I used Splunk Cloud Platform for fraud detection. The first thing is fraud detection, and the second thing is understanding data better because of the data visualization that it has. The display that it has compared to a simple type of visualization is much clearer compared to any kind of thing you might notice on a super dense Wireshark.
Data Security Intern at a manufacturing company with 10,001+ employees
Advanced alerts and clear visuals have improved fraud detection and data-driven decisions
Pros and Cons
- "Data Visualization and IT Alerting and Incident Management are the main valuable features, primarily to get a better idea of what's going on."
- "To be honest, I don't think it's beginner-friendly. It takes time and multiple meetings to actually understand how to create different types of alerts or how to search for them."
What is our primary use case?
What is most valuable?
Data Visualization and IT Alerting and Incident Management are the main valuable features, primarily to get a better idea of what's going on.
When you do data reporting using Splunk Cloud Platform, because you have everything in front of you and it's so detailed and easy to read once you have the data. Another thing that makes it clear is because of the amount of evidence you have in front of you, the data is a lot more valuable. It's less of a human claim and more of evidence presented in front of you when you're trying to make any kind of claim on a certain thing going on.
I really do like about Splunk Cloud Platform the real-time alert where you can search for anything and the data is still stored there because at the end of the day, we are finally in a generation of cloud where everything is stored on a cloud platform to the point that you can search anything, as long as you do it in the appropriate way, you will find the results. It's in a good visual status with good visibility. I appreciate this feature.
What needs improvement?
To be honest, I don't think it's beginner-friendly. It takes time and multiple meetings to actually understand how to create different types of alerts or how to search for them. It's quite similar to how you might search on SQL, but that's asking another set of skills to have. I know there are tutorials on the website, but I feel if they rolled out more free courses on such things that provide a link to a free course for beginner training, I feel people would be interested in it.
For how long have I used the solution?
I ended up getting access around three to four months back. I was part of a team that was using it, so we got on a call together while I was observing them and using it while giving my input for a project.
Buyer's Guide
Splunk Cloud Platform
August 2026
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.
What do I think about the stability of the solution?
I haven't really faced much of it, but my usage was pretty less intensive, so I can't really talk about it for everyone. From my perspective, because of my light amount of research and light usage of it, I would say it's been pretty good. I haven't experienced any stability issues.
What do I think about the scalability of the solution?
Splunk Cloud Platform is a good tool, but it's not the easiest to transfer between different teams because there's a lot of training involved in it. While I do the tool and I do feel it's really useful, if you ever notice in this current industry, people are wanting employees to learn Splunk Cloud Platform, or at least they want applicants who apply for a certain role to have known Splunk Cloud Platform because of not only how new it is or how recent it is after the cloud integration, but also just that it takes time to learn and takes time to be efficient at it.
How are customer service and support?
When you work in a corporation, you have people dedicated just for that.
Which solution did I use previously and why did I switch?
I've used Splunk Cloud Platform very briefly, not too much. I use ServiceNow, Confluence for documentation, and Keyfactor for generating certificates.
How was the initial setup?
It's kind of hard for me to say because I came from a corporation where Splunk Cloud Platform was already a part of the user group where I got access to it, so I didn't have to do any of that.
Which other solutions did I evaluate?
Any IT person would rather use the command prompt. Using a simple command prompt and trying to see based on the elevated access they have, you can always check what's going on. Wireshark itself is a really good tool and a really good alternative to have any kind of packet capture and read through the data to understand what's going on.
Splunk Cloud Platform is different because it offers real-time alert. Wireshark is something that you have to let things be and then later catch and see, while Splunk Cloud Platform updates on its own. It has a lot better visuals overall.
What other advice do I have?
Regarding whether Splunk Cloud Platform's ingest and visualization features have helped improve data reporting and the overall alerting mechanisms, I haven't had the chance to use it for myself, but from the time when I was researching them for the project that I was working on, it seemed to be really effective in at least the fraud department of the team to understand any type of price alerts when something is going on.
Regarding how easy or difficult it was for me to learn how to use it, I would say on a scale of easy with one being the easiest and ten being the hardest, I would say it was around a four or five. I've used other tools before, and I've used other things such as Wireshark and some others a lot before, so I had a much better grasp than a lot of beginners might have. Recently in a meeting where we were trying to teach a beginner about this, the main person who uses it had to go through multiple rounds of meetings to show them how to use it. While watching that, I realized the gap in knowledge between someone who's in IT for years versus someone who's trying to be more hands-on but is unfamiliar with the tool.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 9, 2026
Flag as inappropriateLead Engineer at a retailer with 10,001+ employees
Platform has streamlined fraud investigations and has improved data operations efficiency
Pros and Cons
- "Splunk Cloud Platform has positively impacted my organization by offering a one-stop shop to get a lot of things done."
What is our primary use case?
My main use case for Splunk Cloud Platform is data operations. We ingest all of our feeds into the platform and normalize the data for Enterprise Security and notable use as a specific example of how I use Splunk Cloud Platform for data operations. I think it's a unique case because we are doing retail fraud instead of the normal security authentication and governance.
What is most valuable?
The best features Splunk Cloud Platform offers include GUI access for a lot of operational commands. For example, we're able to restart our search heads, create indexes, and HEC tokens on the front end. Having GUI access for those operational commands helps my team day-to-day as it saves time and reduces errors.
Splunk Cloud Platform has positively impacted my organization by offering a one-stop shop to get a lot of things done. In one place now, we're able to triage incidents much faster within the platform and create our apps to upload easily, which has had a significant impact on my workflow and team.
What needs improvement?
I think Splunk Cloud Platform could be improved by having a little more access to the backend for admins.
For how long have I used the solution?
I have been using Splunk Cloud Platform for three and a half years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
The scalability of Splunk Cloud Platform is pretty easy and pretty good as we have a lot of data. The platform's ability to scale aligns pretty well with my organization's demand fluctuations, and we haven't had major issues regarding scalability.
How are customer service and support?
The customer support for Splunk Cloud Platform is helpful. My experience with Splunk Cloud Platform's app ecosystem is that it's pretty easy to manage updates within this ecosystem. If we are having issues, our Splunk support is pretty quick to hop on a call or get an email to help us when we create a ticket.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; I've only used Splunk.
What was our ROI?
I have seen a return on investment as we have had money saved with investigations and we are able to keep the team to a minimum with the support of the platform.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, I did not evaluate other options as I was not a part of that decision, but previously, I did on-prem.
What other advice do I have?
My advice for others looking into using Splunk Cloud Platform is to create and document protocols for your data before launching. The subscription model impacts my financial planning for data platform investments by working pretty well, and we're currently working on reducing our licensing by working on our feeds before they're indexed. I rate this product an 8.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateBuyer's Guide
Splunk Cloud Platform
August 2026
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.
Associate Manager Enterprise Service Management at a manufacturing company with 10,001+ employees
Proactive monitoring has reduced downtime and now improves performance across our environments
Pros and Cons
- "Splunk Cloud Platform has positively impacted my organization by allowing us to be more proactive with our monitoring."
- "However, I think its accuracy and reliability of output are not very good right now."
What is our primary use case?
My main use case for Splunk Cloud Platform is performance monitoring. For performance monitoring, I get the data in from our workloads into the platform and then write searches in order to set up alerts on certain thresholds for that data. That is the main way I use Splunk Cloud Platform.
What is most valuable?
In my opinion, the best features Splunk Cloud Platform offers are the flexibility to complete virtually any use case. That flexibility has made a difference for my team by allowing us to help other IT teams with increasing efficiency. Splunk Cloud Platform has positively impacted my organization by allowing us to be more proactive with our monitoring. Being more proactive has changed things for my team by allowing us to decrease downtime of business applications.
What needs improvement?
Splunk Cloud Platform could be improved by integrating AI agents into the platform since they should be a native feature, similar to how they are a feature in observability.
For how long have I used the solution?
I have been using Splunk Cloud Platform for over five years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Splunk Cloud Platform's scalability is pretty good.
How are customer service and support?
Customer support for Splunk Cloud Platform can be improved.
Which solution did I use previously and why did I switch?
We previously used a different platform before Splunk Cloud Platform, but I do not want to say the name, and the reason for the switch was more flexibility.
What was our ROI?
I have seen a return on investment with Splunk Cloud Platform, and there is definitely efficiency that was created with time saved, though I do not have a hard number for you.
What other advice do I have?
Overall, Splunk Cloud Platform is very good, but there are some areas of improvement that are still needed, which is why I would rate it an eight out of ten.
Regarding Splunk Cloud Platform's AI capabilities, I do not think I have any issues with its governance and security. However, I think its accuracy and reliability of output are not very good right now. I think AI features need a lot of help in Splunk Cloud Platform.
My experience with Splunk Cloud Platform's app ecosystem is that it is not too difficult to manage updates, but the biggest pain point is with vendors making apps compatible with new versions of Splunk Cloud Platform.
Splunk Cloud Platform does a good job of letting me see what is happening across all my different environments such as my cloud systems, my on-premises systems, and my hybrid setups. The platform's ability to scale aligns well with my organization's demand fluctuations, and it does a good job.
My advice to others looking into using Splunk Cloud Platform is to learn the platform first.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateMonitoring has improved business insights while search guardrails still need refinement
Pros and Cons
- "Splunk Cloud Platform offers exceptional features including quick upgrades, as Splunk Cloud receives the first upgrade for any GA release with rapid support."
- "More guardrails can be implemented, and workload management can be improved in Splunk Cloud Platform."
What is our primary use case?
Splunk Cloud Platform serves as our primary observability solution, focusing on monitoring logs, metrics, and traces for our systems.
We primarily use Splunk Cloud Platform for log monitoring by setting up feature dashboards in my day-to-day work.
Dashboards are used to monitor business API and business-related metrics from logs, which enhances our workflow.
What is most valuable?
Splunk Cloud Platform offers exceptional features including quick upgrades, as Splunk Cloud receives the first upgrade for any GA release with rapid support.
Their team manages indexers and search head upgrades, allowing us to focus on bringing data and creating metrics from it and monitoring that output.
Splunk is very helpful in troubleshooting with its SPL, and the AI assistant significantly helps in troubleshooting issues.
Splunk MCP allows quick turnaround with integration into platforms.
The platform's ability to validate application logs, correlate microservices using trace IDs, and enhance security with threat detection greatly impacts our organization.
What needs improvement?
More guardrails can be implemented, and workload management can be improved in Splunk Cloud Platform.
Ad hoc searches are still being executed with index equal to star, which reveals opportunities for improvement, and there must be a way to enforce this.
Splunk should enforce predicates for users, requiring index equal to an index name instead of allowing index equal to star. This will improve compute utilization and help maintain stability in Splunk Cloud Platform.
For how long have I used the solution?
I have been working in my current field for the last six years.
We have been using Splunk Cloud Platform for the last six years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Scalability is good, as we work with our TAM to ensure our environment is right-sized, preventing any issues or load impacts.
How are customer service and support?
Customer support is very good, and we have a dedicated TAM as well as a dedicated engineer to assist us.
Which solution did I use previously and why did I switch?
We did not use any other solution previously. We were using Splunk Enterprise before migrating to Splunk Cloud Platform, so we have always been Splunk customers.
What was our ROI?
We are utilizing federated search with S3 in our organization, redirecting 20 terabytes of low-value logs into S3.
Using federated search heavily allows us to save significantly on costs, which is a very important metric for us.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing has been very good, as we did not face any issues.
We're receiving all the needed support from the start.
What other advice do I have?
Teams should evaluate their business use case and compare whether that use case can be effectively implemented with Splunk Cloud Platform.
It's important to determine the retention period for logs and to identify high-value logs versus low-value logs; high-value logs can go directly into Splunk Cloud Platform while low-value logs can be redirected to S3, utilizing federated search with S3 for low-value log management.
I would rate this solution a 7 overall.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriateSoftware Engineer at a comms service provider with 10,001+ employees
Logging platform has improved dashboard visibility and simplifies troubleshooting for dev teams
Pros and Cons
- "Splunk Cloud Platform has reduced our errors and has helped us troubleshoot significantly with the alerts that we have set up with the logging that it offers."
What is our primary use case?
My main use case for Splunk Cloud Platform is building dashboards and alerts to help aid our Dev team and video team troubleshoot.
For our acquisitions team, I set up an alert to track the provider issues that cause the errors. From them, it leads to how many times a provider goes down, and it sends it to a web hook.
We mainly use Splunk Cloud Platform to troubleshoot through our logs and find areas of weakness or help us determine where something has gone wrong with our microservices through AWS.
What is most valuable?
The best features Splunk Cloud Platform offers are that it is easy to learn and the accessibility to the different features as well as step-by-step processes.
What makes it easy to learn is the querying style in Splunk, which is straightforward and simple in syntax.
Splunk Cloud Platform positively impacts our organization by allowing us to go through our logs more simply and filter out different material that we are looking at, as well as collect logs in one place for us to search through and build comprehensive dashboards to show leadership and dev.
Splunk Cloud Platform has reduced our errors and has helped us troubleshoot significantly with the alerts that we have set up with the logging that it offers. We have been able to trace issues faster and get more engineers to locate the errors, so visibility has been excellent.
What needs improvement?
I have not had too much interaction with Splunk Cloud Platform, with only three months of experience using it. I have not come across any flaws yet, but I am sure as always, things will come up.
For how long have I used the solution?
I have been using Splunk Cloud Platform for three months.
What do I think about the stability of the solution?
Splunk Cloud Platform has been stable for the past three months.
What other advice do I have?
I have not used Splunk Cloud Platform's AI capabilities.
I have not used Splunk Cloud Platform's zero-setup feature for AI models.
I do not have experience managing updates within Splunk Cloud Platform's app ecosystem.
The solution's visibility into multiple environments, such as cloud, on-premises, and hybrid, is very useful, but I am very siloed, so I do not really work with anything else. I would rate this product an 8.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 15, 2026
Flag as inappropriateTeam Lead Soc at a tech services company with 51-200 employees
Advanced ai-driven threat hunting has improved detection speed and streamlined investigations
Pros and Cons
- "Splunk Cloud Platform is a data analysis tool that works on big data and unstructured data, and what I appreciated about it is that Splunk data processing is very good, and when I performed search and threat hunting on Splunk, I was very satisfied."
- "There is always room for improvement. Splunk can improve because it is a very expensive product."
What is our primary use case?
I was a consumer using Splunk Cloud Platform at that time. I have been familiar with Splunk Cloud Platform. I was a user of Splunk Cloud Platform and a customer also.
What is most valuable?
Splunk Cloud Platform is a data analysis tool that works on big data and unstructured data. What I appreciated about it is that Splunk data processing is very good. When I performed search and threat hunting on Splunk, I was very satisfied.
Splunk Cloud Platform supports AI automation and can empower analysts to use AI assistance and agentic playbooks to accelerate threat detection, investigation, and mean time to detect or mean time to respond.
Since Splunk already offers me an embedded AI solution, why would I go to any other AI solution? Splunk is helping us in the new era of AI.
What needs improvement?
There is always room for improvement. Splunk can improve because it is a very expensive product. Because of the cost, we do not have as many skilled resources for Splunk, which makes it very difficult to find a compatible resource to help us troubleshoot.
For how long have I used the solution?
I have worked with Splunk Cloud Platform for around 10 to 11 months.
What do I think about the stability of the solution?
Splunk Cloud Platform is a very vendor-diverse product. You can integrate almost anything around the infrastructure. It totally supports integration.
What do I think about the scalability of the solution?
Splunk Cloud Platform is currently the best option in the market if you have the capacity to pay what Splunk requires. If you are tight on budget, you can consider other options. With respect to price, Splunk is the best solution, but it is expensive.
When comparing it with LogRhythm, LogRhythm is for small organizations, but Splunk has financial considerations. Splunk has more advantages than LogRhythm when comparing from a financial perspective.
How are customer service and support?
Splunk Cloud Platform is currently owned by Cisco, and Cisco has very great support in my region.
Which solution did I use previously and why did I switch?
I was only using Splunk Cloud Platform.
How was the initial setup?
If you are planning to deploy Splunk Cloud Platform, there is a whole lot of architecture planning involved. You need to plan accordingly as per your infrastructure needs.
What about the implementation team?
I was on the technical side, and the finances were managed by the governance team. I cannot answer questions regarding the subscription model and pricing structure.
What was our ROI?
Splunk Cloud Platform is a Gartner leading product. Splunk is superior in comparison with any other SIEM.
What's my experience with pricing, setup cost, and licensing?
Splunk Cloud Platform is a Gartner leading product. Splunk is superior in comparison with any other SIEM.
Which other solutions did I evaluate?
Splunk Cloud Platform should be improved in certain aspects. In comparison with QRadar, QRadar has dedicated log sources, but Splunk does not have dedicated log sources. We can only sort the log sources from the IPs or hostnames. Splunk can do that, or if they do not do that, it will not affect anything, but it could be beneficial for a SOC analyst to specify the data source.
What other advice do I have?
I cannot suggest additional features that could improve the rating further. I gave this review a rating of 9.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 18, 2026
Flag as inappropriateSplunk Cloud at mp
Cloud security projects have been streamlined and incident investigations gain clear visibility
Pros and Cons
- "Splunk Cloud Platform is the easiest solution we found; every time we worked with Splunk and other IBM solutions, it proved to be reliable."
- "I believe Splunk Cloud Platform can be improved as this project has helped me understand how the system works. I think Splunk Cloud Platform could be improved by making it easier for beginners to learn and use."
What is our primary use case?
I have been working in cyber security for a significant period. I have completed projects in cyber security as well as IT program management. I have hands-on experience with Splunk Cloud Platform based on my education and practical application.
My main use cases for Splunk Cloud Platform include log analysis, security monitoring, dashboard creation, and alert management during cybersecurity labs and SIEM related projects. I used it to investigate failed login attempts, monitor suspicious activities, and review security events in SOC style exercises. I also used Splunk Cloud Platform to improve understanding of incident response workflows, centralized logging, and threat detection in cloud and security environments. My experience comes from hands-on cybersecurity training, projects, and practical lab activities over the last two years
How has it helped my organization?
Splunk Cloud Platform helped improve visibility into security events and system activity during cybersecurity labs and SIEM training projects. It made log analysis and monitoring more efficient by centralizing data from different sources in one place. The dashboards, alerts, and search functionality helped identify suspicious activities more quickly and made investigations easier to manage. It also improved understanding of SOC workflows, incident response, and threat monitoring in cloud and security environments.
What is most valuable?
In my opinion, the best features Splunk Cloud Platform offers are its strong search functionality, dashboards, alerting system, investigation capabilities, and system integration features. Over the last year, I worked on several cybersecurity labs and SIEM related projects utilizing the platform.Splunk Cloud Platform helped with log analysis, security monitoring, dashboard creation, and investigation of suspicious activities. The features I found most valuable include investigation capabilities, dashboard and visual report generation, alert monitoring, centralized log management, and integration with different systems and cloud environments.Splunk Cloud Platform also had a positive impact during incident response exercises where teams worked together in blue team and red team style security scenarios to investigate and respond to simulated cyber threats.
What needs improvement?
I believe Splunk Cloud Platform can be improved as this project has helped me understand how the system works. I think Splunk Cloud Platform could be improved by making it easier for beginners to learn and use. More simple tutorials, guided examples, and beginner friendly dashboards would help new users understand the platform faster. It would also help to have easier SPL query suggestions, clearer error messages, and more built in templates for alerts and reports. Overall, Splunk Cloud Platform is very powerful for security monitoring and log analysis, but simplifying some features would make the learning experience better for new users.
For how long have I used the solution?
My main use case with Splunk Cloud Platform has been over two years.
What do I think about the stability of the solution?
Yes. From my experience in cybersecurity labs and SIEM projects, Splunk Cloud Platform was stable and reliable for log monitoring, dashboards, alerts, and security investigations.
What do I think about the scalability of the solution?
From my experience, Splunk Cloud Platform scales well and can handle logs from multiple systems and environments in one centralized platform. It supports cloud, hybrid, and on-premises environments, making it flexible for growing security and SOC operations.
How are customer service and support?
I did not directly use Splunk Cloud Platform customer service or technical support because my experience was mainly through cybersecurity training labs and educational projects.
Which solution did I use previously and why did I switch?
As part of my cybersecurity training and labs, I also had some exposure to other security and monitoring tools such as Microsoft Sentinel, Wireshark, and basic log monitoring tools. I did not fully switch from another enterprise SIEM solution, but I used Splunk Cloud Platform because it provided strong centralized logging, dashboard visualization, search functionality, and security monitoring features that were very useful for SOC style exercises and cybersecurity projects.
How was the initial setup?
From my experience in training and lab environments, the initial setup was fairly straightforward. Since it is cloud based, access and basic configuration were easier to manage compared to more complex on-premises setups.
What about the implementation team?
No however .Like to work In my case, Splunk Cloud Platform was used mainly in cybersecurity training labs and educational projects, so I did not work directly with an integrator, reseller, or consultant for deployment.
What was our ROI?
As an entry level user, I was not directly involved in ROI measurements, but Splunk Cloud Platform helped improve centralized monitoring and faster security investigations during cybersecurity labs and SOC exercises.
What's my experience with pricing, setup cost, and licensing?
As an entry level user working mainly in cybersecurity labs and training environments, I did not directly manage pricing or licensing decisions. My experience was mainly focused on using the platform for learning, security monitoring, and SIEM related projects. From my experience, the setup and cloud access were straightforward in the training environment, and the platform provided strong features for log analysis, dashboards, and security investigations.
Which other solutions did I evaluate?
Before using Splunk Cloud Platform, I also had some exposure to Microsoft Sentinel during cybersecurity labs and training. From my entry level experience, Splunk stood out because of its strong search features, dashboards, and centralized log analysis. Microsoft Sentinel worked well with Azure, while Splunk felt more flexible for security monitoring and investigations. Learning SPL queries took some time at first, but it became easier with practice.
What other advice do I have?
I would rate Splunk Cloud Platform an 8 out of 10 based on my hands-on experience in cybersecurity labs and SIEM projects. I found it very useful for log analysis, dashboards, alert monitoring, and security investigations across cloud and on-premises environments. My advice for organizations is to invest in user training, especially for SPL queries and dashboards, because once learned, Splunk becomes a very powerful tool for SOC and security operations.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 21, 2026
Flag as inappropriateCyber Security Engineer at Underdefense
Centralized monitoring has strengthened incident detection and automated alerting for our clients
Pros and Cons
- "As a certified Splunk Architect, I consider Splunk the best solution when comparing it with competitors including Elastic, Sumo Logic, Datadog, and Microsoft."
- "One area that has room for improvement in Splunk Cloud Platform is support."
What is our primary use case?
We use both Splunk Cloud Platform and Splunk Enterprise Security. We operate as an MSP and are also a customer for the on-premise solution. We use Splunk Cloud Platform for monitoring purposes, and we use Enterprise Security for the incident monitoring tool, which is a premium solution for both Splunk on-premise and Splunk Cloud.
What is most valuable?
The best features of Splunk Cloud Platform are that you do not have to manage anything and do not have to worry about anything. It is scalable, easy to use, and reliable.
Regarding the machine learning tools in Splunk Cloud Platform, machine learning is great, but it requires specially trained people who understand it and have already worked with machine learning, making it challenging for those who do not have that expertise.
The price of Splunk Cloud Platform is very high, but you get all the advantages when you do not overpay for that. Some customers choose cheaper vendors, but for me, it is a perfect solution with many integrations, ready-to-go rules, and dashboards. It is feature-based.
Regarding the ingestion and visualization features in Splunk Cloud Platform, any device or system that can produce logs can be ingested into Splunk. There is no problem with many different possibilities to ingest the logs, making it a really great tool. Regarding the dashboards, there are also many possibilities to create them. If you know XML, you can write directly in XML and have your own custom dashboards, or you can do it via templates. These are great features.
What needs improvement?
One area that has room for improvement in Splunk Cloud Platform is support. The support knowledge base is the primary concern for me because we had several cases working with support teams, and they could not resolve our problem.
For how long have I used the solution?
I have been using Splunk Cloud Platform for about three years.
What do I think about the stability of the solution?
I rate the stability of Splunk Cloud Platform as ten plus.
What do I think about the scalability of the solution?
I also rate the scalability of Splunk Cloud Platform as ten.
How are customer service and support?
I would rate support for Splunk Cloud Platform about six out of ten.
What other advice do I have?
When assessing the effectiveness of the search capabilities in Splunk Cloud Platform, I notice that searches are slow, which is the main disadvantage of Splunk, but the rest is really great and the most mature. The alerting mechanisms in Splunk Cloud Platform are configured as well as possible, so you can get all the information that you need. They are really great.
As a certified Splunk Architect, I consider Splunk the best solution when comparing it with competitors including Elastic, Sumo Logic, Datadog, and Microsoft.
Regarding integration with third-party tools, Splunk provides federated searches, allowing you to search data even without integrating Splunk with other features such as AWS or data lakes. This is separate pricing, but it is still possible and works really well. However, the downside is that you need to buy additional SOAR if you want to automate certain things such as blocking an IP or user or removing a user or revoking their session.
Approximately thirty to forty people work with Splunk Cloud Platform.
Splunk Cloud Platform is hosted on Splunk Cloud, though this is a tricky question since we also have on-premise Splunk installed in the cloud of client infrastructure. I am discussing only Splunk Cloud Platform here.
My advice for Splunk is that it is the best SIEM solution for me. Based on your needs, you will need a POC. It is good enough for small, medium, or enterprise clients, but you will also need to invest in people who need to learn how to write searches and work with the solution because it is not easy. If you have appropriate people, it will be worth its cost. The learning curve for Splunk Cloud Platform depends on which level you want to achieve, but the downside is that most of their really good trainings are not free, so you will need to invest in learning. I give this review an overall rating of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Apr 14, 2026
Flag as inappropriateSoftware engineer at ProminentPixel
Centralized monitoring has improved real-time insights and alerting for daily operations
Pros and Cons
- "Overall, Splunk Cloud Platform is cost-efficient for us because we are Splunk partners, and it offers better performance."
- "The initial learning curve should be more personalized for new users who just started using Splunk Cloud Platform."
What is our primary use case?
We have used Splunk Cloud Platform for the past one year. We use Splunk Cloud Platform for system monitoring and alerts, and we have personal dashboards to monitor our activities. We ingest logs and monitor all of our operations. We also use AWS along with Splunk Cloud Platform.
What is most valuable?
The powerful search capabilities using SPL are what I appreciate about Splunk Cloud Platform. The second feature we value is its real-time monitoring and alerting.
The best feature is that Splunk Cloud Platform is handled by the Splunk team itself, including installation and all related tasks. We do not have to touch anything; we simply use it for our case.
SPL search capability is one of the primary tools we use every day. We have different search queries configured for alerts, dashboards, and all related functions. It is one of the major tools we use in our daily operations.
Overall, Splunk Cloud Platform is cost-efficient for us because we are Splunk partners, and it offers better performance. It has improved our faster query execution and includes an inbuilt dashboard with better dashboard performance. We gain more meaningful insights using Splunk Cloud Platform compared to other SIEM tools.
What needs improvement?
The initial learning curve should be more personalized for new users who just started using Splunk Cloud Platform. Additionally, the documentation should be more beginner-friendly.
For how long have I used the solution?
I have been using Splunk Cloud Platform for the past one year.
What do I think about the stability of the solution?
Splunk Cloud Platform is working fine for us; it is superb.
What do I think about the scalability of the solution?
It is super scalable for us, whether you consider horizontal or vertical scaling. We are expanding in both directions, so it is highly scalable for us.
How are customer service and support?
We have escalated questions regarding Splunk Cloud to Splunk. During the upgrade, we experienced some issues with our forwarders not coming up and some issues with our search head. All of the issues were resolved. We raised support cases and our issues were solved by the Splunk team itself. It has been good for us so far.
Which solution did I use previously and why did I switch?
We directly use Splunk Cloud Platform.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
It is super smooth; Splunk Cloud Platform integrates with ServiceNow smoothly. We have experienced no problems so far in that regard.
What was our ROI?
We have seen a return on investment with Splunk Cloud Platform at 30 to 40 percent.
What's my experience with pricing, setup cost, and licensing?
We are Splunk partners, so in Splunk Cloud Platform, pricing is not an issue. It is balanced, and from a pricing perspective, it is good for us.
What other advice do I have?
If you are looking for a SIEM tool that has all the capabilities, you should definitely opt for Splunk Cloud Platform. I would rate this solution a 9 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Apr 27, 2026
Flag as inappropriateArchitect at a tech vendor with 10,001+ employees
Cloud monitoring has transformed our security insights and reduces incidents across applications
Pros and Cons
- "Splunk Cloud Platform has positively impacted my organization by reducing a lot of time, reducing a lot of incidents, and helping in mitigating issues without major downtimes."
- "Regarding Splunk Cloud Platform's stability, I would say it is kind of stable, though not completely."
What is our primary use case?
My main use case for Splunk Cloud Platform is general Splunk usage. Instead of on-prem, we are using cloud.
A quick specific example of how I'm using Splunk Cloud Platform is application monitoring, security monitoring, and enterprise security. Specifically for security monitoring, I'm looking for application-related logging, trying to understand how the applications are progressing, and monitoring the status of the servers and other infrastructure.
What is most valuable?
The best features Splunk Cloud Platform offers include ease of use, good integration, and easy scalability.
Regarding how the integration works and how the scalability has helped my team, when SVC usage is high or if there is lots of data coming in, the scalability is helping us with indexer clustering.
Splunk Cloud Platform has positively impacted my organization by reducing a lot of time, reducing a lot of incidents, and helping in mitigating issues without major downtimes.
Regarding time saved, we have caught many anomalies and issues related to applications or security data coming in through the data, which gave us proactive monitoring as well related to those.
What needs improvement?
I think Splunk Cloud Platform can be improved with some improvements on the ingestion pipelines related to edge processors, including all protocols, not only the HEC or other features. Improvements on the HEC side of things would be beneficial.
For how long have I used the solution?
I have been using Splunk Cloud Platform for almost 10 plus years.
What do I think about the stability of the solution?
Regarding Splunk Cloud Platform's stability, I would say it is kind of stable, though not completely.
What do I think about the scalability of the solution?
Splunk Cloud Platform's scalability is pretty much easy. It is auto-scaling, so we are not even bothering much about it.
How are customer service and support?
I find the customer support to be good enough.
Which solution did I use previously and why did I switch?
We previously used an on-prem solution.
What was our ROI?
I have not seen a return on investment yet; it is just the starting for us and it is completely a non-matured setup as of now on our side.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is pretty much seamless.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, we evaluated our on-prem solution.
What other advice do I have?
My advice to others looking into using Splunk Cloud Platform is to review your data. Do not bring all data; just bring in only what you need. I would rate this product an 8.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateBuyer's Guide
Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Popular Comparisons
Tableau Enterprise
Informatica PowerCenter
SAP BusinessObjects Business Intelligence
Qlik Sense
PagerDuty Operations Cloud
Salesforce Service Cloud
Splunk ITSI (IT Service Intelligence)
Panorama Necto
Apache Superset
Splunk Enterprise Platform
Google Cloud Datalab
Buyer's Guide
Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What's your experience or opinion about Spotfire vs. Tableau vs. Qlik?
- A journalist is writing a story about which Data Visualization software product to choose. Can you help him?
- What enterprise data analytics platform has the most powerful data visualization capabilities?
- When evaluating Data Visualization, what aspect do you think is the most important to look for?
- What are the best self-service and Excel-like filtering / display tools?
- What data visualization tool/s do you find to be the best?
- Why is Data Visualization important for companies?
- Which Data Visualization tools are good at collaboration and support the tracking of insight actions?
- How many users on average are licensed users of Data Visualization software in a company?

















