AI Summary
About
Splunk is an enterprise data platform for security (SIEM/SOAR), observability (APM/RUM/infrastructure monitoring), and IT operations, built around ingesting, indexing, and searching machine-generated telemetry at scale. Its footer and site chrome now brand it “a Cisco company,” reflecting Cisco’s 2024 acquisition of Splunk.
The product line spans Splunk Platform (Cloud Platform and self-managed Enterprise) for core log ingestion and search; Splunk Enterprise Security (Essentials/Premier editions) and standalone SOAR for SecOps; and Splunk Observability (Observability Cloud, AppDynamics, IT Service Intelligence, On-Call) for application and infrastructure monitoring. Customers include large enterprises running unlimited-user deployments at petabyte data scale, from cloud-native shops to air-gapped, on-prem, or private-cloud environments.
Pricing is metered across four mechanics — activity-based (ingest + search), workload (compute/storage via Splunk Virtual Compute units or vCPUs), ingest (per GB), and entity (per host/container/device) — but almost every product line routes prospects to a “Get a quote” lead form rather than publishing a rate card. The two exceptions are Observability Cloud and AppDynamics, which publish per-host/vCPU starting prices alongside their sales-led enterprise motion.
Pricing summary : four metering models, almost entirely sales-quoted
Splunk uses a multi-model, mostly sales-quoted metering structure with four billing dimensions, and customers pick which one applies per product:
- Activity-based pricing: a dual meter on both ingest volume and search activity; Splunk describes it as the more transparent, granular option for complex implementations, paired with Cloud Flex for reallocating spend across products. No public rate is shown — quote only.
- Workload pricing: priced on compute/storage resources consumed by search and analytics workloads, measured in Splunk Virtual Compute (SVC) units for Splunk Cloud Platform or vCPUs for Splunk Enterprise. An interactive sizing calculator (Workload Type + GB ingested/day) estimates SVCs, but the actual price is still sales-quoted.
- Ingest pricing: priced purely on GB of data ingested, with unlimited users and search activity at no extra cost.
- Entity pricing: priced on the number of monitored hosts/containers/protected devices, available for Observability and security products, with unlimited ingestion per entity.
Layered on top, Splunk Observability Cloud and Splunk AppDynamics publish self-serve per-host/vCPU starting rates ($15–$75/host/mo and $6–$50/vCPU-or-host/mo respectively), while Splunk Platform, Enterprise Security, SOAR, and IT Service Intelligence remain entirely quote-gated.
What makes this different: Splunk is one of the few usage-metered platforms where the metering mechanic (activity/workload/ingest/entity) is customer-selectable per product, but the actual rate for that mechanic is disclosed for almost none of its core Platform/Security lines — pricing transparency is concentrated in the newer Observability/AppDynamics rate cards, not the legacy SIEM/log-management business.
Pricing by product
Splunk Platform (Cloud Platform & Enterprise)
| Tier | Price | Included | Key mechanics |
|---|---|---|---|
| Splunk Cloud Platform | Contact us | Splunk-managed SaaS; unlimited users; choose activity-based, ingest, or workload pricing | 0.5x weighted ingest rate for eligible Cisco telemetry; Cloud Flex spend reallocation |
| Splunk Enterprise | Contact us | Private cloud, on-prem, or air-gapped deployment; unlimited users; choose ingest or workload pricing | 50% weighted ingest rate for eligible Cisco telemetry |
Splunk Enterprise Security & related products
| Tier | Price | Included | Key mechanics |
|---|---|---|---|
| Enterprise Security — Essentials | Contact us | SIEM, Threat Intelligence, Detection Studio, Exposure Analytics, built-in AI | Cloud or self-managed/on-prem; sales-quoted |
| Enterprise Security — Premier | Contact us | Everything in Essentials plus SOAR, User & Entity Behavior Analytics (UEBA), Automated Threat Analysis | Upgrade path from Essentials; sales-quoted |
| SOAR (standalone) | Contact us | Orchestration, automated triage, and context-enrichment as a standalone product | Sales-quoted, free trial available |
| IT Service Intelligence | Contact us | 30+ pre-built dashboards, 300+ metrics/events, AI-driven incident prediction | Workload or ingest pricing; sales-quoted |
| On-Call | $5/user/mo billed annually (up to 10 seats) | 100+ IT service management integrations | Only broadly self-serve-priced item outside Observability/AppDynamics; free trial |
Splunk Observability Cloud
| Tier | Price | Included | Key mechanics |
|---|---|---|---|
| Infrastructure | $15/host/mo, billed annually | Infrastructure Monitoring, Log Observer Connect, Network Explorer, Synthetic Uptime Monitoring | Entry tier; free trial (“Start for free”) available |
| App & Infra | $60/host/mo, billed annually | Everything in Infrastructure plus APM (incl. Always-On Profiling), Synthetic API Monitoring | Mid tier |
| End-to-End | $75/host/mo, billed annually | Everything in App & Infra plus Real User Monitoring, Synthetic Browser Monitoring | Top tier; Database Monitoring & Secure Application are optional add-ons, “Contact us” |
Standalone module starting prices (sold individually as well as bundled above): Infrastructure Monitoring $15/host/mo; Application Performance Monitoring $55/host/mo; Real User Monitoring $14 per 10,000 sessions; Synthetic Monitoring $1 per 10,000 uptime requests; Database Monitoring $75/database instance/mo; Secure Application $22/host/mo — all billed annually.
Splunk AppDynamics
| Tier | Price | Included | Key mechanics |
|---|---|---|---|
| Infrastructure Edition | $6/vCPU/mo, billed annually | Infrastructure Monitoring only | Entry tier |
| Premium Edition | $33/host/mo, billed annually | Adds Application Performance Monitoring, Database Monitoring, Log Observability | Mid tier |
| Enterprise Edition | $50/host/mo, billed annually | Adds Transaction Analytics | Top tier |
Add-ons (all editions): Application Security $13.75/mo per CPU core; Real User Monitoring $0.06/mo per 1,000 sessions; Browser Synthetics Monitoring $12/mo per test location; SAP $95/mo per CPU core — all billed annually.
Sales motions across products: self-serve starting rates are published only for Observability Cloud, AppDynamics, and On-Call (up to 10 seats); Splunk Platform (Cloud/Enterprise), Enterprise Security, SOAR, and IT Service Intelligence are entirely sales-led and quote-gated via the “Get a quote” / talk-to-sales flow.
Hidden costs : what the per-host and per-GB headline rate leaves out
The advertised per-host or per-vCPU starting price understates what a real deployment pays once add-on modules, database instances, and legacy ingest volume are layered on — a pattern common across the broader AI/infrastructure monitoring pricing category, not just Splunk. Three real-world examples:
Archetype 1 — a 50-host full-stack Observability Cloud team
| Line item | Monthly cost |
|---|---|
| End-to-End tier, 50 hosts @ $75/host/mo | $3,750 |
| Database Monitoring add-on, 10 db instances @ $75 | $750 |
| Secure Application add-on, 50 hosts @ $22/host | $1,100 |
| Total | $5,600 |
The $75/host “starts at” headline is only the App/APM/RUM bundle — the two add-ons Splunk sells separately (Database Monitoring, Secure Application) push the real bill up more than 50% before a single Synthetic Monitoring request is counted.
Archetype 2 — a 20-host AppDynamics Enterprise deployment with security add-ons
| Line item | Monthly cost |
|---|---|
| Enterprise Edition, 20 hosts @ $50/host/mo | $1,000 |
| Application Security add-on, 40 CPU cores @ $13.75/core | $550 |
| SAP add-on, 8 CPU cores @ $95/core | $760 |
| Total | $2,310 |
Application Security and SAP add-ons alone are more than double the base Enterprise Edition license here — a pattern common across Splunk’s per-vCPU/per-core add-on structure.
The classic ingest “surprise renewal”
Splunk’s legacy ingest-per-GB/day model — still the default mechanic behind the quote-gated Splunk Platform and Enterprise Security — is not on a public rate card, so no table above can responsibly price it. Third-party pricing analysts (see costbench.com and siemcostcalculator.com) estimate list rates in the range of $150-$200/GB/day, with real enterprise deals landing far lower (roughly $0.75-$1.00/GB/day all-in on multi-year, 200+ GB/day commitments) once the routine 40-70% enterprise discount is applied. That list-to-street-price gap — and the fact that ingest grows automatically as logging expands — is the mechanic behind Splunk’s long-running “surprise renewal” reputation: teams that add new data sources or expand retention discover the increase only at the next true-up, not at the moment they turned the logging on. This is precisely the AI cost unpredictability / bill-shock pattern our own FinOps coverage tracks in usage-metered software generally, and it is the core argument for workload pricing as an alternative meter.
Want to estimate your own Splunk bill? Use the Splunk pricing calculator to model your monthly cost based on host counts, add-on modules, and ingest volume.
Pricing evolution : from data-volume pioneer to Cisco business unit
Cadence
| Quarter | Price changes | Product / SKU additions | Notes |
|---|---|---|---|
| 2018 Q2 | 0 | 1 | 2018-06-11: Splunk agrees to acquire VictorOps ($120M), later rebranded Splunk On-Call. |
| 2019 Q4 | 1 | 1 | 2019-10-02: SignalFx acquisition (future Observability Cloud); 2019-11-01: perpetual licenses discontinued, term-only pricing going forward. |
| 2021 Q4 | 1 | 0 | .conf21 (Oct 2021): workload-based pricing opened to all Splunk Cloud customers, not just pilot accounts. |
| 2022 Q2 | 1 | 1 | 2022-05: Splunk Observability Cloud brand launches (SignalFx + VictorOps unified); workload pricing becomes the default Cloud model. |
| 2023 Q3 | 0 | 0 | 2023-09-21: Cisco announces agreement to acquire Splunk for ~$28B (923-point Hacker News thread). |
| 2023 Q4 | 0 | 0 | 2023-11-01: Splunk cuts ~7% of workforce ahead of the Cisco deal’s close. |
| 2024 Q1 | 0 | 0 | 2024-03-18: Cisco completes the ~$28B Splunk acquisition; site rebrands “a Cisco company.” |
| 2026 Q3 | 1 | 2 | Live capture shows Observability Cloud unbundled into three tiers ($15/$60/$75/host, vs. the single “$65/host” headline seen in 2022) plus a new 0.5x weighted-ingest discount for eligible Cisco telemetry. |
Tracked range: 2018-2026. The 2022-09 through 2026-08 window is not directly evidenced by a captured Wayback snapshot — the 2026 Q3 row reflects our own live capture compared against the last legible 2022 snapshot, not a dated mid-window event. Quarters not listed above have no corroborated pricing event.
Notable changes
- 2018-06-11 — Splunk agrees to acquire VictorOps for $120 million (Splunk investor news release; Crunchbase).
- 2019-10-02 — Splunk acquires SignalFx, the technical seed of today’s Observability Cloud (splunk.com acquisitions page).
- 2019-11-01 — Splunk stops selling perpetual licenses worldwide; every new deal becomes a term license (splunk.com perpetual-license-faqs.html).
- 2021-10 — Workload-based pricing, previously piloted only with Splunk’s largest accounts, opens to all Splunk Cloud Platform customers at .conf21 (Splunk blog).
- 2022-05 — Observability Cloud launches as a unified brand over SignalFx and VictorOps; workload pricing becomes Splunk Cloud Platform’s default model (TechTarget reporting; own Wayback capture showing the prior single “$65/host” headline).
- 2023-09-21 — Cisco announces an all-cash agreement to acquire Splunk at $157/share (~$28B), its largest acquisition ever — a 923-point, 502-comment Hacker News thread and broad press coverage (Bloomberg, The Register).
- 2023-11-01 — Splunk reduces headcount by roughly 7% ahead of the Cisco deal’s regulatory close (Bloomberg; 167-point Hacker News thread).
- 2024-03-18 — Cisco completes the acquisition in about six months with no antitrust delay; Splunk becomes a Cisco business unit (Cisco newsroom; Bloomberg).
- 2026-09 (current) — Observability Cloud’s pricing page shows three published tiers (Infrastructure $15, App & Infra $60, End-to-End $75, all per host/mo) plus a 0.5x weighted-ingest discount for eligible Cisco telemetry on Splunk Platform/Enterprise — both changes postdate the last legible 2022 Wayback capture but their exact transition date is unverified.
The Cisco acquisition in detail
Cisco’s $28 billion purchase of Splunk — announced 2023-09-21 and closed 2024-03-18 — is the single largest event in Splunk’s pricing history, even though it did not immediately change a single published rate. Its effects show up indirectly: Splunk’s site now carries “a Cisco company” branding throughout its pricing pages, Splunk’s workforce was cut roughly 7% ahead of close (Bloomberg), and by our current live capture, Splunk Platform and Enterprise now advertise a 0.5x weighted ingest rate specifically for customers who also send “eligible Cisco telemetry” — a direct pricing incentive to combine Splunk ingestion with Cisco’s networking estate that did not exist pre-acquisition. Cisco’s own FY2024-FY2025 filings report Splunk contributing $4.3B of Cisco’s $29.6B total ARR (up 22% YoY) and turning EPS-accretive a quarter earlier than planned, meaning the pricing integration is already a measurable part of Cisco’s disclosed unit economics — a useful case study in our FinOps for AI cost management coverage of how M&A reshapes usage-metered pricing.
What’s unique : a customer-selectable meter wrapped in a sales-only quote
1. The metering mechanic is customer-selectable; the rate almost never is. Splunk is one of the few pure-usage platforms where a customer actively chooses between four different billing dimensions — activity-based, workload, ingest, or entity — per product line, rather than the vendor picking one meter for everyone. But having a choice of mechanic doesn’t mean having a visible price: almost none of those mechanics show a public rate outside of Observability Cloud and AppDynamics, so the “flexibility” is really a flexible quoting conversation, not flexible self-serve pricing.
2. Cloud Flex reallocates committed spend across the whole portfolio. Most usage-metered vendors force a separate procurement cycle for every new product a customer wants to add. Cloud Flex lets an existing Splunk customer move already-committed dollars between Platform, Security, and Observability products without restarting procurement — a meaningful reduction in expansion friction for large accounts already locked into an annual commit.
3. A Cisco-telemetry weighted-ingest discount, created by the acquisition itself. Splunk now advertises a 0.5x weighted ingest rate for Splunk Cloud Platform and Enterprise customers who also route “eligible Cisco telemetry” into the platform. This is a pricing mechanic that literally did not exist before the ~$28B Cisco acquisition closed in March 2024 — a rare example of an M&A deal directly rewriting a vendor’s usage-based rate card to reward cross-portfolio adoption, rather than just changing the logo in the footer.
Strengths & weaknesses
| Strengths | Weaknesses |
|---|---|
| Four selectable metering mechanics (activity/workload/ingest/entity) fit different usage shapes | Nearly the entire core revenue line (Platform, Enterprise Security, SOAR, ITSI) hides pricing behind a lead-gated quote form |
| Cloud Flex removes re-procurement friction when reallocating spend across products | Legacy per-GB ingest pricing carries a decade-long “surprise renewal” bill-shock reputation |
| Free self-serve entry points on Observability Cloud, AppDynamics, and SOAR trials | Four concurrent pricing mechanics create genuine buyer confusion about which model applies to them |
| Backed by Cisco’s balance sheet and network-telemetry integration reach post-acquisition | Cisco integration has so far added a discount lever, not a simplified or unified pricing structure across the combined portfolio |
Billing UX : quote-request forms and a workload sizing calculator
- Contact a Splunk Pricing Expert form (talk-to-sales/pricing.html) — the single lead-capture form (name, company, country, question type) that gates every price for Splunk Platform, Enterprise Security, SOAR, and IT Service Intelligence; embedded inline on both the main pricing page and the pricing-models page.
- Workload pricing calculator (pricing-models.html) — lets a prospect pick a Workload Type (Compliance Storage, Data Lake, Basic Reporting, Ad-hoc Investigation, Continuous Monitoring, or a custom addition), enter expected daily GB ingested via a slider, and see an estimated Splunk Virtual Compute (SVC) sizing before routing to “Have Sales Provide Me an Estimate.”
- Cloud Flex — lets customers reallocate committed spend across the entire Splunk portfolio (Platform, Security, Observability) without restarting procurement.
- Per-tier feature checkmark matrices — side-by-side comparison grids on both the Observability Cloud (Infrastructure / App & Infra / End-to-End) and AppDynamics (Infrastructure / Premium / Enterprise) pricing tables.
- “Start for free” / “Free Trial” buttons — a self-serve entry point offered alongside “Contact Sales” on Observability Cloud and its individual modules (Infrastructure Monitoring, APM, RUM, Synthetic Monitoring), a rare non-quote-gated path for an otherwise sales-led company.
Strategic wins : why specific pricing decisions worked
1. Publishing Observability Cloud and AppDynamics rates while keeping the core platform quote-gated
Splunk’s newer cloud-native product lines compete directly with Datadog, New Relic, and Dynatrace — categories where buyers now expect a self-serve rate card before they’ll even take a sales call. Splunk met that expectation for Observability Cloud and AppDynamics specifically, while leaving its legacy SIEM/log-management business (which sells almost exclusively to large enterprises already used to negotiated procurement) fully sales-led. That’s a defensible segmentation of self-serve vs. sales-led motions rather than a blanket policy, and it lets Splunk compete on transparency exactly where the market demands it.
2. Introducing workload pricing as a real alternative to raw ingest
Workload pricing ties cost to the compute Splunk actually spends serving searches and dashboards, not to the raw volume of data a customer chooses to log. That decouples “log more for better visibility” from “pay proportionally more no matter how that data gets used” — a meaningful improvement in choosing the right usage metric for a data platform whose customers were actively discouraged from logging enough data to be useful under the old ingest-only model.
3. Turning the Cisco acquisition into an actual pricing lever
Rather than treating the ~$28B Cisco acquisition purely as a branding and go-to-market event, Splunk built a concrete commercial incentive into the rate card: a 0.5x weighted ingest discount for customers who also send Cisco network telemetry. That gives Cisco’s existing customer base a real financial reason to route more data through Splunk, converting the M&A thesis into something the pricing page itself can sell.
Areas to improve : specific gaps with proposed fixes
1. Quote-gating on roughly 80% of the product line frustrates evaluators
Splunk Platform, Enterprise Security, SOAR, and IT Service Intelligence — the products most buyers actually search for — show no price at all, only a “Get a quote” form. Proposed fix: publish indicative starting-range figures the way Observability Cloud already does (e.g., “Ingest pricing starts around $X/GB/day for committed volumes”), even if the final number still requires a sales conversation for large deals.
2. Four overlapping metering mechanics confuse first-time buyers
Activity-based, workload, ingest, and entity pricing all coexist, and Splunk’s own FAQ pages devote significant space to explaining which one a given customer should pick. Proposed fix: ship a single guided decision tool (Splunk already has separate sizing calculators for workload and pricing estimates) that recommends one mechanic based on a customer’s answers, rather than making the buyer read four separate explainer pages first.
3. The “surprise renewal” cost reputation persists years after workload pricing launched
Despite workload pricing existing since 2021, community sentiment (G2, TrustRadius, and Hacker News threads) still centers on unpredictable ingest-driven bill growth, suggesting the newer model hasn’t fully displaced the legacy perception — or the legacy contracts. Proposed fix: publish transparent, self-serve volume-discount bands for ingest pricing (as Datadog and New Relic have done for their own per-host and per-GB meters), directly addressing the bill-shock narrative and giving finance teams a chargeback-ready cost model instead of leaving it to third-party cost calculators to estimate.
Monetization stack & signals : how Splunk builds & buys its revenue engine
Buys 4 Builds 0 7 signal roles
Splunk's revenue back-office — deal desk, CRM, renewals — now runs on Cisco's shared stack, with no quoting or billing tool named anywhere. Watch the AI Foundations hire below: the meter behind Splunk's AI charges is still an open build/adapt/buy call.
-
“Maintain accurate account, license, contract, and entitlement data in Salesforce and relevant dashboards (e.g., Tableau).”
-
“Maintain accurate account, license, contract, and entitlement data in Salesforce and relevant dashboards (e.g., Tableau).”
-
“Splunk is looking for a Marketing Operations Manager – Marketo Engineering who will be responsible for building, maintaining, and optimizing our Marketo instance.”
-
“Automate recurring marketing processes using tools such as Openprise to improve efficiency and consistency.”
-
“Partner with Product Marketing and Sales to package these foundational capabilities for external customers, including consumption based pricing and metering, positioning against general purpose model providers, model documentation, and developer onboarding.”
-
A France/EMEA renewals seat still sells Term, Cloud and Perpetual license renewals under the Splunk brand, running entitlement and contract data through Salesforce rather than a Splunk-specific renewals tool.
“Managing and selling Term, Cloud, and Perpetual license renewals of Splunk's industry-leading software... Maintain accurate account, license, contract, and entitlement data in Salesforce and relevant dashboards (e.g., Tableau).”
-
Two open Splunk finance seats own gross margin down to product-level profitability and COGS models for new product introductions — margin discipline behind the ingest/workload meter, with no FinOps vendor named in either JD.
“Develop financial models and operational metrics to improve visibility into cloud consumption, infrastructure utilization, unit economics, and product-level profitability.”
-
Two open Splunk finance seats own gross margin down to product-level profitability and COGS models for new product introductions — margin discipline behind the ingest/workload meter, with no FinOps vendor named in either JD.
“Develop financial models and operational metrics to improve visibility into cloud consumption, infrastructure utilization, unit economics, and product-level profitability.”
-
A dedicated Sales Strategy & Transformation track is pushing Splunk toward outcome-based selling — tying price to measured business impact — the value-metric mirror to its per-GB ingest and per-SVC workload meters.
“Lead our continued evolution toward outcome-based selling models, partnering with customers to align pricing and value delivery with measurable business impact.”
-
A dedicated Sales Strategy & Transformation track is pushing Splunk toward outcome-based selling — tying price to measured business impact — the value-metric mirror to its per-GB ingest and per-SVC workload meters.
“Lead our continued evolution toward outcome-based selling models, partnering with customers to align pricing and value delivery with measurable business impact.”
-
One AI Foundations PM owns both the unit economics of inference (cost per token, GPU utilization) and 'consumption based pricing and metering' for Splunk's own models — but the JD frames build / adapt / buy as a decision still to be made, not a shipped in-house meter.
“Make and defend the build / adapt / buy decisions behind each capability... owning the unit economics of inference (cost per token, GPU utilization, cloud margin)... including consumption based pricing and metering.”
-
Splunk's deal desk is staffed inside Cisco's shared 'Deal Strategy & Execution' org, articulating 'Cisco and Splunk buying programs' as one motion — and the JD has deal managers drafting Order Documents by hand, naming no CPQ or quoting system.
“You will be an expert on Cisco's buying programs, draft Order Documents and support sales in customer facing negotiations... Manage custom agreements from end to end, negotiate directly with customers, facilitate internal back-end partners, draft key business language and adhere to internal systems and processes.”
Signals reviewed · derived from public job posts, press & filings
Job postings fill and close over time — once a posting is filled we keep it as a dated citation (the quoted evidence remains); use View open roles for current listings.
Key takeaways
- A published rate card and a sales-led motion can coexist inside one company. Splunk shows that a vendor doesn’t have to choose one pricing-transparency posture company-wide — Observability Cloud and AppDynamics prove self-serve rates work for cloud-native buyers, while the legacy SIEM business stays fully quoted for its enterprise-only audience.
- Letting customers pick the metering mechanic is not the same as pricing transparency. Splunk’s four selectable billing dimensions (activity/workload/ingest/entity) look like flexibility, but almost none of the actual rates are published — mechanic choice and price visibility are two separate axes, and buyers need both to actually compare cost.
- Legacy usage meters can outlive the product decisions that created them. Splunk introduced workload pricing specifically to fix ingest-driven cost unpredictability in 2021, yet the “Splunk is expensive at scale” reputation persists in 2026 community discussion — a reminder that a better metering option doesn’t retire a bad reputation on its own.
- M&A can become a pricing mechanic, not just a branding update. Cisco’s acquisition of Splunk produced a concrete rate-card change (the Cisco-telemetry ingest discount), showing that post-acquisition integration teams should look for real commercial levers, not just logo and messaging updates.
- A single well-documented Hacker News thread can outlive a company’s independence. The 313-point post about replacing Splunk with a custom script (2023) still surfaces in searches about Splunk’s cost years later — pricing reputation compounds in public developer communities in ways a vendor’s own marketing can’t easily counter.
UBP implications
- Selectable metering mechanics need a default recommendation, or they become a tax on buyer attention. When a platform offers multiple usage-based models (as Splunk does with four), the absence of a clear default pushes evaluation cost onto the customer — usage-based pricing strategy should pair mechanic flexibility with a strong recommended path, not leave every buyer to reverse-engineer which meter fits them.
- A published entry-level rate card can de-risk a much larger sales-led relationship. Splunk’s Observability Cloud and AppDynamics rate cards don’t replace enterprise sales — they give prospects a credible anchor price before they ever talk to a rep, which is a valid middle path between “fully public SaaS pricing” and “fully sales-only enterprise pricing.”
- Usage-based pricing reputations are sticky across ownership changes. Splunk’s ingest-based “surprise renewal” story predates the Cisco acquisition by years and has not been resolved by Cisco’s ownership or by workload pricing’s 2021 launch — a signal that fixing a usage-metered pricing model’s reputation requires visible, public pricing changes, not just an internal metering-mechanic swap.
Sources
- Splunk Pricing (accessed 2026-09-01)
- Splunk Pricing Calculator (accessed 2026-09-01)
- Splunk Pricing FAQs (accessed 2026-09-01)
- Splunk Observability Pricing FAQ (accessed 2026-09-01)
- Splunk Platform Pricing FAQ (accessed 2026-09-01)
- Splunk Security Pricing FAQ (accessed 2026-09-01)
- Splunk Ingest Pricing (accessed 2026-09-01)
- Splunk Observability Pricing (accessed 2026-09-01)
- Splunk Pricing Models (accessed 2026-09-01)
- Splunk Workload Pricing (accessed 2026-09-01)
- Splunk Perpetual License FAQ (accessed 2026-09-01)
- Splunk Blog (accessed 2026-09-01)
Bottom line
Splunk is a case study in partial pricing transparency: a company that publishes real, comparable per-host rates for its newer Observability Cloud and AppDynamics lines while keeping the far larger, decades-old SIEM and log-management business entirely behind a sales quote — and that split survived a $28 billion acquisition by Cisco without being resolved either way.
Want to compare Splunk against other observability and security pricing? Browse the pricing blueprint.
Pricing timeline : Major events on a vertical axis
Each milestone below corresponds to a public pricing change, product launch, or material adjustment. Major events use a filled marker; minor adjustments use a faded one.
Observability Cloud unbundled into three published tiers plus a Cisco-telemetry discount
As captured live, Splunk Observability Cloud now publishes three self-serve tiers — Infrastructure $15, App & Infra $60, End-to-End $75 (all per host/mo, billed annually) — replacing the single 'starts at $65/host' headline seen in 2022, alongside standalone modules and a new 0.5x weighted-ingest discount for eligible Cisco telemetry on Splunk Platform. The exact date this unbundling occurred between 2022 and 2026 is not evidenced by a captured snapshot.
Cisco completes the Splunk acquisition
Cisco closes its ~$28 billion purchase of Splunk in about six months with no antitrust delay; Splunk's site and pricing pages are subsequently rebranded 'a Cisco company.' Source: Cisco newsroom; Bloomberg; The Register.
Splunk cuts 7% of workforce ahead of Cisco close
Splunk reduces headcount by roughly 7% while the Cisco acquisition is pending regulatory close, reported by Bloomberg and discussed in a 167-point Hacker News thread.
Cisco agrees to acquire Splunk for ~$28 billion
Cisco announces an all-cash agreement to acquire Splunk at $157/share (~$28B equity value), its largest acquisition ever. The announcement generated a 923-point, 502-comment Hacker News thread and wide press coverage. Source: Splunk/Cisco joint announcement; Bloomberg.
Observability Cloud launches; workload pricing becomes the cloud default
Splunk unifies SignalFx and VictorOps under the Splunk Observability Cloud brand and makes workload-based pricing the default (not just optional) model for all Splunk Cloud Platform customers. A Wayback capture from this period shows the entire Observability Cloud line still sold as one bundle: 'SPLUNK OBSERVABILITY CLOUD STARTS AT $65 per host/month, billed annually,' with every other product line ('Contact us for pricing details'). Source: TechTarget reporting; own Wayback capture.
Workload pricing opened to all Splunk Cloud customers
At .conf21, Splunk opens workload-based pricing (previously piloted with only its largest accounts) to all Splunk Cloud Platform customers, pricing compute/search activity via Splunk Virtual Compute (SVC) units instead of raw ingest volume. Source: Splunk blog, 'Workload Pricing: More Value from Splunk Cloud.'
Perpetual licenses discontinued; term-only pricing
Splunk stops selling perpetual software licenses globally for all new product and service sales, moving every new deal to Annual (Term) licensing bundled with support. Source: splunk.com perpetual-license-faqs.html.
SignalFx acquisition lays the Observability Cloud foundation
Splunk acquires SignalFx, adding real-time cloud-native observability (metrics, traces) that is later rebranded Splunk Observability Cloud. Source: splunk.com acquisitions page.
VictorOps acquisition seeds the on-call product line
Splunk agrees to acquire VictorOps for $120 million; the product is later rebranded Splunk On-Call and remains, years later, the only SecOps-adjacent Splunk product with a simple published per-seat rate ($5/user/mo). Source: Splunk investor news release.
- · Splunk's 2018 acquisition of VictorOps for $120 million became Splunk On-Call, the only Splunk security-operations product still priced simply — $5 per user per month — while its parent SIEM and SOAR products remain entirely quote-gated.
- · Splunk stopped selling perpetual software licenses worldwide on November 1, 2019, permanently moving every new deal to term-based licensing.
- · A 313-point Hacker News post in 2023 showed a solo founder replacing Splunk with a 1,200-line Python script, citing thousands of dollars a year in savings — a recurring theme in Splunk's community reception.
Questions & answers
- How much does Splunk cost?
- Most of Splunk's core products (Platform, Enterprise Security, SOAR, IT Service Intelligence) are entirely sales-quoted with no published price. Only Observability Cloud ($15-$75/host/mo), AppDynamics ($6/vCPU-$50/host/mo), and On-Call ($5/user/mo) publish self-serve starting rates.
- What's the difference between Splunk's ingest, workload, activity-based, and entity pricing models?
- Ingest bills per GB of data indexed per day; workload bills on compute/storage consumed by search (measured in Splunk Virtual Compute units or vCPUs); activity-based combines an ingest and search-activity meter; entity bills per monitored host, container, or device. Customers pick which mechanic applies per product, but the actual rate for each is almost always sales-quoted.
- Is Splunk still an independent company?
- No. Cisco completed its approximately $28 billion acquisition of Splunk on March 18, 2024, and Splunk now operates as a Cisco business unit, branded 'a Cisco company' across its site and pricing pages.
- Does Splunk charge extra for its AI features?
- No published add-on fee is visible: 'Artificial Intelligence' appears as a bundled checkmark feature in both Enterprise Security Essentials and Premier editions, and Splunk's AI Assistant for SPL ships inside the core Observability/Search experience rather than as a separately metered line item.
- Why is Splunk considered expensive?
- Splunk's legacy ingest-based licensing bills per gigabyte of data indexed per day, and a well-documented string of community posts — including a 313-point Hacker News thread about replacing Splunk with a custom script — describes teams building alternatives specifically to avoid Splunk's ingest costs at scale.
- What is Cloud Flex?
- Cloud Flex lets a Splunk customer reallocate committed spend across its entire portfolio (Platform, Security, Observability) without renegotiating a new contract or restarting procurement.