching to Splunk Cloud Platform. We are still maturing it out.
What's my experience with pricing, setup cost, and licensing?
As far as the pricing goes, it was what was expected. It is a premium product. There were no surprises there.
Which other solutions did I evaluate?
We did not evaluate other solutions. We have always been with Splunk.
What other advice do I have?
We are not monitoring multiple cloud environments, but it seems it would be easy to monitor them.
Overall, I would rate Splunk Cloud Platform an eight out of ten. There is always room for improvement, but it has been good.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Cloud Platform
January 2026
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
Incident Manager at a manufacturing company with 10,001+ employees
A stable solution used for visualization and alerting, but it needs to be made more user-friendly
Pros and Cons
- "The most valuable feature of Splunk Cloud Platform is the alerting feature."
- "Splunk Cloud Platform needs to be made more user-friendly because it's not user-friendly."
What is our primary use case?
We use the solution for application status alerting, user activities, and active directories. We use the solution for visualization, alerting, and analyzing events or incidents.
What is most valuable?
The most valuable feature of Splunk Cloud Platform is the alerting feature.
What needs improvement?
Currently, Splunk Cloud Platform is very easy to use and read. The solution's visualization for the end users is also good. However, setting up the solution or an alert is not straightforward. There's a lot of incompatibility and areas that you have to consider while setting up the solution.
All those things make setting up the solution very complex for regular people who know the business operation. So, they have to hire a third party or a technical person who doesn't understand the business to set it up for them, which usually creates a gap.
When someone who cares about the business and understands its operation sets up the solution, they would set it right. There's always a gap when a technical person or third party sets it up. It may lead to many workarounds to fix issues like alert fatigue or false security. Splunk Cloud Platform needs to be made more user-friendly because it's not user-friendly.
For how long have I used the solution?
I have been using Splunk Cloud Platform for four to five years.
What do I think about the stability of the solution?
Splunk Cloud Platform is pretty stable, and I don't have any issues.
What do I think about the scalability of the solution?
Splunk Cloud Platform is a scalable solution.
How are customer service and support?
I usually go to forums and discussions to get answers to my issues. You might need a Splunk account username to talk to technical support. When most users I have talked to face a problem, they Google it. I don't know if the technical support would provide you with support if you were stuck.
Which solution did I use previously and why did I switch?
I have previously used different solutions like DataStage, Datadog, Grafana, and ClickView.
Which other solutions did I evaluate?
We evaluated other options before choosing the Splunk Cloud Platform. But when a company buys Splunk services, the end users have to use what they have as a resource.
What other advice do I have?
Splunk Cloud Platform is a really good tool for getting alerts and better information about incident management and maintenance. Because of the solution's complex setup, most alerts are set by developers or people who create multiple unnecessary alerts, creating alert fatigue. Compared to other systems, like Dynatrace, Splunk Cloud Platform is not a smart system for analyzing alerts.
As a project manager, I oversee the process of contacting the concerned parties, knowing what needs to be monitored and why they need the alerting mechanism. I was not directly involved in the scripting and adding Splunk Cloud Platform in the back end.
As business requirements change, Splunk Cloud Platform needs maintenance in terms of setting up different parameters, which is not an easy task.
Everybody uses the Splunk Cloud Platform in a different way. I would advise users to share their experiences about technical difficulties in the forums and community. Sometimes, others might go through the same problem without much documentation, and sharing your technical problems might help others.
Overall, I rate Splunk Cloud Platform a seven out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
SIEM Engineer at a manufacturing company with 11-50 employees
Offers excellent visibility, and cloud performance, and requires zero maintenance on our end
Pros and Cons
- "he cloud performance is good."
- "Splunk should offer various options for real-time monitoring."
What is our primary use case?
We use Splunk Cloud Platform to monitor our environment.
How has it helped my organization?
Monitoring multiple cloud environments is made easy with the Splunk Cloud Platform due to its fast ingestion and data recovery times.
Splunk's visibility into multiple environments is excellent. I have found that a hybrid environment works the best, as the login portion remains on-premises while the rest is in the cloud. This reduces the maintenance required on-premises.
There are two types of integration. The first involves bringing something into Splunk, while the second entails moving something out of Splunk. Bringing data into Splunk is relatively straightforward, with multiple options such as RAS, SysLog, and Splunk's built-in functions. However, exporting data from Splunk is more challenging and not as straightforward as the process of bringing data into Splunk.
Splunk Cloud Platform has influenced our decision-making processes. Splunk is primarily employed for security purposes; thus, it excels particularly in SIM. It encompasses an asset and identity framework that effectively gathers information about an organization's assets and individual identities, encompassing all users. Therefore, when considering Unified Business and SIM, Splunk proves to be highly proficient.
What is most valuable?
The cloud performance is good.
Not having to perform any maintenance because it is handled by Splunk saves our administrators time which is valuable.
What needs improvement?
Splunk should offer various options for real-time monitoring. If we could enhance the speed of data ingestion or data retrieval, that would be an added advantage. Additionally, there is room for improvement in SaaS-to-SaaS integration. I believe that reintroducing HTML dashboards would be beneficial, as they provide dedicated web features. This, in turn, gives users the flexibility and freedom to create custom dashboards more easily.
For how long have I used the solution?
I have been using Splunk Cloud Platform for five years.
What do I think about the stability of the solution?
I would rate the stability of the Splunk Cloud Platform as an eight out of ten. We still encounter some lagging and errors, but not as much as with the on-premises deployment.
How are customer service and support?
I occasionally get in touch with Splunk technical support, usually regarding data onboarding. These include routine activities like installing or uninstalling applications, as well as making changes to existing ones. On average, we submit at least one ticket per week to them.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used many tools including Elastic, Grafana, Tableau, and Sumo Logic.
Splunk is indeed superior in many cases, but other tools are also making progress to catch up, with Elastic being one of them. They have begun developing their own SIM offering, complete with its own SIM features. Similar to Splunk Cloud, Elastic also has its Elastic Cloud Stack. Some of the features provided by Elastic seem to outperform Splunk. Therefore, there is room for Splunk to enhance these aspects. As for pricing, it could be more competitive, considering that other tools also provide the freedom to choose the Cloud Stack. Although Splunk offers this flexibility, the process often involves extensive discussions, making it less adaptable compared to other tools.
How was the initial setup?
The initial setup is somewhat complex regarding the CI/CD pipeline, and Splunk manages the deployment. Splunk provides a feature called ACS, which enables us to manage the deployment ourselves if desired, but it's simpler to have Splunk handle the deployment on our behalf.
The deployment took around one month and required ten people from Splunk's DevOps team.
What about the implementation team?
The implementation was completed by Splunk.
What's my experience with pricing, setup cost, and licensing?
The pricing is high for small organizations. The cost makes more sense for organizations that have a large amount of data ranges.
What other advice do I have?
I would rate Splunk Cloud Platform an eight out of ten.
There are numerous tools that offer real-time reporting and alerting capabilities. Splunk is indeed effective, but due to the prerequisite of registering logs beforehand, a delay is inevitably introduced. Therefore, while Splunk is suitable for real-time reporting alerts, it may not be as optimal as some alternative solutions.
Resilience has added value and contributed to the improvement of our organization. This is highly significant. In most cases, the SOC team relies on the tool for issue mitigation and ticket resolution. Therefore, it is crucial for Splunk to remain consistently up-to-date and respond as quickly as possible. This holds immense importance.
The extensibility is good, but there is room for improvement, especially in integrating certain logs. Enhancing the process of incorporating raised logs is possible. In most cases now there are limitations on log creation. Previously, a direct option existed to import logs. However, this process has been altered, requiring users to develop an add-on for log integration, leading to increased complexity. Furthermore, users are expected to have knowledge of Python. This can be problematic in cases where users lack such expertise. Therefore, this aspect could certainly be enhanced.
For those who want to evaluate Splunk, it comes down to the volume of data. If they are dealing with a substantial amount of data flowing into their SIM, Splunk would be the superior option. Splunk effectively manages extensive datasets in comparison to other technologies. It also offers numerous additional functionalities, such as an enterprise security suite, assets, and identity framework. Moreover, it has undergone industry testing and has been employed in the field for a considerable duration. In contrast to other organizations, they provide a wealth of features.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Tech Support Supervisor at a government with 10,001+ employees
We can identify an issue in real time and save a few hours every day
Pros and Cons
- "The Splunk Cloud Platform has reduced our mean time to resolve. It has easily saved 20 to 30 minutes every time someone gets locked out. We get 10 or 15 instances per day where people get locked out. It definitely saves a few hours per day."
- "I have not come across anything that I would consider missing as such. If anything, sometimes we have dashboards that would not go into the dark mode. It is a minor issue, but it is the only thing that I wish was there. The dark mode would definitely help."
What is our primary use case?
We have a lot of third-party contractors that come in on our network and do the work. We use it to pretty much check what they are doing and make sure they are not doing anything that they are not supposed to be doing.
We do a lot of user interaction. We have users logging in, and we mainly look into failures and what is causing them to get locked out. We do a lot of that.
We also have Duo. We use Splunk Cloud Platform to keep an eye on who is using Duo, where they have failures, and why. We have quite a few people who are not supposed to be using Duo, and then they end up, for whatever reason, on the Duo side of the house. We use it to keep an eye on them so that we can help them get back to where they are supposed to be.
How has it helped my organization?
The improvement is in terms of helping those users who get locked out because we have that happen quite often. Daily, we have users getting locked out, and using Splunk makes it so much easier to help them. Rather than trying to go to the server and find those logs, we can just go to Splunk and then the dashboard for that particular user and find out exactly which machine is causing the lockout.
It helps us to easily find out which machine is causing the lockout. A lot of people know that customers can exaggerate. We can bring that back into perspective. They might say that they get locked out every day, whereas it might be once a week. We can see that. We do have a dashboard that tells us who is locked out right now. We do use that, and it helps us a lot because even before the user realizes it, we can go back and help. That helps us because they almost do not even know that it is happening. We can see it in real time, and we can fix it and unlock it. If it is something that is reoccurring, we can say, "You have been getting locked out multiple times in the same place for the last couple of hours. Go check this." We can also see why they were locked out. If somebody is putting in the wrong password, we can ignore that and unlock it. We, of course, are going to see where it is coming from. If we see some weird IP address or some weird computer that looks like it belongs to us, we will address that, but it helps us to help the user quickly. We are told what is happening as opposed to having to ask what is happening. We have definitely seen time to value. Instead of having to research, we are told it is there.
The Splunk Cloud Platform has reduced our mean time to resolve. It has easily saved 20 to 30 minutes every time someone gets locked out. We get 10 or 15 instances per day where people get locked out. It definitely saves a few hours per day.
Splunk Cloud Platform definitely frees us up to handle true problems and do true troubleshooting as opposed to handling lock-out issues. It is, of course, big for the user, but it is minute for us because it is answering a question that does not really matter to us. It matters to the user, but for us, we can just unlock their account, and we can figure out why at another time, whereas now, we can unlock their account and figure out why immediately. For example, if it was a machine that they logged into but they do not remember, or they have a cell phone that they logged into but they have not changed their password on, we can figure that out a lot quicker. That helps them quicker. It keeps us from having to go back to that user, and we can knock that out right then and there.
We have not gone into its ability to predict, identify, and solve problems in real time because we use it more after the fact. We do have an MSP, and they handle more of the security side. Their software does real-time monitoring, and they get alerts. We use the Splunk Cloud Platform to see what has already happened.
What is most valuable?
All the features are very equal for me. I do not use any one feature more than the other. They all are pretty equal to me.
What needs improvement?
It works as needed, and it does everything that we want to do. I have not come across anything that I would consider missing as such. If anything, sometimes we have dashboards that would not go into the dark mode. It is a minor issue, but it is the only thing that I wish was there. The dark mode would definitely help.
For how long have I used the solution?
We have been using the Splunk Cloud Platform for about three years.
What do I think about the stability of the solution?
It has always worked when we needed it.
What do I think about the scalability of the solution?
We are a very small shop. We only have 150 gigs a day, and we are not anywhere near that 150. However, from what I see, if there is an easy transition from 150 gigs to 300 terabytes, that is easy scalability.
Which solution did I use previously and why did I switch?
We did not use any similar solution.
How was the initial setup?
I was not involved in its deployment. It was already implemented.
What other advice do I have?
Splunk Cloud Platform has been able to provide business resilience by empowering our staff, but currently, only two of us use it. One thing about coming to the Splunk conference is that we learn a lot. It is a lot more than what we probably can do. We also learned that for most people here, Splunk is a big part of their job. That is their main focus, whereas we have so many different things. We use Splunk; we do a little bit of networking. We do troubleshooting from swapping computers to the almost top level of moving cables.
I would rate the Splunk Cloud Platform a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager Cloud Operations at a computer software company with 201-500 employees
Makes searching for issues very easy
Pros and Cons
- "Splunk helped reduce our mean time to resolve by around 60%."
- "Support is the bigger issue when we have a problem. When we need their help, it takes weeks or months to actually get resolved."
What is our primary use case?
My primary use cases are for troubleshooting, monitoring, and anomaly detection.
How has it helped my organization?
Splunk helped reduce our mean time to resolve by around 60%. We have realized these savings through it solving problems and the proactive monitoring. But it comes with a huge cost. We have to evaluate other products that are comparable to Splunk in the market and see if they offer the same value.
It improved our business resilience.
Splunk has improved my organization by troubleshooting issues. When we have an issue, if we didn't have Splunk, it could take hours or days to figure out where the problem is. With Splunk, it only takes hours or minutes sometimes.
It saves us money by changing our product or process to work in a better way. Splunk is great. It has a lot of value ads and features. But overall, Splunk Cloud is expensive compared to other products in the market.
What is most valuable?
The most valuable feature is the search options. Our infrastructure is huge so if an issue happens, it's hard to find where it is. That's where Splunk comes in handy. You just go to their user interface and do a Google-type search. Just put in a keyword, search it, and you'll figure out where it is. If you have thousands of servers, it's very hard to see where the issue is and where the transaction is logged. Splunk makes it very easy. That's the best part of Splunk.
I would rate Splunk's ability to provide business resilience by empowering oneself a seven out of ten. Whenever we have an issue, Splunk is handy. We have a lot of monitoring in place so if an issue happens, our monitoring helps proactively figure out the issue, and in that way, we can make sure that our environment and infrastructure are up and running, and our customers don't have any issues.
What needs improvement?
It's improved a lot since we began using it. We have been seeing issues, but they get resolved by working with the support. It's just getting expensive with time.
Support is the bigger issue when we have a problem. When we need their help, it takes weeks or months to actually get resolved. To date, we have cases open for two or three months without a resolution. Support is the worst part.
For how long have I used the solution?
I have been using Splunk Cloud Platform for four years.
What do I think about the stability of the solution?
It's stable and highly available. We had issues, but all of these types of platforms have.
What do I think about the scalability of the solution?
Scalability depends on what kind of license you have. If you have ingest-based licenses and you hit your cap, I think they still let you ingest more, but then you have to work with your account team and buy more licenses so you don't lose data. It's scalable, but not automated because it has its own license limitations.
How are customer service and support?
I would rate support a four out of ten. The reason is that they are not proactive, they are reactive. If we notify them about an issue, they are supposed to monitor their infrastructure and tell us that there is an issue and that they are working on it. But rather than doing that, we have to do that, and after doing that, it takes time for them to work on it and solve the problem.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
My company previously used a custom, on-premises solution. Splunk was already implemented when I started at my company.
We're asking ourselves now why we use Splunk. Our next step is to go out and evaluate other products in the market that may be not as costly and offer the same feature set.
How was the initial setup?
It's a cloud, it's all managed service. The only thing we had to do is onboard our applications, which is something I do every day.
It's very straightforward and very easy. You only need to configure and get data and you can be onboarded within minutes. We don't have to go through a lot of configurations, manual steps, or training.
What other advice do I have?
Its ability to predict, identify and solve problems in real time is looking promising. We're looking into it now.
I would rate Splunk an eight out of ten. It has a lot of features and enables us to focus only on our applications and logs. I don't need to worry about the infrastructure behind it.
The best value I get from attending Splunk conferences is getting experts' help for specific use cases.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Splunk Architect Application Software Developer at a tech vendor with 10,001+ employees
Resilient, helps with decision making, and is very fast
Pros and Cons
- "The cloud is very fast."
- "Support could be improved."
What is our primary use case?
I use the solution to create alerts for different servers. I also create dashboards in Splunk.
How has it helped my organization?
We have a lot of servers. It was hard to track which were down as we didn't have a monitoring platform. Splunk changes that. It receives data and if it doesn't get any data, it creates an alert so we are notified if something is down.
We also use it for making reports to help make management easier.
The monitoring of servers for high CPU utilization helps us out. If there are offline servers or high utilizations, we can see the incidents and optimize our processes.
What is most valuable?
The cloud is very fast. We have a lot of data in our Splunk instance and it isn't slow in any way.
The maintenance is good. We have good support if we have queries or issues. With on-premises Splunk, if we ran into issues, we'd have to figure things out ourselves. With the cloud version, it's easier to get support.
We can monitor multiple cloud environments, including Azure and AWS.
It can be difficult to monitor cloud platforms. We are integrating more cloud servers and patching data sources from those servers. It's very easy to use Splunk and have everything go to the dashboards.
We get good visibility into multiple environments. We can easily search from Splunk Cloud to our on-prem or AWS directly. We also do not ingest the data in order to see it.
We can easily integrate with other systems. It's very helpful. We can leverage Splunk to gather any specific reports we want with this integration capability.
The reporting is very good. Every month we have a call with Splunk personnel and they'll show us reports to show high usage for search, for example. From our side, we can change or update in order to optimize our systems.
The cloud has helped us with decision-making. It helps make maintenance decisions very easy.
It's very resilient.
What needs improvement?
Testing can handle a lot of logs, however, we are unsure if the speed will be affected.
When we are using OneDrive or SharePoint, as a developer, we'd like to have better integration between the two.
There are some issues with Splunk blocking some shared mailboxes.
Support could be improved.
For how long have I used the solution?
I have been using the solution for five years.
What do I think about the stability of the solution?
The Splunk cloud is very stable. I've never experienced crashing. If there are issues, they will notify us. It doesn't take long to resolve issues at all. Things tend to be resolved in an hour or so.
What do I think about the scalability of the solution?
The solution is very scalable.
I haven't experienced the extensibility, or the ability to extend the system, however, my understanding is that it is very good. We have yet to upgrade it.
How are customer service and support?
When we have high-priority tickets, it's hard getting help efficiently. We'd prefer to call. It takes time to get someone to help. We've had to submit tickets via the portal, and they asked us to call instead. It's hard to get above P1.
It would be ideal to get a specific phone number or email so that we do not have to wait hours to get help.
We do have different Splunk support services where we talk to them bi-weekly, and at that point, we can talk about any high-priority issues. They do try to help us with queries.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Splunk on-premises.
How was the initial setup?
I do not have any experience with the initial setup. Since it is a cloud deployment, Splunk handles the maintenance mainly.
What's my experience with pricing, setup cost, and licensing?
I'm not aware of the exact pricing. That said, my understanding is that it is very reasonable. However, every application has a price. We need separate licenses for everything. They don't have any bundles.
What other advice do I have?
For the first few years, I used the solution on-premises, and then I moved over to the cloud.
I use the classic dashboard; I don't yet use the studio.
It has not yet affected our security posture.
We have not yet explored federated search.
I'd rate the solution ten out of ten.
If a user is planning to use the Cloud Platform is to consider the pricing. It's fast to access and there is no downtime. It's very good from a user perspective. I'm happy with it. It's helpful.
Users should work to maximize the power of Splunk to get the most out of it. Leverage the applications, including security.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Cloud DevOps Engineer at a financial services firm with 10,001+ employees
Good monitoring and automation capabilities but needs a more efficient UI
Pros and Cons
- "Its monitoring is completely automated."
- "It needs to mature; it's just getting established in the industry on a wider scale."
What is our primary use case?
I use Splunk on my phone, on-premises, and for the automation tasks that we carry out.
We use it to work on dedicated forms and infrastructure and have a lot of virtual machines and instances that are being run for every single application. Our infrastructure is purely based on Azure by Microsoft.
Keeping CMDBs of all the virtual machines is a heavy task. When you use it for your portal use, it might be two or three virtual machines. When a virtual machine is created, we use post-provisioning inside the virtual machine. While post-provisioning, we install Splunk agents so that any activity that is happening inside the VM is virtually monitored by Splunk.
We create a dashboard. We are able to monitor everything from that dashboard.
Splunk also offers enhancements and automation. Splunk plays a major role when it comes to automation. We extract the data from Splunk, and then we use it to automate using a jump server so that we can put in actions on any number of virtual machines.
How has it helped my organization?
The automation is the main advantage. When we need to search for data, as engineers, it's very easy.
What is most valuable?
I like that it's an independent cloud platform. It can work with AWS or Azure.
Its monitoring is completely automated. We do not have to put in other engineers just to maintain Splunk. It maintains itself, and it's very user-friendly. For the dashboards to be created or any sort of code that we want to do with Splunk, we can do it by ourselves. We do not need to have separate resources so it is very cost efficient. We do not require many people; it's resource-efficient as well.
We do use the federated search feature and find it helpful. Earlier, it was hard to withdraw data. We'd have to maintain it. Now, Splunk does it for us. It's a very time-efficient service. It's made a huge impact on automation. We can grab data in real-time any time we need to.
The solution integrates well with other applications and systems in our environment.
What needs improvement?
It could have a more efficient UI. If they could integrate more AI and make search more efficient so that other people can access and use it, not just engineers, that would be ideal.
It needs to mature; it's just getting established in the industry on a wider scale.
The API still needs some enhancements from a post-performance point of view.
From a monitoring point of view, Splunk is doing very well. However, if they could provide a post-provisioning aspect. Right now, we have to install a monitoring tool while we are post-provisioning every virtual machine. If they could be a provider that precluded having a virtual machine being created or provisioned, that would be ideal.
Alerting could be faster. Sometimes the actions that happen take some time to reflect on the Splunk dashboard. There is still latency. Especially when you work in a multi-cloud environment, you deal with a lot of regions. They still need to focus on availability across regions.
They need to have some security enhancements. Most users are using it with other single sign-on features like Okta. If they had their own SSOs that would be ideal. we'd be able to work independently. Right now, we have to log onto the virtual machines then move to Okta, then go to Splunk.
For how long have I used the solution?
I've been using the solution for somewhere around a year or one year and a half.
What do I think about the stability of the solution?
The stability is okay. Sometimes it goes down. I have not witnessed that as I do not use it continuously after the deployment. The resiliency is good. I'd recommend it four out of five.
What do I think about the scalability of the solution?
Everyone in the company uses Splunk.
The scalability is very good. It's extendible.
How are customer service and support?
I don't directly deal with technical support. We have a dedicated team that would work with Splunk.
Generally, my understanding is that if we have a query, we raise a ticket. There may be a separate portal or mailbox we can access as well to get assistance.
Which solution did I use previously and why did I switch?
We previously used Qualys. We switched mainly due to the costs involved. We also didn't want to migrate our resources to it. We simply wanted a monitoring tool, which is why we chose Splunk. Splunk in comparison is really cost-efficient.
How was the initial setup?
I was involved in the deployment of the solution.
Whenever a new resource or a new agent comes into the picture, in an organization, it's always complex. I don't blame Splunk for it, or my firm. It's like two pieces of a jigsaw puzzle and it's the developers who need to cut the pieces. It works really well as of now.
The deployment took somewhere between six to eight months.
We did need a lot of resources or staff members for the deployment. We have a vast infrastructure. We have a dedicated team inside as well who manage incidents and tickets using platforms like ServiceNow, and we still have a lot of resources dedicated to maintaining Splunk. The number of resources that are required to maintain it is more than the number of resources we use for development, actually.
How many people you need depends on the region. I work for Asia and North America. So for us, it was not much personnel. We needed four to five people in the development. There were somewhere around ten to fifteen people working on different parts.
What about the implementation team?
About 90% of the deployment was handled in-house.
What's my experience with pricing, setup cost, and licensing?
I'm only aware of general pricing terms, however, they have enterprise agreements as well. I can't speak to the exact cost. It's reasonable, from my understanding. I'd rate the affordability seven or eight out of ten.
Which other solutions did I evaluate?
Evaluating other options would be a task reserved for the highest management personnel at our firm. I was not involved with that process.
What other advice do I have?
We aren't using the solution across all cloud platforms. We use Azure. However, we would have the flexibility to gather insights from others. We just don't use that particular capability.
Right now, the solution does not affect our decision-making. It's still a very new platform. We're not relying on it completely. It's a work in progress. We need some time with it, to build up trust with it. Splunk is great so far, however, we still need more time and it needs more of a presence in the market.
Right now, in terms of compliance and privacy policy regulations, we limit the features that are not compliant with us. However, they are very flexible. We just use the features we can and block the ones that are unnecessary.
It hasn't had an impact on our security posture. We have very detailed security layers and several processes and teams. We haven't had any real use cases for Splunk. It hasn't actively blocked anything. We already have what we need in place.
I'd advise new users to check if this solution is reliable from a security point of view. Talk to Splunk about the cost as well. Splunk is really convenient for that. And whenever you deploy it in your infrastructure, make sure that the cloud providers or the on-prem solution that you are using are compatible with Splunk. We had issues in that some features that we were using in the cloud were not compatible with Splunk. So we had to make a lot of changes. That is something anyone who is trying to deploy Splunk needs to check - compatibility.
I'd rate the solution seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Popular Comparisons
PagerDuty Operations Cloud
Splunk ITSI (IT Service Intelligence)
Apache Superset
Splunk Enterprise Platform
AppInsights
Buyer's Guide
Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What's your experience or opinion about Spotfire vs. Tableau vs. Qlik?
- A journalist is writing a story about which Data Visualization software product to choose. Can you help him?
- What enterprise data analytics platform has the most powerful data visualization capabilities?
- When evaluating Data Visualization, what aspect do you think is the most important to look for?
- What are the best self-service and Excel-like filtering / display tools?
- What data visualization tool/s do you find to be the best?
- Why is Data Visualization important for companies?
- How many users on average are licensed users of Data Visualization software in a company?








