
Overview
If you're looking for security and operational visibility across your AWS environment - including applications, infrastructure and AWS services such as CloudTrail, Config, VPC Flow Logs, and more - then Splunk Cloud is the right solution for you. Organizations of all sizes leverage Splunk visibility with AWS agility to rapidly troubleshoot applications, ensure security and compliance, and monitor business-critical services in real-time. Splunk Cloud makes it easy to gain end-to-end visibility across your AWS and hybrid environment. Leverage Splunk Cloud with the free Splunk App for AWS to gain critical security, operational and cost optimization insight into your AWS deployment. Whether you're managing applications, infrastructure or a security operations center in the cloud, Splunk delivers Operational Intelligence for a real-time understanding of what's happening across your business and IT so you can make informed decisions. It's easy to get started - and remember - when choosing a product option, match your location and anticipated index volume per day. Splunk Cloud is now FedRAMP authorized: Moderate
Highlights
- Collect and index any machine-generated data from virtually any source or location in real time. Just point Splunk Cloud at your data, and it immediately starts collecting and indexing so you can start searching and analyzing.
- Splunk Cloud offers single-pane-of-glass visibility across on-premise Splunk Enterprise and Splunk Cloud deployments, enabling customers to deploy Splunk as software or SaaS according to their business requirements, while maintaining centralized visibility.
- Splunk Cloud includes support for Splunk apps and other content. Splunk apps deliver a targeted user experience for different roles, use cases and enterprise technologies. These apps can help you visualize data in new ways or provide pre-defined views of leading technologies such as Linux, Windows, VMware and more.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Splunk offers a variety of support options to help ensure your success.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Cloud monitoring has improved alerting and dashboards for production applications
What is our primary use case?
Currently, we are using dashboarding and alerting as our main use cases for Splunk Cloud Platform. We also have scheduled reports that run on a daily basis to feed data into those dashboards. We are actively using alerts to notify in Splunk Cloud Platform are monitoring, alerting, and all the notifications for the applications that we are hosting in production.
What is most valuable?
What I appreciate most about Splunk Cloud Platform is the ability to click and create dashboards and alerts very quickly without spending too much time writing SPL queries and getting results. Additionally, the platform is much faster than Splunk Enterprise, allowing us to see things churn quickly.
Splunk Cloud Platform's ability to scale aligns very well with our demand fluctuations, which is why we migrated to it. Splunk Enterprise was not scaling as our demand for Splunk usage grew, and we started experiencing issues with Splunk Enterprise. We migrated to Splunk Cloud Platform to support the additional usage from multiple users, and we are now expecting it to scale and help all the other additional users benefit from Splunk Cloud Platform.
What needs improvement?
I cannot provide detailed feedback on areas for improvement at this time because we have just migrated to Splunk Cloud Platform.
For how long have I used the solution?
I have been using Splunk Enterprise for almost seven years, and for Splunk Cloud Platform, we have recently migrated approximately one month ago.
How are customer service and support?
On a scale of one to ten, I would rate the customer service experience at seven because we have been receiving answers directly from a Splunk POC who has been on-premises helping us out. However, we have experienced delays in getting answers to some of the issues that we faced during migrations, and that has taken some time to get resolutions to, which is why I am rating it at seven.
What other advice do I have?
Something interesting that happened at the conference before we started is that I went into a session not knowing what to expect, and I went into a completely wrong session. When I checked my schedule, I realized this was not where I was supposed to be.
The session was about edge processor, and I did not know how to configure Splunk edge processor. It was a completely different session than what I had planned.
Since I joined this organization, Splunk has been a very important tool for collecting logins and events. We have been using Splunk Enterprise for a very long time, and very recently, we migrated from Splunk Enterprise to Splunk Cloud Platform. My role has been as an end user of Splunk to see how all the migrations have been completed and everything has been done successfully. In my current role, I am responsible for creating alerts and dashboards in Splunk Cloud Platform to assist the production environment and all the monitoring in the production environment.
We have not seen benefits right away because we have just started to migrate to Splunk Cloud Platform. We have been using Splunk Enterprise for a very long time. Splunk Enterprise has had its benefits, and now we want to migrate to cloud to see how that can help us.
My experiences with deploying Splunk Cloud Platform are that it is relatively new for us, but I can speak about Splunk Enterprise. Splunk Enterprise has really benefited us. We have been able to do a lot of analysis by using Splunk, and we have gained a lot of insight into our applications by using it. I would rate this review at nine overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cloud dashboards and alerts have transformed how our team monitors production in real time
What is our primary use case?
Currently, our main use cases for Splunk Cloud Platform involve using dashboarding and alerting most of the time.
We also have scheduled reports that run daily to feed data into those dashboards, and we are actively using alerts to notify in the Webex channels about any issues that have occurred in production on a real-time basis.
What is most valuable?
I appreciate the fact that you can quickly click and create dashboards and alerts without having to spend too much time writing SPL queries to get your results.
Additionally, the fact that it is so much faster than Splunk Enterprise allows us to see things churn quickly.
Since the time I joined this organization, Splunk has been a very important tool for collecting the logins and the events. My organization has been using Splunk Enterprise for a very long time, and very recently, we migrated from Splunk Enterprise to Splunk Cloud Platform. My role has been as an end user of Splunk to see how all the migrations have completed successfully. Now in my current role, I am responsible for creating alerts and dashboards in Splunk Cloud Platform to assist with all the monitoring in the production environment.
What needs improvement?
I cannot say what improvements can be made right now because we have just migrated to Splunk Cloud Platform. I wish I could say more.
For how long have I used the solution?
I have been using Splunk Enterprise for almost seven years. With Splunk Cloud Platform, we have recently migrated, and it has been just over a month.
What do I think about the stability of the solution?
We have not seen benefits right away because we have just started to migrate to Splunk Cloud Platform.
We have been using Splunk Enterprise for a very long time, which has had its benefits, and now we want to migrate to the cloud to see how that can help us.
What do I think about the scalability of the solution?
Splunk Cloud Platform's ability to scale is a very important feature because it aligns with our demand fluctuations, which is why we migrated to Splunk Cloud Platform.
Splunk Enterprise was not scaling as the demand for Splunk usage grew, leading us to face issues that encouraged our migration to Splunk Cloud Platform to support the additional usage from multiple users.
We now expect it to scale and help all additional users benefit from Splunk Cloud Platform.
How are customer service and support?
I rate the customer service technical support for Splunk Cloud Platform at seven, primarily because we have been getting answers from a Splunk POC who has been on-premises helping us out.
However, we have had some delays in getting answers to certain issues we faced during migrations, which has taken some time and resulted in some churn to get resolutions.
What other advice do I have?
Our team has primarily been using AWS services, and the entire team has been using it for all of the seven years we have been here.
Currently, our workloads vary from a very low client headcount early in the day to peak times during the evening hours when people are using more of the network.
Our top priority for using AWS Cloud includes having a lot of different advantages, one of the primary ones being the serverless concept. Instead of having fixed VMs where everything is being hosted, we are now hosted on the cloud, which alleviates worries about scaling our performance at scale. There are many different advantages for which we migrated from on-premises to cloud, including avoiding issues with failovers, which has been facilitated by using AWS.
For cloud migrations, you have to really be aware of what you need to migrate. You need to prioritize everything that you need to work with and also take into account everything that is being done step by step to ensure a smooth transition from your current on-premises resources to the cloud.
You need to start with prioritizing what you really need to migrate, beginning with a prioritizing list. From that point on, you take small steps to migrate whatever is important, followed by migrating the less critical jobs or aspects. Once the migration is done, you verify everything to ensure that your business-critical aspects are taken care of, and you are not missing anything.
My experiences with deploying Splunk Cloud Platform are relatively new, but I can discuss Splunk Enterprise, which has really benefited us significantly. We have been able to do a lot of analysis using Splunk, and we have gained a lot of insight into our applications through it.
Something interesting that happened at the conference before we started is that I went into a session not knowing what to expect, and I went into a completely wrong session that was about edge processor, which is not what I intended to attend.
When I checked my schedule, I realized this is not where I was supposed to be, and I did not even know how to configure Splunk edge processor, so it was a completely different session than what I planned.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Monitoring has improved business insights while search guardrails still need refinement
What is our primary use case?
Splunk Cloud Platform serves as our primary observability solution, focusing on monitoring logs, metrics, and traces for our systems.
We primarily use Splunk Cloud Platform for log monitoring by setting up feature dashboards in my day-to-day work.
Dashboards are used to monitor business API and business-related metrics from logs, which enhances our workflow.
What is most valuable?
Splunk Cloud Platform offers exceptional features including quick upgrades, as Splunk Cloud receives the first upgrade for any GA release with rapid support.
Their team manages indexers and search head upgrades, allowing us to focus on bringing data and creating metrics from it and monitoring that output.
Splunk is very helpful in troubleshooting with its SPL, and the AI assistant significantly helps in troubleshooting issues.
Splunk MCP allows quick turnaround with integration into platforms.
The platform's ability to validate application logs, correlate microservices using trace IDs, and enhance security with threat detection greatly impacts our organization.
What needs improvement?
More guardrails can be implemented, and workload management can be improved in Splunk Cloud Platform.
Ad hoc searches are still being executed with index equal to star, which reveals opportunities for improvement, and there must be a way to enforce this.
Splunk should enforce predicates for users, requiring index equal to an index name instead of allowing index equal to star. This will improve compute utilization and help maintain stability in Splunk Cloud Platform.
For how long have I used the solution?
I have been working in my current field for the last six years.
We have been using Splunk Cloud Platform for the last six years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Scalability is good, as we work with our TAM to ensure our environment is right-sized, preventing any issues or load impacts.
How are customer service and support?
Customer support is very good, and we have a dedicated TAM as well as a dedicated engineer to assist us.
Which solution did I use previously and why did I switch?
We did not use any other solution previously. We were using Splunk Enterprise before migrating to Splunk Cloud Platform, so we have always been Splunk customers.
What was our ROI?
We are utilizing federated search with S3 in our organization, redirecting 20 terabytes of low-value logs into S3.
Using federated search heavily allows us to save significantly on costs, which is a very important metric for us.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing has been very good, as we did not face any issues.
We're receiving all the needed support from the start.
What other advice do I have?
Teams should evaluate their business use case and compare whether that use case can be effectively implemented with Splunk Cloud Platform.
It's important to determine the retention period for logs and to identify high-value logs versus low-value logs; high-value logs can go directly into Splunk Cloud Platform while low-value logs can be redirected to S3, utilizing federated search with S3 for low-value log management.
I would rate this solution a 7 overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cloud monitoring has transformed our security insights and reduces incidents across applications
What is our primary use case?
My main use case for Splunk Cloud Platform is general Splunk usage. Instead of on-prem, we are using cloud.
A quick specific example of how I'm using Splunk Cloud Platform is application monitoring, security monitoring, and enterprise security. Specifically for security monitoring, I'm looking for application-related logging, trying to understand how the applications are progressing, and monitoring the status of the servers and other infrastructure.
What is most valuable?
The best features Splunk Cloud Platform offers include ease of use, good integration, and easy scalability.
Regarding how the integration works and how the scalability has helped my team, when SVC usage is high or if there is lots of data coming in, the scalability is helping us with indexer clustering.
Splunk Cloud Platform has positively impacted my organization by reducing a lot of time, reducing a lot of incidents, and helping in mitigating issues without major downtimes.
Regarding time saved, we have caught many anomalies and issues related to applications or security data coming in through the data, which gave us proactive monitoring as well related to those.
What needs improvement?
I think Splunk Cloud Platform can be improved with some improvements on the ingestion pipelines related to edge processors, including all protocols, not only the HEC or other features. Improvements on the HEC side of things would be beneficial.
For how long have I used the solution?
I have been using Splunk Cloud Platform for almost 10 plus years.
What do I think about the stability of the solution?
Regarding Splunk Cloud Platform's stability, I would say it is kind of stable, though not completely.
What do I think about the scalability of the solution?
Splunk Cloud Platform's scalability is pretty much easy. It is auto-scaling, so we are not even bothering much about it.
How are customer service and support?
I find the customer support to be good enough.
Which solution did I use previously and why did I switch?
We previously used an on-prem solution.
What was our ROI?
I have not seen a return on investment yet; it is just the starting for us and it is completely a non-matured setup as of now on our side.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is pretty much seamless.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, we evaluated our on-prem solution.
What other advice do I have?
My advice to others looking into using Splunk Cloud Platform is to review your data. Do not bring all data; just bring in only what you need. I would rate this product an 8.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cloud logging has transformed availability and now supports fast alerts and responsive dashboards
What is our primary use case?
My main use case for Splunk Cloud Platform includes observability, log management, alerting, dashboarding, and serving as a centralized logging platform.
We have multiple customers in the company that forward their logs to Splunk Cloud Platform, and I help them onboard their applications, as well as creating their dashboards and alerts on Splunk Cloud Platform. I also use the Model Context Protocol, the Splunk MCP server, so that they can use the Agentic AI, as well as their Q and Cloud CLIs to query the platform using MCP.
What is most valuable?
The best features Splunk Cloud Platform offers include accessibility, uptime, redundancy, availability, and ease of use.
I find myself relying on availability the most day-to-day, as well as the features that are available such as MCP.
Splunk Cloud Platform has positively impacted my organization because earlier we were an on-premise enterprise having issues with availability and management. The cloud platform has made availability much better, and customers love the experience as it is very quick and responsive.
Uptime has significantly improved since moving to Splunk Cloud Platform, as well as the support that we get from our support peers at Splunk and Cisco, which is very helpful. The availability of the platform in general has improved, and queries run faster.
What needs improvement?
Splunk Cloud Platform can be improved by providing dedicated documentation, especially regarding the edge processors and MCP, along with continuous updates. Sometimes the model we face gets updated without notifying us, so we need proactive notifications if something is being changed on the back end to notify customers before they see issues.
For how long have I used the solution?
I have been using Splunk Cloud Platform for six months.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable most of the time.
What do I think about the scalability of the solution?
Splunk Cloud Platform is highly scalable.
How are customer service and support?
The customer support is rated eight out of ten.
Which solution did I use previously and why did I switch?
Earlier, we were using a fully on-premise solution, and therefore we had all our servers, search heads, and indexers managed by us. Now we have moved to the cloud.
How was the initial setup?
We did not purchase Splunk Cloud Platform through the AWS marketplace because we already had a license with Splunk Cloud Platform running the enterprise license, and we just migrated it to the cloud.
What was our ROI?
I cannot share metrics, but we have seen a return on investment.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Cloud Platform.
What other advice do I have?
I would rate Splunk Cloud Platform a 10 out of 10.
I chose this rating because the issues we were seeing previously with the on-premise platform are now much better handled, and we do not see them anymore. We do see some new issues occur, but we are learning as we go.
Regarding Splunk Cloud Platform's AI capabilities, I have not used its governance and security features, but I have appreciated the ability to secure data.
The accuracy of Splunk Cloud Platform's output is very good, and the reliability is always also very good.
My impressions of Splunk Cloud Platform's visibility into multiple environments are that we are completely on cloud. Earlier, we were on-premise, and while I have not used Splunk Cloud Platform in a hybrid environment or an on-premise environment, we truly love the cloud environment as it enhances the availability and speed of the platform, and the support provided is very useful.
Regarding Splunk Cloud Platform's zero setup feature for AI models, it works in the best way possible because it is very quick.
My experience with Splunk Cloud Platform's app ecosystem is that it is very easy to manage updates within this ecosystem.
The platform's ability to scale aligns very well with my organization's demand fluctuations, and this has a positive impact on our IT resources as it is very scalable, allowing us to deploy apps very quickly. As the organization demand grows, we can make that happen very quickly too, so the turnaround for customers is very quick.
I use a hybrid of native models over third-party integrations in Splunk Cloud Platform's environment, as some third-party integrations are much more resilient and much more developed than Splunk Cloud Platform's native integrations.
I would highly advise Splunk Cloud Platform to all other users or customers. I recommend they ensure that their support with Splunk and Cisco folks has been confirmed and documented appropriately. Documentation needs to be improved, but the platform overall is very stable and very useful. My overall rating for Splunk Cloud Platform is 10 out of 10.