Secure Your Organization and Mature Your Security Posture with Splunk

Splunk helps security teams navigate uncharted waters and quickly identify, investigate, respond and adapt to threats in dynamic, digital business environments. Splunk's flexible pricing allows you to grow and meet your evolving organizational needs—whether you need to address a specific category of threat, respond to a potential breach, or meet a board-level initiative for compliance or risk. 

ANALYTICS-DRIVEN SIEM

Splunk Enterprise Security


Back to pricing page »

Can I try Splunk Enterprise Security before I buy it?

Yes. The Splunk Enterprise Security Online Sandbox, a free 7-day evaluation, enables you to experience the power of Splunk Enterprise Security – with no downloads, hardware set-up, or configuration required. Get started here.

Can I buy Splunk Enterprise Security as a standalone product?

Splunk Enterprise Security is a Splunk Premium Solution, which requires a Splunk Enterprise license or Splunk Cloud subscription. Please contact us to request pricing information for Splunk Enterprise Security.

What does the license metric “Index Volume/Day” mean?

Splunk Enterprise Security software is priced by how much data you send into your Splunk installation in a day. We recommend that you purchase a license size that aligns with the maximum amount of data you expect to send to Splunk in one day. With this pricing model, you pay once to index the data and then can perform unlimited searches against that data, as well as store as much data as you like. You also have complete flexibility in infrastructure deployment, with no restriction on the number of nodes, cores or sockets.

Do I get a volume discount if I buy a larger Splunk Enterprise Security license?

Yes. Splunk Enterprise Security pricing has built-in volume discounts. You pay based on the amount of data indexed by your Splunk instance on a daily basis, calculated in GB per day. We determine the total plan price by multiplying your desired daily index volume by the unit price per GB.

Can I buy an index volume not mentioned here?

Yes. You can buy any index volume from 1 GB/day to multiple terabytes of data per day. If you are looking for pricing at an index volume not shown here, please contact us.

Do I need to buy support every year?

Yes, first year support is required when buying a Perpetual License. With a Perpetual License, to continue receiving support after the first year, you must purchase an annual support renewal. If you purchase an Annual (Term) License, support is included in the license price. Splunk Enterprise Security’s support offerings include all major and minor software updates and customer support. You can find more information about Splunk Enterprise Security’s support offerings here.

What are the licensing options for Splunk Enterprise Security?

Splunk offers both Perpetual and Term Licenses for Splunk Enterprise Security. A Perpetual License is a one-time license fee that grants you an indefinite right to use the software for as long as you comply with all terms of the license agreement. A Term License is for a specific time period, usually a year, during which you are allowed to access and use the software. At the end of the term, you must stop using the software or purchase new licenses. Splunk also offers multi-year term license options for customers interested in a longer term commitment.

For the Annual (Term) License, the per unit price quoted above includes Standard support. If you renew your Annual (Term) License at the end of your license period, you will also get Standard support included.

Where can I find pricing for Splunk Premium Solutions, such as Splunk Enterprise Security, or Splunk IT Service Intelligence?

These Splunk Premium Solutions require a Splunk Enterprise or Splunk Cloud subscription. Please contact us to request pricing information for Splunk Premium Solutions.

 

Still have questions? Contact us.

How Much Can You Save With Splunk?

Analytics-Driven SIEM

Splunk Enterprise Security in the Cloud


Back to pricing page »

Can I try Splunk Enterprise Security in the Cloud before I buy it?

Yes. The Splunk Enterprise Security Online Sandbox, a free 7-day evaluation, enables you to experience the power of Splunk Enterprise Security – with no downloads, hardware set-up, or configuration required Get started here

Can I buy Splunk Enterprise Security in the Cloud as a standalone product?

Splunk Enterprise Security in the Cloud requires a Splunk Cloud license. Please contact us contact us to request pricing information for Splunk Enterprise Security.

What does the license metric “Index Volume/Day” mean?

Splunk Enterprise Security in the Cloud is priced by how much data you send into Splunk Cloud in a day. We recommend that you purchase an instance size that aligns with the maximum amount of data you expect to send to Splunk in one day. With this pricing model, you pay once to index the data and then can perform unlimited searches against that data.

Do I get a volume discount if I buy a larger Splunk Enterprise Security Cloud instance?

Yes. Splunk Enterprise Security in the Cloud pricing has built-in volume discounts. You pay based on the amount of data indexed by Splunk Cloud on a daily basis, calculated in GB per day. We determine the total plan price by multiplying your desired daily index volume by the unit price per GB. The minimum purchase for Splunk Enterprise Security in the Cloud is 50 GB/day. The unit price per GB decreases as total daily index volume grows from 50 GB/day to 100 GB/day and beyond.

What index volumes are available?

You can buy any index volume from 50 GB/day to multiple terabytes of data per day. For detailed pricing information, please contact us and we will get the pricing information to you.

Does the plan price include support?

Yes, the pricing for Splunk Enterprise Security in the Cloud includes support.

Can I buy more storage with Splunk Cloud?

Your Splunk Enterprise Security in the Cloud Annual Subscription supports storage equivalent to 90 days of indexed data. If you need additional storage, please contact us.

Which AWS Availability Region will my instance be hosted in?

Splunk Enterprise Security in the Cloud is primarily available through the Amazon Web Services (AWS) US East (N. Virginia) Availability Region. If you require your data to be co-located, we support global Availability Regions in the US (N. Virginia, California, Oregon), EU (Dublin, Frankfurt, London), Asia Pacific (Singapore, Sydney, Tokyo) and South America (São Paulo). To deploy in other AWS Availability Regions (different pricing may apply), please contact us.

Have more questions about Splunk Cloud?

Read the technical FAQs.

 

Still have questions? Contact us.

We Offer Significant Volume Discounts

LEVERAGE MACHINE LEARNING

Splunk User Behavior Analytics


Back to pricing page »

Can I try Splunk User Behavior Analytics (UBA) before I buy it?

Yes. Customers can request a Cloud based sandbox trial of Splunk UBA by contacting us.

What is the pricing metric for Splunk UBA and how does it work?

Splunk UBA uses the “ingestion-based” pricing metric. Customers with an existing Splunk Enterprise Security license can purchase UBA as an add-on for data indexed in Enterprise Security under the ingestion-based pricing metric. Splunk UBA is available starting at 500 GB/day. Splunk UBA is also available as a stand-alone offering under the “per monitored account” pricing metric for data ingested from Splunk Enterprise.

Do I get a volume discount if I buy a larger Splunk UBA license?

Yes. Splunk UBA pricing has built-in volume discounts for both ingestion-based and monitored accounts pricing metrics.

Do I need to buy support every year?

Yes, first year support is required when buying a Perpetual License. With a Perpetual License, to continue receiving support after the first year, you must purchase an annual support renewal. If you purchase an Annual (Term) License, support is included in the license price. Splunk’s support offerings include all major and minor software updates and customer support. You can find more information about Splunk’s support offerings here.

Do I need to buy Content Subscription for UBA every year?

If you purchase an Annual (Term) License, Content Subscription is included in the license price.

For a Perpetual License, UBA content subscription is purchased separately, in addition to annual support & maintenance. Splunk’s Content Subscription Service is a delivery mechanism that helps you stay current with the time sensitive nature of the problems you are trying to address. Read more about it here.

What are the licensing options for Splunk UBA?

Splunk offers both Perpetual and Term Licenses for Splunk UBA. A Perpetual License is a one-time license fee that grants you an indefinite right to use the software for as long as you comply with all terms of the license agreement. A Term (Annual) License is for a specific time period, usually a year, during which you are allowed to access and use the software. At the end of the term, you must stop using the software or purchase new licenses. Splunk also offers multi-year term license options for customers interested in a longer term commitment.

Where can I find pricing for Splunk Premium Solutions, such as Splunk User Behavior Analytics (UBA), Splunk Enterprise Security, or Splunk IT Service Intelligence?

Please contact us to request pricing information for Splunk Premium Solutions.

Still have questions? Contact us.

How Much Can You Save With Splunk?

Prepare for the next outbreak

Splunk Insights for Ransomware


Back to pricing page »

Can I try Splunk Insights for Ransomware before I buy it?

Yes. Splunk Insights for Ransomware leverages techniques you can find in a free Splunk app called Splunk Security Essentials for Ransomware. Therefore, you can download Splunk Enterprise free and use it in conjunction with the free Splunk Security Essentials for Ransomware app.

Can I buy Splunk Insights for Ransomware as a standalone product?

Yes, you can buy Splunk Insights for Ransomware standalone. Please contact us to request pricing.

What is the pricing metric for Splunk Insights for Ransomware?

Splunk Insights for Ransomware software is priced by the number of Ransomware Monitored Accounts. “Number of Insights for Ransomware Monitored Accounts” means the number of user and system accounts in Microsoft Active Directory, Lightweight Directory Access Protocol (LDAP) or any similar service that is used to authenticate users inside the network. You can monitor up to 3,000 accounts with Splunk Insights for Ransomware.

The license for Splunk Insights for Ransomware is limited to the following use case: to detect if any ransomware is present, attempting to be present or attempting to be disseminated in Customer’s environment. Not stackable with other Splunk licenses.

Splunk Insights for Ransomware is only available as an Annual (Term) License.

Do I get a volume discount if I buy a larger Splunk Insights for Ransomware license?

Yes. Splunk Insights for Ransomware pricing has built-in volume discounts. You pay based on the number of monitored accounts and we have established pricing tiers with fixed band pricing (not calculated per unit).

I need to buy a solution for more than 3,000 monitored accounts, can I?

The number of monitored accounts supported by the Splunk Insights for Ransomware is capped at 3,000. If you have more than 3,000 monitored accounts, contact us.

Do I need to buy support every year?

Standard Support is included in the license price. Splunk’s support offerings include all major and minor software updates and customer support. You can find more information about Splunk’s support offerings here.

 

Still have questions? Contact us.