Simple and predictable pricing for security professionals

Splunk offers straightforward pricing for our Data-to-Everything Platform, SIEM / Security Analytics, SOAR and UEBA capabilities. Our pricing options include entity-based, workload-based, and more, with the ability to buy offerings in packages or individually.

Modernized Security Operations

Splunk Security Cloud*

What pricing options are available to purchase Splunk® Security Cloud?

Protected-Device Pricing: Splunk Security Cloud is priced by the number of devices that you protect with Splunk. We define a protected device as any device on the customer network whose IP address is referenced in any data ingested into the Splunk platform.

For more information on protected-device pricing, please refer to the Pricing Programs FAQ or contact us.

 

What are the benefits of Protected-Device Pricing?

By pricing Splunk Security Cloud based on the number of devices that customers protect with the offering, we eliminate the need for customers to anticipate future data ingest or compute needs. Customers can determine that they need to ingest more data into Splunk or run more compute-intensive searches, and they will not pay extra for doing so — subject to service limits.

 

Are Security Cloud offerings available on-prem?

No, Security Cloud offerings are only available as cloud-delivered software subscriptions.

 

Want to learn more about Security Cloud?

Please refer to the main security pricing page or contact us.

 

*At present, only available in the US. Contact our sales team for more details.

We offer significant volume discounts

Basic Detections & Dashboards

Splunk Security Cloud Foundations

What pricing options are available to purchase Security Cloud Foundations?

Workload Pricing: This pricing model is based on compute capacity consumed, measured in Splunk Virtual Compute (SVC) units. For more information on Workload pricing, please refer to the Pricing Programs FAQ or contact us.

 

Is Security Cloud Foundations available on-prem?

No, Security Cloud Foundations is only available as cloud-delivered software subscription.

 

Want to learn more about Security Cloud Foundations?

Please refer to the main security pricing page or contact us.

 

How much can you save with Splunk?

Analytics-Driven SIEM

Splunk Enterprise Security in the Cloud

Can I buy Splunk Enterprise Security in the Cloud as a standalone product?

Yes. Splunk Enterprise Security in the Cloud requires a Splunk Cloud license, but that is the only requirement for purchase. Please contact us to request additional pricing information for Splunk Enterprise Security.

 

What are the pricing options for Splunk Enterprise Security in the Cloud?

Workload Pricing: This pricing model is based on compute capacity consumed, measured in Splunk Virtual Compute (SVC) units. For more information on Workload pricing, please refer to the Pricing Programs FAQ or contact us.

 

Do I get a volume discount if I buy a larger Splunk Enterprise Security Cloud instance?

Yes. Splunk Enterprise Security pricing has built-in volume discounts. Contact us to learn more.

 

What license types apply?

Workload pricing applies to both on-prem and cloud deployments of Splunk Enterprise Security. It does not currently apply to Splunk Phantom or Splunk User Behavior Analytics

 

Does the plan price include support?

Yes, cloud plans for Splunk Enterprise Security include support.

 

Can I buy more storage with Splunk Cloud?

Yes. Please contact us for more details around purchasing additional storage.

 

Have more questions about Splunk Enterprise Security in the Cloud?

Contact us.

We offer significant volume discounts

Analytics-Driven SIEM

Splunk Enterprise Security On-Premises

Can I buy Splunk Enterprise Security as a standalone product?

Yes. Splunk Enterprise Security deployed on-premises requires a Splunk Enterprise license, but that is the only requirement for purchase. Please contact us to request additional pricing information for Splunk Enterprise Security.

 

What does the license metric “Index Volume/Day” mean?

“Index Volume/Day” is one of several pricing options for Splunk Enterprise Security, and it represents the amount of data you send to your Splunk installation in a day. If you opt for Index Volume/Day pricing, we recommend that you purchase a license size that aligns with the maximum amount of data you expect to send to Splunk in one day. With this pricing model, you pay once to index the data and then can perform unlimited searches against that data, as well as store as much data as you like. You also have complete flexibility in infrastructure deployment, with no restriction on the number of nodes, cores or sockets.

 

Do I get a volume discount if I buy a larger Splunk Enterprise Security license?

Yes. Splunk Enterprise Security pricing has built-in volume discounts. You pay based on the amount of data indexed by your Splunk instance on a daily basis, calculated in GB per day. We determine the total plan price by multiplying your desired daily index volume by the unit price per GB.

 

Can I buy an index volume not mentioned here?

Yes. You can buy any index volume from 1 GB/day to multiple terabytes of data per day. If you are looking for pricing at an index volume not shown here, please contact us.

 

What Pricing Options Apply for Splunk Enterprise Security when deployed on-premises?

Ingest pricing, predictive pricing, workload pricing. Learn more about these pricing options here.

 

Are there alternatives to volume-based pricing?

Splunk now offers a number of different pricing options depending on an organization's needs. Traditionally, Enterprise Security has been priced by index volume. While this pricing still stands, qualifying customers now have the option to purchase via workload pricing determined by the amount of compute power assigned to a Splunk instance. This pricing model removes data limits and is familiar to many in the industry. Additionally, the predictive pricing program may also be available. Customers who purchase Splunk Enterprise Security in the Cloud have access to protected-device pricing, in which customers pay a fixed amount per each device that they want to protect in their organization.

Contact us for more information or visit the Data-to-Everything Pricing updates page for more information.

 

Do I need to buy support every year?

If you purchase an Annual (Term) License, support is included in the license price. Splunk Enterprise Security’s support offerings include all major and minor software updates and customer support. You can find more information about Splunk Enterprise Security’s support offerings here.

 

What are the licensing options for Splunk Enterprise Security?

Splunk offers Term Licenses for Splunk Enterprise Security. A Term License is for a specific time period, usually a year, during which you are allowed to access and use the software. At the end of the term, you must stop using the software or purchase new licenses. Splunk also offers multi-year term license options for customers interested in a longer term commitment.
For the Annual (Term) License, the per unit price quoted above includes Standard support. If you renew your Annual (Term) License at the end of your license period, you will also get Standard support included.

 

If I already own Splunk Enterprise Security, do I get a discount for Splunk User Behavior Analytics (UBA) and/or Splunk Phantom?

Yes. Splunk offers discounts for customers who purchase multiple products from the Splunk Security Operations Suite, which includes Splunk Enterprise Security, Splunk User Behavior Analytics and Splunk Phantom.

 

How much can you save with Splunk?

LEVERAGE MACHINE LEARNING

Splunk User Behavior Analytics

Can I try Splunk User Behavior Analytics (UBA) before I buy it?

Yes. Customers can request a cloud-based sandbox trial of Splunk UBA by contacting us.

 

What is the pricing metric for Splunk UBA and how does it work?

Splunk UBA uses the ingestion-based pricing metric. Customers with an existing Splunk Enterprise Security license can purchase UBA as an add-on for data indexed in Enterprise Security under the ingestion-based pricing metric. Splunk UBA is available starting at 100 GB/day. Splunk UBA is also available as a stand-alone offering under the “per monitored account” pricing metric for data ingested from Splunk Enterprise.

 

Do I get a volume discount if I buy a larger Splunk UBA license?

Yes. Splunk UBA pricing has built-in volume discounts for both ingestion-based and monitored accounts pricing metrics.

 

Do I need to buy support every year?

If you purchase an Annual (Term) License, support is included in the license price. Splunk’s support offerings include all major and minor software updates and customer support. You can find more information about Splunk’s support offerings here.

 

Do I need to buy Content Subscription for UBA every year?

If you purchase an Annual (Term) License, Content Subscription is included in the license price.

 

Splunk’s Content Subscription Service is a delivery mechanism that helps you stay current with the time-sensitive nature of the problems you are trying to address. Read more about it here.

 

What are the licensing options for Splunk UBA?

Splunk offers Term Licenses for Splunk UBA. A Term (Annual) License is for a specific time period, usually a year, during which you are allowed to access and use the software. At the end of the term, you must stop using the software or purchase new licenses. Splunk also offers multi-year term license options for customers interested in a longer term commitment.

 

Where can I find pricing for Splunk Premium Solutions, such as Splunk User Behavior Analytics (UBA), Splunk Enterprise Security or Splunk IT Service Intelligence?

Please contact us to request pricing information for Splunk Premium Solutions.

 

Still have questions? Contact us.

We offer significant volume discounts

SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE

Splunk Phantom

Can I try Splunk Phantom before I buy it?

Yes. Customers can download the Free Splunk Phantom Community Edition after registering with the Phantom Community. Sign up here.

 

What is the pricing metric for Splunk Phantom and how does it work?

Splunk Phantom uses a user seat pricing metric. The annual subscription price of a Phantom deployment is based on the number of people that use the product, in other words, the number of “user accounts in Phantom” or analyst “seats” that a customer needs.

 

Do I get a volume discount if I buy a larger Splunk Phantom license?

Yes. Splunk Phantom pricing has built-in volume discounts.

 

Do I get a discount for Splunk Phantom if I already own Splunk Enterprise Security?

Yes. Splunk offers discounts for customers who purchase multiple products from the Splunk Security Operations Suite, which includes Splunk Enterprise Security, Splunk User Behavior Analytics and Splunk Phantom.

 

Do I need to buy support for Splunk Phantom every year?

Yes. Support is included in the term license price. Splunk’s support offerings include all major and minor software updates and customer support. You can find more information about Splunk’s support offerings here.

 

Do I need to buy a Content Subscription for Splunk Phantom every year?

No. All Phantom Community content is available to Phantom Community Edition users as well as paid Phantom Enterprise Edition users.

 

What are the licensing options for Splunk Phantom?

Splunk offers term licenses for Splunk Phantom. At the end of the term, you must stop using the software or purchase new term licenses. Splunk also offers multi-year term license options for customers interested in a longer term commitment.

 

Where can I find additional pricing information for Splunk Phantom?

Please contact us to request a detailed quote.

 

Still have questions? Contact us.