Overview
The Splunk Enterprise AMI accelerates the speed at which organizations deploy Splunk Enterprise in AWS. Splunk Enterprise is the leading platform for Operational Intelligence, delivering an easy, fast, and secure way to search, analyze and visualize the massive streams of machine data generated by your IT systems and technology infrastructure - physical, virtual and in the cloud. Use this AMI to take Splunk for a test drive, or as the basis for your Enterprise-level deployment. The Splunk Enterprise AMI ships with a fully-featured trial license that is valid for 60 days after launch. After the trial expires, your deployment will default to Splunk Free.
Highlights
- Collect and index any machine-generated data from virtually any source or location in real time. Just point Splunk Enterprise at your data, and it immediately starts collecting and indexing--so you can start searching and analyzing.
- With Splunk Enterprise, you can correlate complex events spanning many diverse data sources across your environment. Types of correlations include time-based correlations, transaction-based correlations, sub-searches, lookups, and joins.
- Splunk Enterprise scales to collect and index tens of terabytes of data per day. And because the insights from your data are mission critical, Splunk Enterprise's clustering technology provides the availability you need, even as you scale out your low-cost, distributed computing environment.
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Refunds are not available
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
To learn what's new in Enterprise 10.4.3, please visit https://docs.splunk.com/Documentation/Splunk/10.4.3/ReleaseNotes/MeetSplunk
Additional details
Usage instructions
Get started with Splunk Web:
- In your EC2 Management Console, find your instance running Splunk Enterprise.
- Copy its public IP.
- Paste the public IP into a new browser tab (do not hit enter yet).
- Append :8000 to the end of the IP.
- Hit enter.
- Log into Splunk for the first time with the following credentials: ** username: admin ** password for Enterprise 7.2.5 and above: SPLUNK-$instance-id$ ** password for Enterprise 7.2.0 and below: $instance-id$
Please modify the security groups to allow and disallow certain IP addresses per your requirements. The default is open to all IP addresses.
Read more about the Splunk Enterprise AMI here: https://docs.splunk.com/Documentation/Splunk/latest/Admin/AbouttheSplunkAMI
Upgrade Instructions: http://docs.splunk.com/Documentation/Splunk/latest/Installation/HowtoupgradeSplunk
Resources
Vendor resources
Support
Vendor support
Options available
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Centralized log analytics has improved alerting and speeds up finding issues across servers
What is our primary use case?
The main use case for Splunk Enterprise Platform is collecting logs from across the enterprise and ingesting them so that we can use them to easily search and also for alerting if there are problems with all the different applications and pieces of software that we have installed here.
A simple example of how I use Splunk Enterprise Platform for alerting or searching is if we have a Linux server that is running out of memory. We have the Linux logs in Splunk and then we have an alert set up that if the memory gets below a certain threshold, then it creates a ticket for our team to address it. If the memory gets so low that it is a critical issue, then we get paged that it is an urgent issue we need to take care of.
What is most valuable?
Splunk Enterprise Platform is very user-friendly, and our users love the ability to use the search interface, which helps determine issues when you know something is happening, but you do not know where it is happening in all of our various items that exist, all the systems that produce logging data.
For our use case, the absolute best feature of Splunk Enterprise Platform is that you can get data into Splunk Enterprise Platform from anywhere, and that is really useful because there are just so many different sources.
We are primarily using Universal Forwarders, but we also use HEC forwarders and heavy forwarders to integrate different data sources.
Our users definitely love the ability to create their own dashboards in Splunk Enterprise Platform so that they can monitor the applications that they are involved in, making that a popular feature.
Splunk Enterprise Platform has made it a lot faster to find problems. This is very much Splunk Enterprise Platform's core functionality where instead of having to go and SSH into different servers and look at log files on each one, which can take a lot of time, you are able to search via the GUI and pull up logs across all of the applications being monitored.
What needs improvement?
I think making the user interface easier to navigate for users is important for improving Splunk Enterprise Platform. It may be that SPL2 takes care of some of this. I have not used that yet, but I know using just SPL, it takes quite a training for users to learn how to search Splunk Enterprise Platform most effectively.
I come from using Atlassian products a lot, and I found their documentation to be a lot easier to use, so I think Splunk Enterprise Platform could benefit from a lot more documentation out there. When I Google for an issue in Splunk Enterprise Platform, it is maybe 50-50 on whether I will pull back the information I need. It seems like I have to open a support request often with them.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about 10 years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable, but it could be better.
What do I think about the scalability of the solution?
The scalability of Splunk Enterprise Platform is pretty good, as we have not had significant issues with scaling it.
How are customer service and support?
The customer support for Splunk Enterprise Platform could be better in that the support agents could be more knowledgeable. It takes a lot of communication to get them on board usually with what we are experiencing.
How was the initial setup?
It was fairly easy to do, and I appreciate the opportunity to provide feedback regarding my experience with Splunk Enterprise Platform.
What's my experience with pricing, setup cost, and licensing?
I believe that Splunk Enterprise Platform is expensive, but that is about all I know regarding pricing, setup cost, and licensing.
Which other solutions did I evaluate?
I know we evaluated options before choosing Splunk Enterprise Platform, but it has been several years ago and I was not involved in that process, so I do not know what the other options were.
What other advice do I have?
I would advise others looking into using Splunk Enterprise Platform to carefully evaluate if there is any less expensive option out there at this time that would do enough of what Splunk Enterprise Platform provides, as it is a very expensive product. I would rate my overall experience with Splunk Enterprise Platform an 8.
Admin role has gained deeper observability and now supports teams with efficient dashboards
What is our primary use case?
I am an admin for Splunk Enterprise Platform, so I mostly help other teams use it and enable it. I enable other teams to use dashboards or onboarding different apps and such.
More recently, we had an onboarding or ingestion of some extra data and as a POC for the HashiCorp app. It was a little challenging because we had to work around some of the different file types and they wanted them coming from specific locations to specific servers. That was a fun thing to do.
What is most valuable?
Splunk Enterprise Platform offers great observability into all my apps, as well as being able to use the GUI to edit different things and be able to provide the best experience for our internal teams so that way we can provide the best experience for our customers.
The overall visibility of Splunk Enterprise Platform is great, but I do really appreciate being able to do specific searches for different teams if they're missing data or if they need extra data in, as well as looking at dashboards and enabling those teams to have the most efficient and productive time.
I think it handles large data very well. It seems to regulate and maintain itself very well. It corrects itself back on course to resolve those errors.
What needs improvement?
I am pretty new to the product, so I haven't really found anything specific. I would really appreciate being able to see who edited certain dashboards or alerts. I think that would be really helpful in the future.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about eight months.
What do I think about the stability of the solution?
It has been reliable.
What do I think about the scalability of the solution?
It seems to scale very well, and we have never had issues with licensing or pushing up that license usage.
How are customer service and support?
I have interacted with Splunk support and we have weekly or biweekly meetings with them. It has been great to be able to talk through some of the issues that we have, along with getting some links or putting in a support ticket.
What other advice do I have?
I would say look into how you would use Splunk Enterprise Platform and maybe compare other options as well. Also, I have always had a really good experience with Splunk and onboarding has been pretty easy, as well as it being super scalable, allowing you to have great observability. It is really good at self-regulating. Any issues or errors, for example a slowed queue or suddenly ingesting a lot of data, it is really good at regulating itself. I think that is great. I would rate this product a 9 out of 10.
Monitoring has reduced outages and provides live insight into video on demand success rates
What is our primary use case?
My main use case for Splunk Enterprise Platform is to monitor the video on demand success rate for our video platform.
A specific example of how I use Splunk Enterprise Platform for monitoring the video on demand success rate is that we monitor the success rate of video on demand plays on different markets where customers will order a video on demand program that will play on their set-top box. We collect a lot of log data for that and if a video on demand session fails, it logs an alarm code that will be monitored through our Splunk Enterprise Platform dashboards. It allows us to show the successful setup rate. It gives us information on the user, their MAC address, so we can see if all of the failed attempts are from the same user or different users. It also shows us different markets and allows us to narrow in on what device it might have failed in on based on what alarm ID it flags.
What is most valuable?
The best features Splunk Enterprise Platform offers include the customization because the way we have our dashboards set up helps us identify anomalies or if we have something that is happening or if an issue is cleared or not.
Regarding the customization aspect, we have it set up to graph the success rate over time, and the way the graph shows not only the success rate but failures on the same graph makes it easy to identify those anomalies. It will have a success rate line and then if there is a failure and the success rate line goes down, there is another line on the same graph that will show how many failures there were at that time.
Splunk Enterprise Platform has positively impacted my organization by helping us reduce our outages through monitoring.
Monitoring with Splunk Enterprise Platform has reduced outages for us because it is live data and that has allowed us to see trends in an area and anticipate if something is going to happen in a market that we need to get on top of.
What needs improvement?
I do not have any suggestions on how Splunk Enterprise Platform can be improved because I am happy with it.
If I had to think of one area where Splunk Enterprise Platform could be better or easier to use, helpful hints maybe could be added where you hover over something and it gives you some ideas of what you can do for that feature.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for approximately five years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Its scalability is easy.
How are customer service and support?
I have no complaints concerning customer support for Splunk Enterprise Platform.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Splunk Enterprise Platform in my department.
How was the initial setup?
My experience with pricing, setup cost, and licensing is great; I just log in. I was given a login and that is how I worked it. I do not think my department dealt with any of that; that is a whole other department within our organization.
What was our ROI?
I would say we probably do benefit from having Splunk Enterprise Platform because we use it every day and they have expanded our use of it and they have even decided to migrate it into the cloud versus trying to use other open platform systems. We continue to use it, which would tell me that it has been beneficial.
Which other solutions did I evaluate?
Before choosing Splunk Enterprise Platform, I did not evaluate other options.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Platform is to research the product and utilize all the support that Splunk provides. I have rated this review a ten out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized logs have transformed user behavior analysis and now speed up daily investigations
What is our primary use case?
My main use case for Splunk Enterprise Platform is as a log consolidation tool.
In my day-to-day work, we receive email logs, web logs, and any kind of user activity logs, and we investigate based on anomalies in user activity.
We initiated user behavior analysis, so we're looking for variations from a known baseline.
What is most valuable?
Splunk Enterprise Platform's best features include the ability to ingest data from any source without having to spend too much time getting the data into a set format.
The flexibility in data ingestion makes ingesting new data sources very easy and very quick for our team, allowing us to have new data sources online within a couple of days.
Splunk Enterprise Platform has positively impacted our organization by giving us insights into user behavior that we didn't have before, enabling us to track and monitor user activity that would otherwise have been missed.
It has led to faster investigations, as typically, we can go from query to resolution within a day.
What needs improvement?
The ability to delete data is something I would suggest for improvement, as at the moment, you can delete data from search, but you can't delete data permanently, which is an issue sometimes.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for 15 years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
For our scale, Splunk Enterprise Platform's scalability is fine, as we have a relatively small license.
How are customer service and support?
Customer support for Splunk Enterprise Platform is good, but technical support is variable.
I would rate customer support an eight on a scale of one to ten.
Which solution did I use previously and why did I switch?
We did not use a different solution before Splunk Enterprise Platform; this was our first.
How was the initial setup?
I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive.
What was our ROI?
I can't share any exact figures regarding return on investment, but we've had Splunk Enterprise Platform for 15 years, so I would say they're happy with their ROI.
What's my experience with pricing, setup cost, and licensing?
I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive.
Which other solutions did I evaluate?
I evaluated other options before choosing Splunk Enterprise Platform; I can't remember them all, but I think Elasticsearch was one of them.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Platform is to make sure you have a defined use case you can measure against.
Splunk Enterprise Platform is deployed on-premises in our organization.
We don't have it at that scale, but I'm sure Splunk Enterprise Platform would work very well for managing data sovereignty at a petabyte scale within our environment.
We don't use the trusted control plane, so I don't have experiences in maintaining granular control over data using it.
We won't be using Splunk Enterprise Platform with any AI because of the client data we hold, which affects how we manage access to our operational data.
My impression of Splunk Enterprise Platform's approach to managing governance within a private network environment is very good.
The cost of it keeps it from being a perfect ten for me.
For manual searches, we are very happy with the outputs of Splunk Enterprise Platform.
I would rate this product an overall nine out of ten.
Centralized monitoring has improved cloud VM insights and supports proactive CPU management
What is our primary use case?
Splunk Enterprise Platform is used primarily for our SOC and ingesting all metrics and data from all the virtual machines that we're running in our cloud environment.
A specific example of how I use Splunk Enterprise Platform in my daily work is monitoring CPU usage for VMs, and if CPU credits run out on a burstable instance, we know to add more credits or reconsider how we're using that VM.
What is most valuable?
The latest best feature Splunk Enterprise Platform offers is probably MCP server, where people in the organization don't need to have knowledge of SPL and syntax; they can just query Splunk Enterprise Platform directly.
MCP server has changed the way my team works and collaborates by democratizing the use of Splunk Enterprise Platform so we don't have to go to someone that knows how to use it; anybody can spin up the co-pilot agent and start querying.
Splunk Enterprise Platform has positively impacted our organization by providing insight into our environment in a centralized manner so that we don't have to set up alerts in a bunch of different places; we just have to look at one place to get what we need.
Splunk Enterprise Platform helped save time; we've had a few issues where VMs stopped responding and we had trouble figuring out what was going on, but we just went on Splunk Enterprise Platform and it was easy to see the data there.
What needs improvement?
Splunk Enterprise Platform can improve by taking more positive steps towards user-friendliness so that more people can access it without having to go through a bunch of training to learn how to use it.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about a year and a half.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Platform's scalability is very good; we can just start plugging in indexes as we need.
How are customer service and support?
The customer support has been acceptable; we had an issue that we thought should be easily solvable or something that works out of the box, but it didn't.
Which solution did I use previously and why did I switch?
I previously used Microsoft Sentinel and switched because we had more places we needed to ingest data from.
What was our ROI?
I have not seen a return on investment and think we have some internal issues; we really just got Splunk Enterprise Platform for our SOC.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been fairly straightforward; the partner we had to help us set up was pretty good.
What other advice do I have?
I cannot comment on Splunk Enterprise Platform's capability to manage data sovereignty at a petabyte scale within my environment because we're not at that level.
We haven't been using Splunk Enterprise Platform's federated search for querying data in place, so there hasn't been much evolution or primary drivers for either expanding or limiting its use.
I have no experience in maintaining granular control over data using the trusted control plane within Splunk Enterprise Platform; we don't use it much.
I learned a lot at this conference about how we can manage access to our operational data through Splunk Enterprise Platform; we're not quite at that level, but once we are, then I'll have more feedback.
I don't think we use the feature to track specific metrics to evaluate the success of reducing TCO with Splunk Enterprise Platform's non-indexing analytics approach.
My advice to others looking into using Splunk Enterprise Platform is to start small; ingest a little bit of data that you can start to see returns on right away, and then expand from there as you learn how it works. My overall review rating for Splunk Enterprise Platform is eight out of ten.