Splunk
- Company typePrivate
- Founded2003
- HeadquartersSan Francisco, United States
- Headcount5,001–10,000
- GTM typeB2B
- OfferingSoftware
Splunk firmographics
Firmographics- Name
- Splunk
- Legal name
- Splunk LLC
- Website
- https://splunk.com
- Company type
- Private
- Founded year
- 2003
- Operating status
- Acquired
- Headcount range
- 5,001–10,000 employees
- Ownership category
- akta.pro rank
Splunk industry classification
Industry- Product category
- Security and Observability Software Platform
- NAICS
- Software Publishers (513210), Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Attack Detection & Response for Cloud/SaaS (SOC for Cloud) (HDADAGAJ)
- akta.pro secondary industries
- Observability, Monitoring & AIOps (BPAEAKAG), Model Governance, Risk & Compliance (GRC) Platforms (HDAAAKAA)
Keywords
Where Splunk is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Splunk business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Subscription Software: Splunk generates the majority of revenue through subscription-based licensing of its cloud platform and enterprise software. Pricing includes ingest pricing (based on data volume indexed) and workload pricing models. Enterprise agreements typically involve multi-year contracts with annual billing.
- Professional Services: Implementation, training, and consulting services to support Splunk deployments and integrations.
- Platform Licensing: As part of Cisco, Splunk technology is embedded across Cisco's networking and security portfolio, creating cross-sell and upsell opportunities within Cisco's customer base.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Splunk Cloud Platform - Subscription-based cloud deployment |
| Subscription | Annual | Splunk Enterprise - Perpetual or subscription license |
| Freemium | Monthly | Free Trials and Free Editions |
| Usage-based | Pay-as-you-go | Observability Cloud - Usage-based pricing |
| Usage-based | Monthly | Workload Pricing Model |
Go-to-market motion1 record
Distribution channels6 records
Marketing channels7 records
Splunk product offering
Product offeringCore offering
Splunk provides a unified security and observability data platform that ingests and analyzes machine data at petabyte scale, combining SIEM, SOAR, UEBA, APM, AIOps, and IT service intelligence into a single foundation. The platform is delivered as Splunk Cloud Platform (SaaS) or Splunk Enterprise (on-premises) with modular security and observability products, AI-driven agentic operations, and a 2,000+ integration ecosystem. It sells subscription software, perpetual licenses, and professional services to enterprise security and IT operations teams worldwide.
Product overview
Splunk is a unified data platform for security and observability, now a Cisco company following the $28 billion acquisition completed in March 2024. The platform operates on a core-plus-modules architecture centered on Splunk Enterprise and Splunk Cloud Platform as the foundational data engine. Security capabilities are delivered through Splunk Enterprise Security (SIEM), Splunk SOAR (automation), Splunk User and Entity Behavior Analytics (UEBA), Detection Studio, Attack Analyzer, Asset and Risk Intelligence, and Security Essentials. Observability is provided via Splunk Observability Cloud, IT Service Intelligence (ITSI), Splunk AppDynamics, Application Performance Monitoring, Infrastructure Monitoring, Real User Monitoring, Synthetic Monitoring, Database Monitoring, and Digital Experience Analytics. AI capabilities are embedded throughout via AI Toolkit, AI Assistant for SPL (natural language to SPL translation), Splunk MCP Server (Model Context Protocol), Agent Observability (AI agent monitoring), and AI SRE (autonomous troubleshooting). The platform is extensible through Splunkbase with over 2,000 integrations, supports OpenTelemetry instrumentation, and offers SDKs in multiple programming languages.
Differentiator
Problem solved
Functional benefit
Brands
- Splunk Cloud Platform: Flexible data platform offered as a service
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk SOAR
- Splunk Observability Cloud
- Splunk IT Service Intelligence (ITSI)
- Splunk AppDynamics
- Splunk AI Assistant
- AI Toolkit
- Splunk User and Entity Behavior Analytics (UEBA)
- Detection Studio
- Agent Observability
- AI SRE
- Automated Threat Analysis
Products and services
- Splunk Cloud Platform Flexible data platform offered as a service for cloud deployments, providing unified security and observability capabilities without infrastructure management.
- Splunk Enterprise On-premises data platform unifying security and observability with log analysis, infrastructure monitoring, and security operations capabilities.
- Splunk Enterprise Security (ES) AI-powered SecOps platform unifying threat detection, investigation, and response (TDIR) with built-in Cisco Talos threat intelligence for stopping emerging threats at machine speed.
- Splunk SOAR Security Orchestration, Automation and Response platform accelerating and automating incident response with customizable playbooks and automated workflows.
- Splunk User and Entity Behavior Analytics (UEBA) Behavioral analytics solution detecting user and entity anomalies to identify insider threats, credential compromise, and lateral movement.
- Splunk IT Service Intelligence (ITSI) AIOps-powered service monitoring using AI and machine learning to identify anomalies, correlate data, reduce alert noise, and proactively prevent outages.
- Splunk Observability Cloud Comprehensive observability platform providing real-time visibility across any environment with integrated APM, infrastructure monitoring, digital experience analytics, and AI SRE capabilities.
- Splunk AppDynamics Full-stack application performance monitoring optimizing apps with comprehensive insight across applications, infrastructure, and digital experiences.
- Splunk AI Toolkit Platform for building, testing, and deploying custom AI models with embedded anomaly detection workflow for automating detection within IT and security environments.
- Splunk AI Assistant for SPL Natural language interface enabling users to query Splunk data using conversational language, translating natural language queries to SPL for search and analysis.
- Splunk MCP Server Model Context Protocol server connecting AI models securely to Splunk data, enabling AI systems to access and analyze enterprise data.
- Agentic SOC AI-powered security operations center that unifies threat detection, investigation, and response with built-in Cisco Talos threat intelligence, using AI to anticipate, find, and stop emerging threats at machine speed.
- Splunk Agent Observability Monitors AI agents, models, and infrastructure costs with real-time guardrail enforcement, hallucination detection, and bias evaluation for multi-agent systems.
- Splunk AI SRE Site reliability engineering powered by agentic AI for troubleshooting incidents with autonomous action and intelligent root cause analysis.
- Splunk Attack Analyzer Automated threat analysis for examining malicious artifacts, URLs, files and other potential threats through dynamic analysis.
- Splunk On-Call (formerly VictorOps) Incident management and on-call scheduling solution enabling teams to alert, escalate, and resolve incidents efficiently.
- Splunk Detection Studio Tool for developing and monitoring security detections within Splunk Enterprise Security, enabling security teams to create custom detection rules.
- Splunk Asset and Risk Intelligence Continuous asset and identity intelligence for tracking assets, understanding risk posture, and maintaining security visibility.
- Splunk Real User Monitoring (RUM) Browser and mobile user experience monitoring capturing actual user interactions to diagnose performance issues and optimize digital experiences.
- Splunk Synthetic Monitoring Synthetic testing and monitoring simulating user transactions to proactively detect performance degradation and availability issues.
- Splunk Database Monitoring Database performance monitoring providing visibility into database operations, queries, and infrastructure health.
- Splunk Infrastructure Monitoring Cloud, container and on-premises infrastructure monitoring with comprehensive metrics and alerting capabilities.
- Splunk Application Performance Monitoring (APM) Application performance monitoring for troubleshooting performance issues from third-party APIs, network, down to code level with AI-powered acceleration.
- Splunk Digital Experience Analytics Comprehensive user experience analytics including session replay to understand how users interact with web and mobile applications.
- Splunk Federated Search Unified search across different data sources enabling queries to span multiple Splunk deployments and external data stores.
- Splunk Log Observer Connect Log analysis and monitoring tool connecting raw log data with observability workflows and visualizations.
- Splunk Exposure Analytics Security exposure analysis and management identifying vulnerabilities and risks across the enterprise attack surface.
- Splunk Runtime Application Security Real-time application security monitoring and protection for runtime environments.
- Splunk Security Essentials Guided security content and best practices helping organizations implement effective security monitoring and detection capabilities.
- Splunkbase Splunk marketplace with over 2,000 integrations, apps, and add-ons extending Splunk platform capabilities across security, IT, DevOps, and industry-specific use cases.
Companies that use Splunk
Customer profileNamed customers19 records
Segments9 records
Ideal customer profiles4 records
Splunk technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration16 records
AI capability10 records
Feature12 records
Splunk partnerships and signals
Strategic signalPartnerships
16 partnerships are on record, tiered core and minor.
- NetAppcoreNetApp and Cisco expanded their collaboration with a Splunk SOAR playbook enabling automated ransomware response at the storage layer. The integration allows Splunk SOAR users to automatically take incident response actions on NetApp ONTAP storage including blocking suspicious users, taking snapshots, and isolating data volumes. This combines NetApp's Intelligent Data Infrastructure with Splunk's security analytics for improved cyber resilience against AI-accelerated cyberattacks.
- GDIT (General Dynamics Information Technology)coreGDIT and Splunk signed a strategic collaboration agreement to deliver AI-powered cybersecurity offerings to U.S. federal government customers. The partnership combines GDIT's mission support and technology integration experience with Splunk's AI, cybersecurity and data analytics capabilities. Focus areas include AI-powered Security Operations Centers, zero trust offerings, and improved cyber resilience. GDIT has already implemented Splunk across 187 U.S. Air Force bases covering over one million users and for the Virginia Information Technologies Agency serving 8.8 million residents.
- WideField SecuritycoreCisco announced intent to acquire WideField Security to integrate into Splunk business. The acquisition will enable correlation of identity, session, and activity telemetry across human, non-human, and AI-agent activity. WideField specializes in identity security across SaaS, cloud, and on-premises environments with telemetry standardization capabilities. This is part of Cisco's strategy to strengthen agentic security operations center capabilities.
- Galileo TechnologiescoreCisco announced acquisition of Galileo, an AI agent observability platform, to extend Splunk Observability Cloud's existing AI Agent Monitoring capabilities. Galileo provides real-time guardrail enforcement, hallucination detection, bias evaluation, and cost tracking for multi-agent systems. The acquisition positions Splunk as a unified control plane spanning infrastructure, security, and AI agent behavior telemetry.
- Astrix SecuritycoreCisco reportedly acquiring Astrix Security as part of strategy to manage non-human identities and permissions for AI agents. This extends Cisco's secure networking strategy from traditional infrastructure into AI behavior governance and identity control, positioning the company as the trust and security layer for enterprise AI deployments.
- TrainocateminorTrainocate Inc., headquartered in Tokyo, launched two new certified training courses for Splunk Cloud management available in Japanese. The courses target individuals transitioning from Splunk Enterprise on-premises to cloud operations and new administrators. Both offerings are eligible for Splunk training units.
- NetAppcoreNetApp and Cisco expanded their FlexPod converged infrastructure partnership with pre-validated AI architectures integrating NetApp storage, Cisco networking, and NVIDIA AI technologies. Additionally, NetApp released a Ransomware Resilience integration with Splunk SIEM and a new custom SOAR playbook for automated incident response directly on NetApp ONTAP storage.
- AWScoreStrategic collaboration agreement extended between Splunk and AWS for cloud deployments. Splunk is available on AWS Marketplace and AWS has invested heavily in government-specific compliance certifications including FedRAMP. Joint solutions for financial services, public sector, and enterprise observability.
- AccenturecoreAccenture and Splunk formed a Business Group to help organizations capitalize on cloud and drive greater value from data and analytics insights. Accenture provides implementation and consulting services for Splunk deployments globally.
- DeloittecoreDeloitte is a global strategic partner providing consulting and implementation services for Splunk solutions across security, observability, and digital transformation engagements.
- EY (Ernst & Young)coreEY is a global partner providing cybersecurity consulting and implementation services for Splunk solutions, including managed security services and compliance offerings.
- Booz Allen HamiltoncoreBooz Allen Hamilton is a strategic partner providing defense and federal government cybersecurity services using Splunk technology, including specialized solutions for national security and defense applications.
- McLaren RacingminorMulti-year Formula 1 partnership extension bringing Splunk data analytics to McLaren racing operations for performance optimization and operational excellence.
- MicrosoftcoreSplunk integrates with Microsoft Azure, Microsoft 365, and Azure Sentinel. Joint go-to-market for federal government customers including Azure government cloud deployments. Splunk available through Azure Marketplace.
- Google CloudcoreSplunk Observability Cloud available on Google Cloud with integrations for Google Cloud operations suite. Strategic partnership announced for joint customer deployments and data analytics integration.
- Cisco SystemscoreCisco completed acquisition of Splunk in March 2024 for approximately $28 billion. Splunk is now integrated into Cisco's broader networking, security, and observability portfolio. Splunk technology powers Cisco Data Fabric and Agentic SOC capabilities. The acquisition combined Cisco's networking expertise with Splunk's SIEM and observability platform.
Scale indicators13 records
Recent moves7 records
Expansion highlights6 records
Splunk competitors and assessment
Company assessmentDirect peers
- Datadog: Datadog is a cloud-native observability and security platform competing head-to-head with Splunk Observability Cloud and Enterprise Security on APM, infrastructure monitoring, SIEM, and cloud security. It is Splunk's most cited direct competitor in pricing-page and analyst comparisons.
- Dynatrace: Dynatrace provides AI-driven observability, APM, and application security with Davis AI engine, directly overlapping with Splunk ITSI, AppDynamics, and Observability Cloud. Frequently compared on agentic cloud operations and AIOps.
- Elastic: Elastic provides search and observability (Elastic Observability, Elastic Security SIEM) on the Elasticsearch platform, directly competing with Splunk's search-driven data foundation. It is positioned as a lower-cost alternative to Splunk Enterprise and ES.
- New Relic: New Relic offers full-stack observability and APM, competing with Splunk Observability Cloud and AppDynamics. It is frequently cited in observability vendor comparisons and is named explicitly as a Splunk competitor.
- Sumo Logic: Sumo Logic is a cloud-native SaaS log management and SIEM platform directly competing with Splunk Cloud Platform and Enterprise Security, particularly in mid-market and DevOps-led deployments.
- LogRhythm (Exabeam / LogRhythm): LogRhythm and Exabeam are enterprise SIEM and UEBA vendors that compete head-to-head with Splunk Enterprise Security and UEBA in mid-market and enterprise security operations deals.
Broad incumbents
- Microsoft Sentinel: Microsoft Sentinel is a cloud-native SIEM bundled with the Azure ecosystem and E5/M365 licenses, directly competing with Splunk Enterprise Security. Its native integration with Microsoft Defender, Entra ID, and Azure data sources makes it the most strategically dangerous incumbent challenger.
- IBM QRadar: IBM QRadar is a longstanding enterprise SIEM platform competing with Splunk ES for large, regulated accounts. It is part of IBM's broader security portfolio and is a frequent finalist in enterprise SIEM deals.
- ServiceNow (Security Operations / ITSM): ServiceNow offers Security Incident Response and ITSM workflows that intersect with Splunk SOAR and ITSI. It competes at the workflow and SecOps orchestration layer, often integrating with Splunk as part of broader enterprise deals.
Emerging players
- Palo Alto Networks (Cortex XSIAM / XDR): Palo Alto Networks' Cortex XSIAM and XDR offering is a fast-growing SIEM and security operations platform that consolidates detection, investigation, and response on a single data lake, directly competing with Splunk ES and Agentic SOC.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Splunk social profiles
Digital presenceSplunk compliance and trust
Trust signalCompliance10 records
Splunk financial estimates
Financial estimateRevenue estimate
Valuation estimate
Splunk leadership team
Management profileNumber of profiles
Profiles44 records
Splunk subsidiaries and ownership
Company hierarchySubsidiaries3 records
Splunk funding detail
Funding detailFunding overview
Funding rounds9 records
Investors9 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Splunk M&A and investment
M&A and investmentM&A16 records
Investments3 records
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Splunk
What does Splunk do?
Splunk provides a unified security and observability data platform that ingests and analyzes machine data at petabyte scale, combining SIEM, SOAR, UEBA, APM, AIOps, and IT service intelligence into a single foundation. The platform is delivered as Splunk Cloud Platform (SaaS) or Splunk Enterprise (on-premises) with modular security and observability products, AI-driven agentic operations, and a 2,000+ integration ecosystem. It sells subscription software, perpetual licenses, and professional services to enterprise security and IT operations teams worldwide.
Is Splunk a public or private company?
Splunk is a private company. It is classified as corporate owned and is currently acquired.
When was Splunk founded?
Splunk was founded in 2003. It employs 5,001 to 10,000 people.
Where is Splunk based?
Splunk is headquartered in San Francisco, United States, in the North America region.
How does Splunk make money?
Three revenue lines are on record. Subscription Software is the primary driver. The others are professional Services and platform Licensing.
Who are Splunk's main competitors?
Direct peers on record are Datadog, Dynatrace, Elastic, New Relic, Sumo Logic and LogRhythm (Exabeam / LogRhythm). Broad incumbents are Microsoft Sentinel, IBM QRadar and ServiceNow (Security Operations / ITSM). Palo Alto Networks (Cortex XSIAM / XDR) is listed as an emerging player.
Does Splunk have an API?
Yes. Splunk offers a comprehensive REST API enabling developers to build custom applications, automate workflows, and integrate with external systems. The platform provides SDKs in multiple languages (Python, JavaScript, Java, Go, Ruby, PHP) and supports OpenTelemetry for instrumentation. Splunk also offers the Splunk AI Search service with specific terms governing input/output ownership and genAI usage, including restrictions against using outputs for developing competing products or providing professional advice. Developer documentation is at help.splunk.com.
What industry is Splunk in?
Splunk's product category is Security and Observability Software Platform. Its primary akta.pro industry code is HDADAGAJ, Attack Detection & Response for Cloud/SaaS (SOC for Cloud), with a secondary code of BPAEAKAG, Observability, Monitoring & AIOps. Its NAICS code is 513210 and its SIC code is 7372.