Splunk pricing: Predictable, flexible, and built for scale

Flexible plans, predictable costs, and zero surprise overages. Maximize your ROI with built-in controls and pay only for what you need.

Contact us now for a quote.

Contact a Splunk pricing expert

< Back

PRICING PLANS

Choose a plan based on your business drivers

Work with your data, your way. With a variety of pricing models to choose from, you can find the approach that works best for you.

Splunk Platform

Manage telemetry data efficiently and pay only for what you need, no surprise overages. Take control of your data with Ingest and Edge Processors to filter noise before it impacts your budget, and use Federated Search and Machine Data Lake to land and analyze data where it lives. Plus, with Cloud Flex, you can easily reallocate spend across the entire Splunk portfolio without restarting procurement.

  • Choose from activity-based, workload, or ingest pricing
  • Unlimited users and ability to scale to petabytes of data
  • Built-in data filtering and cost controls to eliminate billing surprises
  • Ultimate budget agility with Cloud Flex

Splunk Cloud Platform

Use the Splunk-managed SaaS version of Splunk. Choose from activity-based, ingest, or workload pricing for unlimited users.

  • Bring more eligible Cisco telemetry into Splunk with built-in value at a 0.5x weighted ingest rate
  • Shift investments across Splunk products as your needs change with Cloud Flex
Get a quote
Free trial

Splunk Enterprise

Deploy in a private cloud or on-prem, even in air-gapped environments. Choose from data-ingest or workload pricing for unlimited users.

  • Expand visibility by operationalizing more eligible Cisco telemetry with a weighted ingest rate of 50%
  • Turn raw telemetry into complete operational context​ in any environment
Get a quote
Free trial

Splunk Enterprise Security

The leading AI-powered SecOps platform unifies best-in-class SIEM, SOAR, UEBA, threat intelligence, and detection engineering. Choose between Essentials or Premier editions to reduce costs and align with your goals. Available in the cloud and for self-managed or on-prem environments.

  • Choose from activity-based, workload, or ingest pricing
  • Upgrade from Essentials to Premier when you’re ready
  • Storage and deployment options to fit your needs
  • Full control of usage and costs without hindering scale

Splunk Enterprise Security - Essentials

Threat detection, investigation, and response (TDIR) at petabyte scale. Power your agentic SOC and integrate your AI and SIEM solutions in one place.

Splunk Enterprise Security - Premier

Up-level the analyst experience with the leading AI-powered SecOps platform built for scale and speed. Get all the benefits of Essentials plus UEBA, SOAR, and Automated Threat Analysis.

 

Essentials Edition

Get a quote

Premier Edition

Get a quote

SIEM
Threat Intelligence
Detection Studio
Exposure Analytics
SOAR
User and Entity Behavior Analytics (UEBA)
Artificial Intelligence

Splunk Security Orchestration, Automation, and Response (SOAR)

Use Splunk SOAR as a standalone product. Orchestrate a response plan, automate triage and context enrichment activities, and respond faster with better precision.

Free trial

Splunk Observability

Ensure the resilience and uptime of your critical applications, networks, infrastructure, and business operations. With Splunk Observability Cloud, AppDynamics, IT Service Intelligence (ITSI), and flexible pricing options, you gain complete visibility into performance issues, root causes, and business impacts without spending more than you need.

Splunk Observability Cloud

All your metrics, traces, and logs automatically monitored and correlated in one place. Transparent, flexible pricing avoids billing surprises.

  • Simple, host-based entity pricing starting at $15 per host per month
  • Pay only for what you need
  • Enables predictive AI operations to boost productivity, save money
Free edition

Splunk Observability Cloud Pricing

 

 

Infrastructure

Starts at

$15

per host/month billed anually

Get a quote

 

 

App & Infra

Starts at

$60

per host/month billed anually

Get a quote

 

 

End-to-End

Starts at

$75

per host/month billed anually

Get a quote

 

Infrastructure Monitoring
Log Observer Connect
Network Explorer
Synthetic Uptime Monitoring
APM (incl. Always On Profiling)
Synthetic API Monitoring
Real User Monitoring
Synthetic Browser Monitoring
Database Monitoring Optional add-on. Contact us to learn more.
Secure Application Optional add-on. Contact us to learn more.

Splunk AppDynamics

Correlate hybrid and on-prem application performance with business impact. Bundled base pricing with the ability to add new capabilities only when you need them.

  • Starts at $6 per month, per CPU core, billed annually
  • Optimize traditional, three-tiered, and on-prem business application performance linked to business outcomes
  • Mitigate billing surprises with data and cost controls
Free trial

Splunk AppDynamics Pricing

 

 

Infrastructure Edition

Starts at

$6

per vCPU/month billed anually

Get a quote

 

 

Premium Edition

Starts at

$33

per host/month billed anually

Get a quote

 

 

Enterprise Edition

Starts at

$50

per host/month billed anually

Get a quote

 

Infrastructure Monitoring
Application Performance Monitoring
Database Monitoring
Log Observability
Transaction Analytics

Add-ons

For all editions

Application Security $13.75/month, per CPU core, billed anually
Real User Monitoring $0.06/month, per 1000 tokens, billed anually
Browser Synthetics Monitoring $12/month, per test location, billed anually
SAP $95/month, per CPU Core, billed anually

Splunk IT Service Intelligence

AI-driven incident prediction, detection, and resolution all from one place minimizes alert noise and saves you time.

  • Workload or ingest pricing
  • 30+ pre-configured dashboards and 300+ metrics and events for immediate value
  • Manage, identify, and correlate important system alerts from anywhere
Product tour

Splunk On-Call

Streamline on-call schedules and escalation policies, identify the right person or team for any issue, and remediate incidents faster with Splunk On-Call.

  • Starting at just $5 per user, per month, billed annually for up to 10 seats
  • Integrates with 100+ IT service management integrations
  • Reduce time to resolution with streamlined on-call incident response
Free trial

General Pricing FAQs

Splunk products are priced to provide optimal value for the way you use them and for your deployment. We offer Activity-based, ingest, workload, and entity pricing. Choose the products and pricing models that best fit your needs. You have control over costs and usage, as well as the flexibility to change later.

 

See Splunk Platform pricing, Splunk Security pricing, and Splunk Observability pricing for details. 

Unlike other vendors that penalize you for unexpected data spikes, Splunk offers predictable pricing models. We only charge for overages when you consistently exceed your purchased data ingestion or storage capacity.

 

This approach offers you the flexibility to extend beyond your subscription limits during critical incidents while maintaining control over your costs. You can continuously monitor usage, and if you require increased capacity, you can easily adjust your allocation via the Splunk Support Portal.

Yes. With Cloud Flex, you can reallocate your spend across the entire Splunk portfolio based on what you are actually using, without needing to restart the procurement process. Cloud Flex covers Splunk Platform, Security, Observability, AI, Storage, and Federated Search products, giving you ultimate financial agility.

With numerous deployment options, AI innovation, and our commitment to support for cloud, hybrid, and fully on-premises, air-gapped environments, Splunk helps turn your data into insights and outcomes.

 

As a flexible platform, Splunk allows you to only purchase the solutions you need and optimize your data ingestion, which can lead to cost savings and increased value while reducing your total cost of ownership (TCO).

There are no explicit limits regarding the usage or total number of users allowed to use Splunk at one organization.

 

Splunk usage is generally governed by licensing models that specify capacity thresholds such as data ingestion volumes or user seat counts, depending on the product and deployment type. We give you the flexibility to choose the pricing model and limits that fit your needs. 

 

Contact us if you have questions or need help optimizing data ingestion and usage within license limits. 

Splunk provides data management strategies and tools to help you balance operational visibility with cost efficiency, including: 

 

  • Ingest and Edge Processors: Filter, redact, and route data to focus only on what matters, reducing unnecessary data ingestion and storage costs before data is indexed. 
  • Federated Search: Access and analyze data where it resides (like Amazon S3), avoiding costly data movement and duplication. 
  • Real-time Monitoring: Track usage through access tokens and alerts to detect unexpected consumption spikes and take corrective actions instantly. 

Yes. Volume discounts are available for each of our different plans and solutions. Contact a Splunk pricing expert for details.

Yes. Splunk product purchases include standard support. Support offerings include all major and minor software updates and technical support. Premium support is also available.

Get started

Go from visibility to action with the power of Splunk.