Listing Thumbnail

    Splunk Enterprise

     Info
    Sold by: Splunk 
    Deployed on AWS
    AWS Free Tier
    The Splunk Enterprise AMI accelerates the speed at which organizations deploy Splunk Enterprise in AWS..
    4.3

    Overview

    The Splunk Enterprise AMI accelerates the speed at which organizations deploy Splunk Enterprise in AWS. Splunk Enterprise is the leading platform for Operational Intelligence, delivering an easy, fast, and secure way to search, analyze and visualize the massive streams of machine data generated by your IT systems and technology infrastructure - physical, virtual and in the cloud. Use this AMI to take Splunk for a test drive, or as the basis for your Enterprise-level deployment. The Splunk Enterprise AMI ships with a fully-featured trial license that is valid for 60 days after launch. After the trial expires, your deployment will default to Splunk Free.

    Highlights

    • Collect and index any machine-generated data from virtually any source or location in real time. Just point Splunk Enterprise at your data, and it immediately starts collecting and indexing--so you can start searching and analyzing.
    • With Splunk Enterprise, you can correlate complex events spanning many diverse data sources across your environment. Types of correlations include time-based correlations, transaction-based correlations, sub-searches, lookups, and joins.
    • Splunk Enterprise scales to collect and index tens of terabytes of data per day. And because the insights from your data are mission critical, Splunk Enterprise's clustering technology provides the availability you need, even as you scale out your low-cost, distributed computing environment.

    Details

    Sold by

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    AmazonLinux 2023

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Splunk Enterprise

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    Refunds are not available

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    To learn what's new in Enterprise 10.4.3, please visit https://docs.splunk.com/Documentation/Splunk/10.4.3/ReleaseNotes/MeetSplunk 

    Additional details

    Usage instructions

    Get started with Splunk Web:

    • In your EC2 Management Console, find your instance running Splunk Enterprise.
    • Copy its public IP.
    • Paste the public IP into a new browser tab (do not hit enter yet).
    • Append :8000 to the end of the IP.
    • Hit enter.
    • Log into Splunk for the first time with the following credentials: ** username: admin ** password for Enterprise 7.2.5 and above: SPLUNK-$instance-id$ ** password for Enterprise 7.2.0 and below: $instance-id$

    Please modify the security groups to allow and disallow certain IP addresses per your requirements. The default is open to all IP addresses.

    Read more about the Splunk Enterprise AMI here: https://docs.splunk.com/Documentation/Splunk/latest/Admin/AbouttheSplunkAMI 

    Upgrade Instructions: http://docs.splunk.com/Documentation/Splunk/latest/Installation/HowtoupgradeSplunk 

    Resources

    Support

    Vendor support

    Options available

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Migration
    Top
    10
    In Data Anonymization, Data Security and Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Real-time Data Collection and Indexing
    Collects and indexes machine-generated data from virtually any source or location in real time with automatic indexing upon data ingestion
    Complex Event Correlation
    Correlates complex events spanning multiple diverse data sources using time-based correlations, transaction-based correlations, sub-searches, lookups, and joins
    High-Volume Data Processing
    Scales to collect and index tens of terabytes of data per day
    Clustering and High Availability
    Provides clustering technology for availability and fault tolerance across distributed computing environments
    Machine Data Search and Analysis
    Enables searching, analyzing, and visualizing machine-generated data streams from IT systems and technology infrastructure
    Real-time Data Collection and Indexing
    Collects and indexes machine-generated data from virtually any source or location in real time with automatic indexing upon data ingestion.
    Complex Event Correlation
    Correlates complex events spanning multiple diverse data sources using time-based correlations, transaction-based correlations, sub-searches, lookups, and joins.
    Scalable Data Processing
    Scales to collect and index tens of terabytes of data per day with distributed computing architecture.
    High Availability Clustering
    Provides clustering technology for availability and fault tolerance across distributed low-cost computing environments.
    Search and Analysis Capabilities
    Enables searching and analyzing of indexed machine data with visualization capabilities for operational intelligence.
    Data Routing and Destination Management
    Routes data to multiple destinations with capability to deliver specific data to targeted tools while archiving full fidelity data to cost-effective storage
    Data Optimization and Reduction
    Reduces data streams by up to 50% through removal of unused log and metric data
    Event Processing and Transformation
    Processes event data through centralized parsing with capabilities to route, optimize, reformat, and enrich data in flight
    Role-Based Access Control
    Implements role-based access control with support for external authentication via LDAP, Splunk, and OpenID Connect identity providers
    Real-Time Monitoring and Configuration
    Provides GUI-based configuration and testing interface with real-time capture and monitoring of observability pipeline

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.3
    535 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    57%
    36%
    5%
    1%
    1%
    37 AWS reviews
    |
    498 external reviews
    External reviews are from G2  and PeerSpot .
    reviewer2901339

    Centralized log analytics has improved alerting and speeds up finding issues across servers

    Reviewed on Sep 21, 2026
    Review provided by PeerSpot

    What is our primary use case?

    The main use case for Splunk Enterprise Platform is collecting logs from across the enterprise and ingesting them so that we can use them to easily search and also for alerting if there are problems with all the different applications and pieces of software that we have installed here.

    A simple example of how I use Splunk Enterprise Platform for alerting or searching is if we have a Linux server that is running out of memory. We have the Linux logs in Splunk and then we have an alert set up that if the memory gets below a certain threshold, then it creates a ticket for our team to address it. If the memory gets so low that it is a critical issue, then we get paged that it is an urgent issue we need to take care of.

    What is most valuable?

    Splunk Enterprise Platform is very user-friendly, and our users love the ability to use the search interface, which helps determine issues when you know something is happening, but you do not know where it is happening in all of our various items that exist, all the systems that produce logging data.

    For our use case, the absolute best feature of Splunk Enterprise Platform is that you can get data into Splunk Enterprise Platform from anywhere, and that is really useful because there are just so many different sources.

    We are primarily using Universal Forwarders, but we also use HEC forwarders and heavy forwarders to integrate different data sources.

    Our users definitely love the ability to create their own dashboards in Splunk Enterprise Platform so that they can monitor the applications that they are involved in, making that a popular feature.

    Splunk Enterprise Platform has made it a lot faster to find problems. This is very much Splunk Enterprise Platform's core functionality where instead of having to go and SSH into different servers and look at log files on each one, which can take a lot of time, you are able to search via the GUI and pull up logs across all of the applications being monitored.

    What needs improvement?

    I think making the user interface easier to navigate for users is important for improving Splunk Enterprise Platform. It may be that SPL2 takes care of some of this. I have not used that yet, but I know using just SPL, it takes quite a training for users to learn how to search Splunk Enterprise Platform most effectively.

    I come from using Atlassian products a lot, and I found their documentation to be a lot easier to use, so I think Splunk Enterprise Platform could benefit from a lot more documentation out there. When I Google for an issue in Splunk Enterprise Platform, it is maybe 50-50 on whether I will pull back the information I need. It seems like I have to open a support request often with them.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for about 10 years.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is stable, but it could be better.

    What do I think about the scalability of the solution?

    The scalability of Splunk Enterprise Platform is pretty good, as we have not had significant issues with scaling it.

    How are customer service and support?

    The customer support for Splunk Enterprise Platform could be better in that the support agents could be more knowledgeable. It takes a lot of communication to get them on board usually with what we are experiencing.

    How was the initial setup?

    It was fairly easy to do, and I appreciate the opportunity to provide feedback regarding my experience with Splunk Enterprise Platform.

    What's my experience with pricing, setup cost, and licensing?

    I believe that Splunk Enterprise Platform is expensive, but that is about all I know regarding pricing, setup cost, and licensing.

    Which other solutions did I evaluate?

    I know we evaluated options before choosing Splunk Enterprise Platform, but it has been several years ago and I was not involved in that process, so I do not know what the other options were.

    What other advice do I have?

    I would advise others looking into using Splunk Enterprise Platform to carefully evaluate if there is any less expensive option out there at this time that would do enough of what Splunk Enterprise Platform provides, as it is a very expensive product. I would rate my overall experience with Splunk Enterprise Platform an 8.

    reviewer2900259

    Admin role has gained deeper observability and now supports teams with efficient dashboards

    Reviewed on Sep 18, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I am an admin for Splunk Enterprise Platform, so I mostly help other teams use it and enable it. I enable other teams to use dashboards or onboarding different apps and such.

    More recently, we had an onboarding or ingestion of some extra data and as a POC for the HashiCorp app. It was a little challenging because we had to work around some of the different file types and they wanted them coming from specific locations to specific servers. That was a fun thing to do.

    What is most valuable?

    Splunk Enterprise Platform offers great observability into all my apps, as well as being able to use the GUI to edit different things and be able to provide the best experience for our internal teams so that way we can provide the best experience for our customers.

    The overall visibility of Splunk Enterprise Platform is great, but I do really appreciate being able to do specific searches for different teams if they're missing data or if they need extra data in, as well as looking at dashboards and enabling those teams to have the most efficient and productive time.

    I think it handles large data very well. It seems to regulate and maintain itself very well. It corrects itself back on course to resolve those errors.

    What needs improvement?

    I am pretty new to the product, so I haven't really found anything specific. I would really appreciate being able to see who edited certain dashboards or alerts. I think that would be really helpful in the future.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for about eight months.

    What do I think about the stability of the solution?

    It has been reliable.

    What do I think about the scalability of the solution?

    It seems to scale very well, and we have never had issues with licensing or pushing up that license usage.

    How are customer service and support?

    I have interacted with Splunk support and we have weekly or biweekly meetings with them. It has been great to be able to talk through some of the issues that we have, along with getting some links or putting in a support ticket.

    What other advice do I have?

    I would say look into how you would use Splunk Enterprise Platform and maybe compare other options as well. Also, I have always had a really good experience with Splunk and onboarding has been pretty easy, as well as it being super scalable, allowing you to have great observability. It is really good at self-regulating. Any issues or errors, for example a slowed queue or suddenly ingesting a lot of data, it is really good at regulating itself. I think that is great. I would rate this product a 9 out of 10.

    Justim C

    Monitoring has reduced outages and provides live insight into video on demand success rates

    Reviewed on Sep 16, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Splunk Enterprise Platform is to monitor the video on demand success rate for our video platform.

    A specific example of how I use Splunk Enterprise Platform for monitoring the video on demand success rate is that we monitor the success rate of video on demand plays on different markets where customers will order a video on demand program that will play on their set-top box. We collect a lot of log data for that and if a video on demand session fails, it logs an alarm code that will be monitored through our Splunk Enterprise Platform dashboards. It allows us to show the successful setup rate. It gives us information on the user, their MAC address, so we can see if all of the failed attempts are from the same user or different users. It also shows us different markets and allows us to narrow in on what device it might have failed in on based on what alarm ID it flags.

    What is most valuable?

    The best features Splunk Enterprise Platform offers include the customization because the way we have our dashboards set up helps us identify anomalies or if we have something that is happening or if an issue is cleared or not.

    Regarding the customization aspect, we have it set up to graph the success rate over time, and the way the graph shows not only the success rate but failures on the same graph makes it easy to identify those anomalies. It will have a success rate line and then if there is a failure and the success rate line goes down, there is another line on the same graph that will show how many failures there were at that time.

    Splunk Enterprise Platform has positively impacted my organization by helping us reduce our outages through monitoring.

    Monitoring with Splunk Enterprise Platform has reduced outages for us because it is live data and that has allowed us to see trends in an area and anticipate if something is going to happen in a market that we need to get on top of.

    What needs improvement?

    I do not have any suggestions on how Splunk Enterprise Platform can be improved because I am happy with it.

    If I had to think of one area where Splunk Enterprise Platform could be better or easier to use, helpful hints maybe could be added where you hover over something and it gives you some ideas of what you can do for that feature.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for approximately five years.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is stable.

    What do I think about the scalability of the solution?

    Its scalability is easy.

    How are customer service and support?

    I have no complaints concerning customer support for Splunk Enterprise Platform.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution before Splunk Enterprise Platform in my department.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing is great; I just log in. I was given a login and that is how I worked it. I do not think my department dealt with any of that; that is a whole other department within our organization.

    What was our ROI?

    I would say we probably do benefit from having Splunk Enterprise Platform because we use it every day and they have expanded our use of it and they have even decided to migrate it into the cloud versus trying to use other open platform systems. We continue to use it, which would tell me that it has been beneficial.

    Which other solutions did I evaluate?

    Before choosing Splunk Enterprise Platform, I did not evaluate other options.

    What other advice do I have?

    My advice to others looking into using Splunk Enterprise Platform is to research the product and utilize all the support that Splunk provides. I have rated this review a ten out of ten.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2900028

    Centralized logs have transformed user behavior analysis and now speed up daily investigations

    Reviewed on Sep 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Splunk Enterprise Platform is as a log consolidation tool.

    In my day-to-day work, we receive email logs, web logs, and any kind of user activity logs, and we investigate based on anomalies in user activity.

    We initiated user behavior analysis, so we're looking for variations from a known baseline.

    What is most valuable?

    Splunk Enterprise Platform's best features include the ability to ingest data from any source without having to spend too much time getting the data into a set format.

    The flexibility in data ingestion makes ingesting new data sources very easy and very quick for our team, allowing us to have new data sources online within a couple of days.

    Splunk Enterprise Platform has positively impacted our organization by giving us insights into user behavior that we didn't have before, enabling us to track and monitor user activity that would otherwise have been missed.

    It has led to faster investigations, as typically, we can go from query to resolution within a day.

    What needs improvement?

    The ability to delete data is something I would suggest for improvement, as at the moment, you can delete data from search, but you can't delete data permanently, which is an issue sometimes.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for 15 years.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is stable.

    What do I think about the scalability of the solution?

    For our scale, Splunk Enterprise Platform's scalability is fine, as we have a relatively small license.

    How are customer service and support?

    Customer support for Splunk Enterprise Platform is good, but technical support is variable.

    I would rate customer support an eight on a scale of one to ten.

    Which solution did I use previously and why did I switch?

    We did not use a different solution before Splunk Enterprise Platform; this was our first.

    How was the initial setup?

    I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive.

    What was our ROI?

    I can't share any exact figures regarding return on investment, but we've had Splunk Enterprise Platform for 15 years, so I would say they're happy with their ROI.

    What's my experience with pricing, setup cost, and licensing?

    I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive.

    Which other solutions did I evaluate?

    I evaluated other options before choosing Splunk Enterprise Platform; I can't remember them all, but I think Elasticsearch was one of them.

    What other advice do I have?

    My advice to others looking into using Splunk Enterprise Platform is to make sure you have a defined use case you can measure against.

    Splunk Enterprise Platform is deployed on-premises in our organization.

    We don't have it at that scale, but I'm sure Splunk Enterprise Platform would work very well for managing data sovereignty at a petabyte scale within our environment.

    We don't use the trusted control plane, so I don't have experiences in maintaining granular control over data using it.

    We won't be using Splunk Enterprise Platform with any AI because of the client data we hold, which affects how we manage access to our operational data.

    My impression of Splunk Enterprise Platform's approach to managing governance within a private network environment is very good.

    The cost of it keeps it from being a perfect ten for me.

    For manual searches, we are very happy with the outputs of Splunk Enterprise Platform.

    I would rate this product an overall nine out of ten.

    reviewer2900010

    Centralized monitoring has improved cloud VM insights and supports proactive CPU management

    Reviewed on Sep 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Splunk Enterprise Platform is used primarily for our SOC and ingesting all metrics and data from all the virtual machines that we're running in our cloud environment.

    A specific example of how I use Splunk Enterprise Platform in my daily work is monitoring CPU usage for VMs, and if CPU credits run out on a burstable instance, we know to add more credits or reconsider how we're using that VM.

    What is most valuable?

    The latest best feature Splunk Enterprise Platform offers is probably MCP server, where people in the organization don't need to have knowledge of SPL and syntax; they can just query Splunk Enterprise Platform directly.

    MCP server has changed the way my team works and collaborates by democratizing the use of Splunk Enterprise Platform so we don't have to go to someone that knows how to use it; anybody can spin up the co-pilot agent and start querying.

    Splunk Enterprise Platform has positively impacted our organization by providing insight into our environment in a centralized manner so that we don't have to set up alerts in a bunch of different places; we just have to look at one place to get what we need.

    Splunk Enterprise Platform helped save time; we've had a few issues where VMs stopped responding and we had trouble figuring out what was going on, but we just went on Splunk Enterprise Platform and it was easy to see the data there.

    What needs improvement?

    Splunk Enterprise Platform can improve by taking more positive steps towards user-friendliness so that more people can access it without having to go through a bunch of training to learn how to use it.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for about a year and a half.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is stable.

    What do I think about the scalability of the solution?

    Splunk Enterprise Platform's scalability is very good; we can just start plugging in indexes as we need.

    How are customer service and support?

    The customer support has been acceptable; we had an issue that we thought should be easily solvable or something that works out of the box, but it didn't.

    Which solution did I use previously and why did I switch?

    I previously used Microsoft Sentinel and switched because we had more places we needed to ingest data from.

    What was our ROI?

    I have not seen a return on investment and think we have some internal issues; we really just got Splunk Enterprise Platform for our SOC.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing has been fairly straightforward; the partner we had to help us set up was pretty good.

    What other advice do I have?

    I cannot comment on Splunk Enterprise Platform's capability to manage data sovereignty at a petabyte scale within my environment because we're not at that level.

    We haven't been using Splunk Enterprise Platform's federated search for querying data in place, so there hasn't been much evolution or primary drivers for either expanding or limiting its use.

    I have no experience in maintaining granular control over data using the trusted control plane within Splunk Enterprise Platform; we don't use it much.

    I learned a lot at this conference about how we can manage access to our operational data through Splunk Enterprise Platform; we're not quite at that level, but once we are, then I'll have more feedback.

    I don't think we use the feature to track specific metrics to evaluate the success of reducing TCO with Splunk Enterprise Platform's non-indexing analytics approach.

    My advice to others looking into using Splunk Enterprise Platform is to start small; ingest a little bit of data that you can start to see returns on right away, and then expand from there as you learn how it works. My overall review rating for Splunk Enterprise Platform is eight out of ten.

    View all reviews