SPECIFIC TERMS FOR SPLUNK OFFERINGS

Last updated: August 2026

Additional terms apply to certain Splunk Offerings as well as to certain Hosted Services environments. The below terms apply to your Offerings and Hosted Services as applicable and are incorporated into the Splunk General Terms.

Splunk Offers Terms
Splunk Cloud Platform
  1. Service Description

    https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice

  2. Security and Protection of Customer Content on Splunk Cloud Platform

    Splunk maintains administrative, physical and technical safeguards to protect the security of Customer Content on Splunk Cloud Platform as set out in the Splunk Cloud Security Exhibit located at https://www.splunk.com/en_us/legal/splunk-cloud-security-addendum.html (“Cloud Security Exhibit”).

    Splunk’s security safeguards include, without limitation, employee (and contractor, as applicable) security training, background testing and confidentiality obligations. Splunk’s security controls adhere to generally accepted industry standards, are subject to audit by third-parties (as described in the Cloud Security Exhibit), and are designed to (a) ensure the security and integrity of Customer Content; (b) detect and protect against threats or hazards to the security or integrity of Customer Content; and (c) prevent unauthorized access to Customer Content.

  3. Service Level Schedule – Splunk Cloud Platform

    Splunk’s Splunk Cloud Service Level Schedule, set out at https://www.splunk.com/en_us/legal/splunk-cloud-service-level-schedule.html, will apply to the availability and uptime of the Splunk Cloud Platform, subject to planned downtime and any unscheduled emergency maintenance according to Splunk’s Maintenance Policy referenced in the Splunk Service Level Schedule. Customer will be entitled to service credits for downtime in accordance with the applicable Service Level Schedule.

  4. Data Usage Policy for Splunk Cloud Platform

    For Subscriptions based on Maximum Daily Indexing Volume, Customer is entitled to periodically exceed the daily volume purchased by Customer in accordance with Splunk’s data ingestion and daily license usage policy set out at https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice# Data_policies.

Splunk On-Call
  1. Service Description

    https://help.victorops.com/

  2. Additional Users

    If Customer wants to add additional permitted users, Customer can do so through the Offering administrative portal, and either (i) Splunk will immediately charge Customer’s credit card for the prorated amount for the current term, or (ii) if Customer does not have a credit card on file, then Splunk will invoice Customer for the additional permitted users in accordance with the General Terms.

  3. Support

    Splunk On-Call support is provided via the following portal:
    https://help.victorops.com/knowledge-base/how-to-contact-splunk-on-call-support/.

  4. Security of Customer Content

    Splunk maintains administrative, physical and technical safeguards to protect the security of Customer Content on Splunk On-Call as set out in the Splunk On-Call Security Exhibit located at https://www.splunk.com/en_us/legal/splunk-on-call-security-addendum.html (“Splunk On-Call Security Exhibit”).


    Customer acknowledges and agrees that Splunk On-Call has not yet undergone a security audit by an independent third party and therefore does not have SOC2 or ISO27001 certification.

  5. Service Level Schedule
    Splunk’s Splunk On-Call Service Level Schedule, set out at https://www.splunk.com/en_us/legal/splunk-on-call-service-level-schedule.html, will apply to the availability and uptime of the Splunk On-Call service.
Splunk Observability Cloud

Splunk Observability Cloud includes the following services (as part of a suite or as individual services): Splunk Infrastructure Monitoring, Splunk Application Performance Monitoring (Splunk APM), Splunk Real User Monitoring (Splunk RUM), Splunk Log Observer Connect, and Splunk Synthetic Monitoring.

 

  1. Service Descriptions

    https://docs.splunk.com/Observability/

  2. Usage, Subscription Limits Enforcement, and Entitlements
    https://www.splunk.com/en_us/legal/usage-subscription-limits-enforcement-and-entitlements.html
  3. Security and Protection of Customer Content.
    • Splunk maintains administrative, physical and technical safeguards to protect the security of Customer Content as set out in the Security Exhibit located at https://www.splunk.com/en_us/legal/splunk-observability-security-addendum.html (“Observability Security Exhibit”). Splunk’s security safeguards include, without limitation, employee (and contractor, as applicable) security training, background testing and confidentiality obligations.
    • Splunk’s security controls adhere to generally accepted industry standards, are subject to audit by third-parties (as described in the Observability Security Exhibit), and are designed to (a) ensure the security and integrity of Customer Content; (b) detect and protect against threats or hazards to the security or integrity of Customer Content; and (c) prevent unauthorized access to Customer Content.
    • Customer is responsible for using Splunk Observability Cloud in compliance with applicable laws, including but not limited to providing notice to and obtaining any necessary consent from individuals whose data will be collected by Customer’s use of the services.
  4. Service Level Schedule – Splunk Observability Cloud
    Splunk’s Splunk Observability Cloud Service Level Schedule, set out at https://www.splunk.com/en_us/legal/observability-service-level-schedule.html, will apply to the availability and uptime of the Splunk Observability Cloud. Customer will be entitled to service credits for downtime in accordance with the applicable Service Level Schedule.
  5. Integration with PCI-DSS-Certified Environments
    Customer hereby acknowledges that Splunk Observability Cloud is not PCI-DSS-certified. Integrating PCI-DSS-certified platforms with Splunk Observability Cloud may result in exposure of PCI data to non-PCI-certified environments.
  6. Definitions
    The following definitions are applicable to Orders for Splunk Observability Cloud services.

"Analyzed Trace" means a trace that was sent to and processed by Splunk APM.

"APM Identities" means the count of all unique spans and initiating operations across all service endpoints for metricization. Additional dimensions on these, specified as select span tags, create further APM Identities based on the count of values of those tags.

“Container” means a stand-alone, executable package of software that includes application software and sufficient operating system libraries to run in isolation but shares the       underlying operating system with other Containers.

“Custom Metric” means any Metric that is not automatically collected and reported as part of Splunk’s standard Host-based integrations.

“Host” means a virtual machine or physical server being monitored.

“Metric” means any unique combination of a metric name and dimension value reporting data to Splunk within the last hour.

“Monitoring MetricSet” means a set of metrics created by default for certain components in a monitored distributed application and designed to alert on changes in application  performance. A Monitoring MetricSet includes metrics such as request rate, error rate, and latency percentiles.

“MTS” means Metric Time Series.

Profiled Container” means a Container that is instrumented to send Profiling data to Splunk APM.

Profiling” means automated collection and analysis of code behavior data from runtime environments.

Profiling Volume” means the amount of Profiling data that customers pay for to be ingested by Splunk APM.

"Serverless Function" means a stand-alone, executable package of single-purpose software that runs in serverless environments and is triggered by an event or message.

“Session Volume” means the amount of Session data that customers pay for to be ingested by Splunk RUM.

"Span" means an area of code instrumented to be captured as part of a recorded transaction (eg. rpc, function). Each service can have many spans. At a minimum, there will be 2 spans - inbound and outbound to the service.

“TAPM” means Trace Analyzed Per Minute.

"Trace" means an array of spans represented as a Directed Acyclic Graph.

“Trace Volume” means amount of trace data per minute that customers pay for to be ingested by Splunk APM.

“Troubleshooting MetricSet” means a set of metrics created by default for certain components in a monitored distributed application and designed to enable detailed analysis  and  troubleshooting of an application. A Troubleshooting MetricSet includes metrics such as the request rate, error rate, root-cause error rate and latency percentiles.

Splunk Observability Free Edition

Terms are available at https://www.splunk.com/en_us/legal/splunk-observability-free-edition-terms.html

Splunk AppDynamics
  1. Service Description and Documentation

    Splunk AppDynamics is offered as a Hosted Service and an On-Premise Product, as indicated in the relevant Order and described more fully in the Documentation available at http://docs.appdynamics.com. (The Hosted Service and On-Premise Product versions are collectively referred here to as the “Product”). The Product provides performance monitoring and analysis of applications, websites, databases and IT infrastructure.

  2. License Entitlements and Restrictions
    Splunk AppDynamics Hosted Service:
    https://help.splunk.com/en/appdynamics-saas 
    Splunk AppDynamics On-Premise Product:
    https://docs.appdynamics.com/appd/onprem/24.x/24.4/en/cisco-appdynamics-licensing/on-premises-licensing/on-premises-license-entitlements-and-restrictions
  3. Security, and Protection of Customer Data
    • The administrative, physical and technical safeguards applicable to the delivery, provisioning, support, and maintenance of the Product are set forth in the Cisco Information Security Exhibit located at https://trustportal.cisco.com/c/r/ctp/trust-portal.html#/1604543381171981 (“Cisco ISE”).
    • These security safeguards adhere to generally accepted industry standards, are subject to audit by third parties as described in the Cisco ISE and are designed to (a) ensure the security and integrity of Customer Content; (b) detect and protect against threats or hazards to the security or integrity of Customer Content; and (c) prevent unauthorized access to Customer Content.
    • Customer is responsible for using the Product in compliance with applicable laws, including but not limited to providing notice to and obtaining any necessary consent from individuals whose data will be collected by Customer’s use of the services.
  4. Service Level Agreement and Enterprise Support
    • The Service Level Agreement exhibit applies to your use of the Splunk AppDynamics Hosted Service. The Service Level Agreement exhibit does not apply to the Splunk AppDynamics On-Premise Product.
    • Enterprise Support, as defined and detailed in the Splunk AppDynamics Enterprise Support exhibit, apply to your use of the Splunk AppDynamics Product

    The term "Offer Description" in the exhibits referenced in this Section 4 refers to these Specific Terms for Splunk Offerings, including this Splunk AppDynamics section. Support pursuant to the Service Level Agreement and Enterprise Support exhibits is delivered by Cisco Systems Inc. (or its designated Affiliate) (“Cisco”).

  5. Systems Information
    The Product collects Systems Information to assist with understanding product usage and enabling product improvements. For more information on Systems Information, please see: https://trustportal.cisco.com/c/r/ctp/trust-portal.html#/1604543672547988.
  6. Data Deletion and Retention
    Notwithstanding anything in the General Terms to the contrary, the Splunk AppDynamics Hosted Service retains personal data in registration information and email delivery information for no more than one (1) year after expiration or termination of the Splunk AppDynamics Hosted Service Term. Personal data in support information will be deleted upon request.
  7. Additional Limits on Usage
    In addition to any usage limits described in the General Terms and Documentation, you will not (and will not authorize any third party to) configure the Product to intentionally collect any: (1) social security numbers or other government-issued identification numbers, (2) unencrypted passwords or other authentication credentials, (3) health information, biometric data, generic data, or any other similar data, (4) payment, financial, insurance or similar information, (5) data relating to a person under the age of 13 years old, or (6) data that is classified as sensitive data, or special category data, under applicable laws. A breach of this paragraph is considered a misuse of our intellectual property rights.
  8. Additional Obligations for the Splunk AppDynamics On-Premise Product
    • If you purchase the Splunk AppDynamics On-Premise Product, you must download, install, and host it in your environment, where you will exercise exclusive control over it and ensure appropriate back-ups of your data are done.
    • You will maintain the Splunk AppDynamics On-Premise Product software in a secured environment accessible only to you and your Third-Party Providers.
    • You will replace or patch the Splunk AppDynamics On-Premise Product software when new releases become available.
    • You will not (and will not authorize any third party to) publish the result of any benchmarking tests run on the Splunk AppDynamics On-Premise Product.
    • You will implement and maintain appropriate technical and organizational measures designed to protect the Splunk AppDynamics On-Premise Product software against accidental loss, destruction or alteration, unauthorized access, or unlawful destruction.
    • Oracle Corporation is a third-party beneficiary under the General Terms solely with respect to the MySQL database included with the Splunk AppDynamics On-Premise Product software.
  9. Open Source Technology
    Separate licenses terms apply to third party open-source technology used in the Product. Open-source terms are found at Cisco’s Open Source webpage, available at: https://www.cisco.com/c/en/us/about/legal/open-source-documentation-responsive.html.
  10. End of Life Policy
    Splunk may end of life the Product in accordance with the Cisco End of Life policy, available at: https://www.cisco.com/c/en/us/products/eos-eol-policy.html
  11. The following products and support, which may be included with your purchase of the Product, are governed by the terms and conditions located at https://www.snpgroup.com/en/eula/ or any superseding agreement between You and Datavard AG, Germany and/or SNP Deutschland GmbH (collectively “SNP”): SNP CrystalBridge Monitoring (formerly known as Datavard Insights) licensed under the “SAP Peak Bundle,” “Enterprise Edition for SAP Solutions Bundle,” or “SAP Peak or Enterprise Edition for SAP Solutions Bundle” software suites; and support for such software suites from SNP.
Splunk Synthetic Monitoring (Legacy Rigor Platform)
  1. Service Description

    https://help.rigor.com/hc/en-us

  2. Security

    Customer hereby acknowledges and agrees that Splunk Synthetic Monitoring (Legacy Rigor Platform) has not yet undergone a security audit by an independent third party and therefore does not have SOC2 or ISO27001 certification.  The security terms in Splunk’s Cloud Security Exhibit and the Observability Security Exhibit do NOT apply. Customer may not upload or transmit to this environment any regulated data, such as financial information (including PCI-DSS data), protected health information, ITAR data or classified information.

  3. Usage, Subscription Limits Enforcement, and Entitlements
    https://www.splunk.com/en_us/legal/usage-subscription-limits-enforcement-and-entitlements.html
Splunk Secure Gateway

Secure Gateway app facilitates communication between mobile devices and Splunk instances with an end-to-end encrypted free cloud service called Spacebridge. Spacebridge cloud service environment, and the service itself, is separate from the Splunk Enterprise and Splunk Cloud offering. Spacebridge is a free Hosted Service and use is subject to Splunk General Terms available at: https://www.splunk.com/en_us/legal/splunk-general-terms.html. See here to learn more about the Spacebridge offering. Learn more

You may not transmit regulated data, including PHI data or PCI data, to Spacebridge unless you are using Spacebridge with a managed Splunk Cloud deployment and have specifically purchased the applicable regulated environment for that managed Splunk Cloud deployment. Spacebridge does not leverage the FIPS 140-2 validated Splunk Cryptographic Module and may not be used in environments that require this standard.

You must agree to use Spacebridge to use Splunk Secure Gateway. If you want to permanently disable the use of Spacebridge, you must disable Splunk Secure Gateway. Disable Splunk Secure Gateway in Apps > Manage Apps. If you’re using a managed Splunk Cloud deployment, file a support ticket to disable Splunk Secure Gateway.

Splunk Security Offerings Terms

Splunk Asset and Risk Intelligence and Exposure Analytics feature of ES Premier

  1. Security Industry Certifications
    Customer acknowledges and agrees that Splunk Asset and Risk Intelligence has not yet undergone a security audit by an independent third party and therefore does not have SOC2 or ISO27001 certification.
  2. Support
    Support for Splunk Asset and Risk Intelligence is set out at https://www.splunk.com/en_us/pdfs/data-sheets/asset-risk-intelligence.pdf
Splunk Attack Analyzer and Automated Threat Analysis feature of ES Premier
  1. Service Level Schedule
    The Service Level Schedule for the Splunk Attack Analyzer, set out at https://www.splunk.com/en_us/legal/attack-analyzer-service-level-schedule.html, will apply to service availability of the Splunk Attack Analyzer Hosted Service. Customer will be entitled to service credits for downtime in accordance with the Service Level Schedule.
  2. Support
    Support for Splunk Attack Analyzer is set out at https://www.splunk.com/en_us/pdfs/data-sheets/attack-analyzer.pdf.
  3. Security of Customer Content
    Splunk maintains administrative, physical and technical safeguards to protect the security of Customer Content on Splunk Attack Analyzer as set out in the Splunk Attack Analyzer Security Exhibit located at https://www.splunk.com/en_us/legal/splunk-attack-analyzer-security-exhibit.html (“SAA Security Exhibit”).
  4. Use of Customer Content
    The operation and functionality of Splunk Attack Analyzer depends on the continuous improvement of detection capabilities through the application of threat intelligence information that is derived from the data our customers submit to the Splunk Attack Analyzer service. Accordingly, Customer agrees that Splunk may use Customer Content submitted to Splunk Attack Analyzer for purposes of analyzing threat trends, enhancing detection capabilities, and otherwise testing, improving and operating Splunk’s products and services, provided that Customer Content will not be disclosed to any third party except in aggregated format and in a manner that does not identify Customer as the source of the Customer Content and could not otherwise be attributable to Customer or any individual.
  5. Use of Customer Content by Cisco Talos
    Cisco’s Talos Threat Hunting Service may be deployed as part of the Splunk Attack Analyzer service in which case the Cisco Talos team may access Customer Content if such data triggers or is related to a security event. Talos Threat Hunting will process data as set forth in the Threat Hunting Offer Disclosure 
Splunk Enterprise Security
  1. Threat Data Usage.
    The operation and functionality of Splunk security Offerings depends on continuously updating and improving detection capabilities through the application of threat intelligence, threat detection, and security event information that is derived from the data our customers submit to Splunk’s Enterprise Security Hosted Service (“Threat Data”). Accordingly, Customer instructs and grants Splunk the right to extract a copy of Threat Data and use Threat Data in connection with providing, creating, and improving our Offerings, which includes training and improving algorithms, detections, and models, and using artificial intelligence, machine learning, and other techniques with Threat Data to gain insights, and to make the Offerings more responsive and predictive to the needs of you and our customers , and to grant to others rights to do any of the foregoing, provided that in all cases Splunk’s use of Threat Data is subject to Splunk’s obligations under the General Terms with respect to Customer Content and Confidential Information. More information about this use is set out in our Documentation at https://help.splunk.com/en/?resourceId=ES_User_ShareThreatData
  2. Use of Customer Content by Cisco Talos
    Cisco’s Talos Threat Hunting may be deployed as part of the Splunk Enterprise Security service.  The Cisco Talos team may access Customer Content if such data triggers or is related to a security event. Talos Threat Hunting will process data as set forth in the Threat Hunting Offer Disclosure .
Splunk Intelligence Management (TruSTAR legacy service)
  1. Service Description
    https://docs.splunk.com/Documentation/SIM/current/User/Intelligenceoverview
  2. Security
    Customer hereby acknowledges and agrees that Splunk Intelligence Management no longer has SOC2 attestation as audited by an independent third party. 
Splunk SOAR

Use of Customer Content by Cisco Talos.

Cisco’s Talos Threat Hunting may be deployed as part of the Splunk SOAR service. The Cisco Talos team may access Customer Content if such data triggers or is related to a security event. Talos Threat Hunting will process data as set forth in the Threat Hunting Offer Disclosure.

 

Hosted Services Environment Terms
FedRAMP or StateRAMP for Splunk Cloud Platform

If you access or use any Hosted Services in the specially isolated Amazon Web Services (“AWS”) GovCloud (US) region that are provisioned in a FedRAMP or StateRAMP authorized environment (“Government Cloud”), you acknowledge the Government Cloud is a more restricted environment.

 

Customer acknowledges that FedRAMP Moderate or StateRAMP Moderate authorized offerings will only meet the standards of an authorized FedRAMP Moderate or StateRAMP Moderate Hosted Service, respectively, if Customer performs its obligations as set out in both the “FedRAMP Low or Moderate Control Implementation Summary (CIS) Worksheet” and the “FedRAMP Low or Moderate Customer Responsibility Matrix (CRM) Worksheet” available from Splunk upon request. Customer acknowledges that FedRAMP High authorized offerings will only meet the standards of an authorized FedRAMP High Hosted Service if Customer performs its obligations as set out in the “SSP Appendix J Control Implementation Summary (CIS) and Customer Responsibility Matrix (CRM) Workbook” available from Splunk upon request. To maintain the security of the FedRAMP or StateRAMP authorized offerings, Customer agrees to cooperate with Splunk to remediate any security vulnerabilities upon Splunk’s request.

 

Business Associate Agreement

Splunk will comply with the requirements and obligations in the Splunk Business Associate Agreement set out at https://www.splunk.com/en_us/legal/splunk-baa.html for (i) Hosted Services provisioned in Splunk Cloud Platform’s Premium HIPAA environment, as specified in an Order; and (ii) Splunk Observability Cloud.

Splunk AI Offerings Terms
Splunk AI Offerings
  1. ORDER OF PRECEDENCE.

    In the event of a conflict between these Specific Terms and the SGT, these Specific Terms will control solely with respect to your use of AI Offerings.

  2. RESPONSIBLE AI AND AI OFFERING DOCUMENTATION.

    We will use artificial intelligence consistent with the Cisco Principles for Responsible Artificial Intelligence (RAI Principles) and the Cisco Responsible Artificial Intelligence Framework (RAI Framework). To the extent required by applicable law, we will provide you with information about our Agentic AI Features and AI Offerings, except that we will not be required to provide information that is proprietary, confidential, or which may harm our other customers. AI Offerings are elements of the respective Offerings through which they are made available. The functionality and details relevant to specific AI Offerings are set forth in the AI Offering Documentation pertinent to such underlying Offerings.

  3. PURPOSE AND USE.

    When you interact with an AI Offering, Splunk will use your Inputs, Context Data, and Outputs (collectively, “AI Service Data”) in accordance with the Cisco General Disclosures. You grant Splunk a worldwide, royalty-free, non-exclusive, sub-licensable, fully paid-up license to access and use your AI Service Data for such purposes as described in the Cisco General Disclosures.

  4. TRAINING AND FINE-TUNING.

    Splunk will not use your AI Service Data for Training and Fine-Tuning AI Models unless you affirmatively opt in to such use through settings in the AI Offering controlled by your authorized administrator. If you opt in, you agree that you also hereby grant Splunk a perpetual, irrevocable, worldwide, royalty-free, non-exclusive, transferable, sublicensable (through multiple tiers), fully paid-up license to use and transform the AI Service Data submitted while your opt-in election is active for the purpose of Training and Fine-Tuning AI Models in any form, medium or technology now known or later developed and to commercialize such AI models and make derivatives thereof. If you subsequently opt out, Splunk will cease using any new AI Service Data for any new Training and Fine-Tuning. An AI Model trained or fine-tuned using your AI Service Data may generate outputs for other users that are the same as or similar to outputs generated for you, this reflects general patterns learned by the AI Model and does not constitute disclosure of your AI Service Data or Confidential Information to other users. 

  5. FEEDBACK.

    “Feedback” has the meaning given in the SGT. Regardless of your Section 4 election, Splunk may use Feedback for any lawful purpose, including Training and Fine-Tuning.

  6. OWNERSHIP OF INPUTS.

    Except with respect to any Pre-existing Splunk Content, as between you and Splunk, Inputs are owned by you. For each Input, you represent and warrant that you have all rights necessary for you to grant the licenses granted in these Terms, and that such Input, and your provision thereof to and through an AI Offering, comply with all applicable laws, rules and regulations, and these Terms.

  7. OWNERSHIP OF OUTPUTS.

    Except with respect to Pre-existing Splunk Content, as between you and Splunk, Outputs are owned by you. You will have the right to access and use the Pre-existing Splunk Content in connection with your applicable Offerings, and those rights will be of the same scope and duration as your rights to the underlying Offering.

  8. RESTRICTIONS AND ACCEPTABLE USE

    In using an AI Offering, you must comply with the Policy, applicable Documentation, and these Terms. In addition, you may not, and may not allow any user or third party to: (i) use an AI Offering or Outputs for any activity for which applicable regulations would require licensure by a local, state, or federal agency or regulatory body if performed by a human; or (ii) use any Output relating to a person for any purpose that could have a legal or material impact on that person, such as making credit, educational, employment, housing, insurance, legal, medical, or other important decisions about them. Your access to and use of an AI Offering is subject to temporary throttling in Splunk’s reasonable discretion in accordance with relevant Documentation.

  9. HIGH-RISK AND SENSITIVE USES.

    An AI Offering is not designed or intended for, and you shall not use it or permit its use for: (i) any use where a failure of the AI Offering could result in death, serious bodily injury, or physical or environmental damage (“Hazardous Use”); or (ii) submitting as Input any sensitive or regulated data, including government-issued identifiers, financial or payment card data, protected health information, biometric or genetic data, children’s data, or special-category data under applicable law, except to the extent expressly permitted for the underlying Offering and AI Offering in the applicable Documentation or Offer Disclosure. You will defend, indemnify and hold Splunk and its affiliates harmless from and against all damages, costs, and attorneys’ fees in connection with any claims arising from a Hazardous Use or your submission or use of such sensitive or regulated data in connection with an AI Offering, including any claims based in strict liability or that Splunk or any of Splunk’s suppliers was negligent in designing or providing the AI Offering or any part thereof to you.

  10. THIRD-PARTY SERVICE PROVIDERS.

    The AI Offering may integrate with a third-party AI service as outlined herein or in the applicable AI Offering Documentation. In cases where such third-party integration is embedded in the AI Offering as provided to you by Splunk, and Splunk transmits your AI Service Data to the third party, Splunk will bind the third party to contractual obligations to afford confidentiality and security safeguards to such AI Service Data that are consistent with those by which Splunk is bound. You consent to Splunk sending your AI Service Data to such third-party AI service to provide the AI Offering services and for the purposes agreed herein.

  11. SUSPENSION.

    If Splunk, in its sole discretion, believes your use of an AI Offering or Agentic AI Features may be in breach of the applicable terms or could result in a potential harm to Splunk, Splunk customers, Splunk vendors, or the general public, Splunk may immediately suspend your use of the AI Offering or Agentic AI Features.

  12. DISCLAIMER OF WARRANTIES.

    YOUR USE OF AN AI OFFERING IS AT YOUR OWN RISK. AI OFFERINGS ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES OF ANY KIND. SPLUNK AND ITS SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, RELIABILITY, AND ERROR-FREE OPERATION. THE DISCLAIMERS AND LIMITATIONS OF LIABILITY APPLY TO DAMAGES OR INJURY ARISING FROM THE USE OR PERFORMANCE OF AI OFFERINGS, EXCEPT TO THE EXTENT SUCH DAMAGES OR INJURY ARISE OUT OF SPLUNK’S GROSS NEGLIGENCE, WILLFUL MISCONDUCT, OR FRAUD. 

  13. INDEMNIFICATION.

    Subject to Section 21 of the SGT, Splunk will defend and indemnify you against any third-party claim alleging that your authorized use of Outputs generated by an AI Offering, including Outputs generated through embedded third-party AI models, infringes or misappropriates a third party’s intellectual property right, except to the extent the claim is attributable to your Inputs, modification of Outputs, use of Outputs in violation of these Terms, the Policy, or the Documentation, failure to conduct reasonable due diligence appropriate for your use case, failure to use safety controls made available by Splunk, or use of an Output that you knew or reasonably should have known was likely to infringe. Without limiting the “Your Indemnification to Us” subpart of Section 21 of the SGT, you will defend and indemnify Splunk from all third-party claims arising from your use of an AI Offering in a manner inconsistent with these Terms, the Policy, or the Documentation.

  14. AGENTIC AI FEATURES.

    If an Offering or AI Offering includes Agentic AI Features, Splunk will identify such features in the applicable Documentation or user interface. The terms in this Section 14 apply to your use of Agentic AI Features:

    • Customer Responsibility and Risk Acceptance for Agentic AI Features. You acknowledge and agree that Agentic AI Features are designed to operate with at least a degree of autonomy. You are responsible for (i) configuring, validating, and monitoring the Agentic AI Features; (ii) carrying out any AI impact assessments required by law; (iii) reviewing and approving any proposed or executed actions by or results from Agentic AI Features; and (iv) ensuring that your use of Agentic AI Features complies with all applicable laws. You understand that Agentic AI Features may generate erroneous, unintended, or unwanted actions, results, configurations, or modifications. There are inherent risks associated with use of Agentic AI Features and their autonomous operation. Splunk will use commercially reasonable efforts to ensure the Agentic AI Features function as described in the applicable documentation. Splunk will be liable for errors, damages, or losses arising directly from (v) a material defect in the Agentic AI Features as provided by Splunk, (vi) Splunk's gross negligence or willful misconduct, or (vii) Splunk’s breach of its express obligations under these Terms. Except as set forth above, and to the extent permitted by law, Splunk disclaims all liability for any actions taken or not taken by Agentic AI Features, or for any consequences arising from such actions or inactions.

    • Human-in-the-Loop Controls. Where Splunk provides Human-in-the-Loop Controls, you are responsible for configuring and actively using these controls to review, approve, modify, or reject results or actions proposed or taken by the Agentic AI Features. Your failure to properly vet results or configure or use such controls, or your decision to override or disable them, will not diminish your responsibility or acceptance of risk as outlined herein. You acknowledge that the effectiveness of Agentic AI Features is contingent upon your proper implementation and oversight of these controls.

    • Indemnification for Agentic AI Features. In addition to your indemnification obligations set forth in the General Terms and Section 13 above, you agree to defend, indemnify, and hold harmless Splunk, its affiliates, and its personnel from and against any claims, causes of action, demands, recoveries, losses, damages, fines, penalties, or other costs or expenses arising from or in connection with (i) your use of any Agentic AI Features in a manner inconsistent with these Terms; (ii) your failure to properly configure any Agentic AI Feature; or (iii) your failure to use or configure Human-in-the-Loop controls provided for Agentic AI Features. This indemnification obligation will not apply to the extent such claims arise directly from a material defect in the Agentic AI Features as provided by Splunk, or from Splunk's gross negligence or willful misconduct. For clarity, issues relating to the uptime, accuracy, or inherent biases of third-party AI Model providers shall not be considered a material defect.

  15. DEFINITIONS

    “Agentic AI Features” means features or functionality that are (1) designed to autonomously initiate or execute actions, configurations, or modification within your environment or other systems; and (2) identified as an Agentic AI Feature within the Splunk Offering user interface or relevant Documentation.


    "AI Model" means a computational system, algorithm, or framework that has been trained on data to learn patterns, relationships, or representations and is designed to process inputs (e.g., prompts or data) and generate relevant and responsive outputs. This term encompasses the underlying architecture, parameters, and weights, and any associated algorithms necessary for its functionality. For clarity, "AI Model" expressly excludes (i) the data used to train the AI Model, (ii) specific inputs provided by a user to the AI Model, and (iii) the outputs generated by the AI Model.


    “AI Offering” means a feature, function, or add-on module of a Splunk product or service that uses artificial intelligence in processing information or producing a response to an end-user provided prompt.


    “AI Offering Documentation” means the descriptive, instructional, and other supporting documentation published by Splunk pertinent to a Specific AI Offering found using “Splunk AI” keywords search here: https://help.splunk.com/en.


    “Context Data” means data stored in your instance of the Splunk Offering that underlies your use of the AI Offering (e.g. your Splunk Cloud environment) provided by the Splunk system to an AI Model, together with end-user provided Input that provides relevant reference data used by the AI Model to meaningfully respond to Input.


    “Human-in-the-Loop Control” means a process in which AI-generated outputs or actions allow for human review, approval, or intervention before or during execution.


    “Input” means the raw data or content that you upload or submit to an AI Offering or that is used as input context from your Offering environment to power an AI Offering.


    “Modify” means to evolve and improve the AI Offering, including without limitation by correcting errors, resolving interoperability issues, patching security vulnerabilities, making feature modifications; improvements; and additions, and by improving services associated with the AI Offering.


    “Output” means the data or content generated by an AI Offering and displayed to the end-user as the response or final result of the end-user’s interaction with the AI Offering.


    “Policy” means the Cisco Acceptable Use Policy as set forth here: https://www.cisco.com/c/dam/en_us/about/legal/cisco-acceptable-use-policy.pdf.


    "Pre-existing Splunk Content” means any materials in which Splunk has pre-existing intellectual property ownership or rights.


    "Training and Fine-Tuning” means teaching or conditioning AI Models to learn patterns and perform specific tasks by supplying the AI Models with datasets and optimizing their relevant parameters; it includes adapting pre-trained AI Models to improve performance through methods such as adjusting relevant weights.

Cisco Firewall Promotional Splunk Capacity Offer
Promotional Capacity Terms
  1. Splunk Cloud Platform or Splunk Enterprise Capacity provided free-of-charge pursuant to the Cisco Firewall Promotional Splunk Capacity offering (“Promotional Capacity”) is subject to the Splunk General Terms and the following additional terms and conditions:
    • In addition to your purchase of eligible Cisco products as described in the promotional materials, you must purchase and maintain at least as much paid-for Capacity of an eligible Splunk product as you receive in Promotional Capacity, and Promotional Capacity will be co-termed with your current license or subscription term for the eligible Splunk product(s), excluding any renewal periods. Splunk makes no guarantee that the Promotional Capacity will be offered at the time of renewal. Upon expiration of the free offering, if you wish to continue utilizing any previously offered Promotional Capacity, you will be required to pay for such Capacity at then-current rates.
    • Promotional Capacity is additive to your paid-for Capacity and not intended to offset or substitute any paid-for Capacity for any Splunk Offering.
    • Promotional Capacity may not be transferred from the legal entity associated with the eligible Cisco Secure Firewall licenses and cannot be combined or split between Splunk instances.
    • Promotional Capacity is provided at the same Support service level as the paid capacity, e.g. if the paid capacity has premium support, the Promotional Capacity will be delivered as premium support.
    • The Promotional Capacity does not apply for determining eligibility for OnDemand Services and Education credits (outlined here: https://www.splunk.com/en_us/customer-success/success-plans.html).
    • Promotional Capacity must be ingested via the Cisco Security Cloud App (https://splunkbase.splunk.com/app/7404) and either of the sourcetype methods, cisco:sfw:estreamer or cisco:ftd:syslog. Promotional Capacity may only be used for ingesting/processing data from qualifying Firewall licenses.
  2. Splunk reserves the right to reduce or immediately terminate any Promotional Capacity if you fail to maintain any eligibility criterion during the course of the promotional period, including but not limited to
    • You fail to maintain an eligible Cisco Secure Firewall Threat Defense license subscription and applicable Cisco Support contract for each such license;
    • You reduce your paid Capacity of eligible Splunk products;
    • Your underlying contract with Splunk is terminated;
    • You deactivate threat data sharing or other required telemetry.
Integrated Enterprise Value Program
  1. The Integrated Enterprise Value (IEV) Program allows Cisco customers to ingest qualifying Cisco data sources into Splunk at a weighted rate (“IEV Rate”). The IEV Program is subject to the Splunk General Terms and the following additional terms:
    • The IEV Program, including the IEV Rate, is only offered for Splunk Enterprise, Splunk Cloud Platform, and Machine Data Lake.
    • To qualify for the IEV Rate, You must enable and maintain telemetry data sharing with Splunk.
    • Splunk can modify the IEV Program and its terms at any time, in its sole discretion.
    • Information about the IEV Program, including prerequisites, license scope, and eligible data, is available here.
Activity Based Pricing
  1. The Activity Based Pricing (“ABP”) Offer

    The ABP Offer provides a licensing model in which Customer commits to an aggregate annual dollar amount (prorated if necessary for quoted periods less than one year) that is based on a committed amount of daily ingest and daily search volume capacity represented by the ABP Products as quoted in each associated annual period (or prorated if necessary). This committed dollar amount establishes a separate “ABP Subscription Balance” for each Splunk Cloud Platform instance (“Instance”) represented within the ABP Products. Customer may then pool its search and data ingest dollar usage within, but not across, each Instance’s ABP Subscription Balance. Such usage is measured, and the equivalent value is deducted from the applicable ABP Subscription Balance in accordance with the terms herein.

    All Splunk Cloud Platform terms listed in the Specific Terms for Splunk Offerings apply to the ABP Offer.

    1. ABP Licensed Capacity
      Under the ABP Offer, Searches and Ingestion are measured in the sub-sections below.
      1. Searches
        1. Search Capacity provided by the ABP Products (“Search”) measures searches as defined here: https://docs.splunk.com/Documentation/Splunk/9.4.2/SearchReference/Search#:~:text=Description,subsearches%20in%20the%20Search%20Manual.
        2. Customer acknowledges that Searches used for Splunk Cloud operations and maintenance are excluded from consuming Search Capacity, and that search metrics displayed in the CMC may differ from those calculated under this ABP Offer-specific definition.
        3. Each Search executed by Customer will deduct its equivalent value (as quoted and as defined in these terms) from the ABP Subscription Balance(s). Such equivalent value is the sum of the Splunk Cloud Platform Core Search unit price and a proportional share of the annual dollar amount(s) for any quoted Premium Apps included in the ABP Products. For example, a quantity of 36,500 Splunk Cloud Platform Core Searches with a unit price of $1 and an aggregate annual Premium App Search price of $36,500 would result in a proportional share of $1 per Search, making the total equivalent value, deducted from the applicable instance’s ABP Subscription Balance, $2 per Search.
        4. For purposes of determining the number of Searches consumed by any individual search, the volume of data scanned per search (measured in GB) will be taken into account to determine number of Searches consumed as follows:
          GB Scanned per Search Search Counts
          Less than 10 GB

          1 Search

          10 GB to 100 GB

          5 Searches

          Greater than 100 GB 25 Searches
      2. Ingest
        1. Ingest Capacity provided by the ABP Products measures each GB of uncompressed data indexed in the associated Splunk instance (“Ingest”). Each GB of Ingest consumes one GB of Ingest Capacity. This consumption deducts the unit price of Ingest from the ABP Subscription Balance(s). For each GB of Cisco-generated data eligible for the Cisco source type benefit (i.e. Integrated Enterprise Value), one GB consumes 0.5 GB of Ingest Capacity.
        2. Each GB of data ingested by Customer will deduct its equivalent value (as quoted) from the ABP Subscription Balance(s).
      3. Usage & Performance

        In the event that usage of the ABP products exceeds the daily ingest and search volume commitment by more than 20% or if you have unoptimized searches, then service performance and responsiveness may degrade. To protect service health, Splunk may engage with Customer to provide guidance on optimized search efficiency. ABP Subscription Balance Management

        Splunk updates Customer’s ABP Subscription Balance(s) (i) upon issuance of invoices that include amounts for ABP Products, with such amounts to be credited to the ABP Subscription Balance(s) and (ii) on a recurring basis each month during the Initial Term as the ABP Subscription Balance(s) are drawn down by Customer usage of ABP Licensed Capacity. If Customer consistently exceeds its daily ingest and search volume commitment by more than 20%, it agrees to engage with Splunk to optimize its ABP usage or to purchase additional ABP Licensed Capacity as needed, at the same annualized unit rates specified in the Order Table

        1. Balance Rollover

          At the end of each annual period (prorated if less than 1 year), Customer may roll over any unused, surplus ABP Subscription Balance for each Instance (up to a maximum of 20% of the value of the ABP Products as quoted in that period), if any, from such period to the next annual period for that same Instance. For clarity, any unused, surplus ABP Subscription Balance remaining after the End Date of the Initial Term (i.e. the last quoted annual period) will not be subject to this provision and will instead be subject to the Carry Forward sub-section below.

        2. Carry Forward

          Upon the expiration of the Initial Term, if Customer renews all Instances in the ABP Offer for a period equal to or longer than the Initial Term quoted herein and for an annualized dollar commitment per Instance equal to or greater than the associated annual dollar commitment applicable to the final year of this Order Document (pro-rated partial dollar amounts will be annualized for this determination), Splunk will rollover any remaining unused, surplus ABP Subscription Balance for each Instance to such ABP Offer renewal’s ABP Subscription Balance in the first year only, up to a maximum of 1/12th of its annual dollar commitment applicable to the final period of this Order Document (“Maximum Rollover Subscription Balance”). Any other positive Subscription Balance is forfeited. Splunk may invoice Customer for any negative balance at the end of the Initial Term if applicable, and Customer will pay such invoice in accordance with applicable payment terms.

    2. Cloud Flex Program Addendum

      If Customer purchases a Splunk Cloud Platform Activity Based Pricing Subscription in conjunction with Splunk’s Cloud Flex Offering, the following will apply. Customer acknowledges that any Cloud Flex Reallocation request that includes either a Splunk Cloud Platform - Activity Based Pricing Search SKU, or an Activity Based Pricing Premium App SKU(s), must reallocate identical quantities across both the Splunk Cloud Platform - Activity Based Pricing Search SKU and any Activity Based Pricing Premium App SKU(s). For clarity, the licensed Capacity of Activity Based Pricing Premium

    3. Reporting

      Splunk (or an Affiliate Distributor or authorized reseller) will provide Customer with a report on a monthly cadence showing actual Search and Ingestion usage.