Splunk does not publish a price for its cloud platform or for Enterprise Security. You buy it through a quote, on one of three models: workload pricing, sized in compute units called SVCs; ingest pricing, sized in gigabytes a day; or, for the cloud platform, activity-based pricing that meters both ingest and search. The vendor's service terms say a cloud subscription is workload-based by default and ingest-based only "by exception". On top of the platform come Enterprise Security, archive storage and any searches over data held outside Splunk.
This guide explains each part of the bill using only the vendor's own pricing pages and documentation, read on 23 September 2026. We quote no third-party price estimates, because Splunk publishes no list price to check them against. What you can do is understand the units, so you can read a quote and compare it with the alternatives.
The pricing models at a glance
| Model | What you pay for | Available for (vendor's words) | Published list price |
|---|---|---|---|
| Workload | "The amount of compute and storage resources required to run search and analytics workloads", in SVCs on Cloud and vCPUs on Enterprise | Cloud Platform, Enterprise, Enterprise Security, ITSI | No |
| Ingest | "Gigabytes of data ingested into Splunk" a day | Cloud Platform, Enterprise, Enterprise Security, ITSI | No |
| Activity-based | "A dual-meter pricing model based on both ingest and search activity" | Cloud Platform | No |
| Entity | "The number of monitored hosts, containers, and protected devices" | Observability Cloud and AppDynamics, not the SIEM | Observability from $15 per host a month |
Source: the vendor's pricing models and platform pricing pages, accessed 23 September 2026.
Cloud Platform and Enterprise pricing both include unlimited users. Entity pricing and the $15 figure apply to observability, not to security, so ignore them when you price a SIEM.
How each part of the bill works
Workload pricing and SVCs
The Cloud Platform service details (updated 6 March 2026) define the unit. A Splunk Virtual Compute (SVC) is "a unit of capabilities in Splunk Cloud Platform that includes compute, memory, and I/O resources". The same page says your subscription "is workload-based and is sized for resource capacity".
Under workload pricing, ingestion is not metered. In the vendor's words, "workload-based subscriptions do not meter ingestion. You can increase ingest and/or search load and operate the service to your desired performance objective until the SVC entitlement of your subscription reaches full utilization." So the cost driver is how hard you work the platform: more searches, more correlation, more dashboards and more data all consume SVCs.
The vendor says workload pricing is best suited to "storing data that is searched and analyzed infrequently". A security team running correlation searches all day is the opposite case, so model SVC use carefully.
The official pricing calculator takes a workload type and your daily GB and returns an estimated number of SVCs. It does not return a price.
Ingest pricing
Ingest pricing charges for "gigabytes of data ingested into Splunk" a day. On the cloud platform, an ingest subscription still comes with compute: "SVCs are allocated to your subscription plan based on your ingest-based subscription (GB/day), up to the maximum of 1 SVC for every 10 GB/day." A 150 GB a day subscription therefore gets up to 15 SVCs.
The overage rule is specific. On an ingest subscription, "you can exceed your purchased daily index volume a maximum of five times in a calendar month". The pricing FAQ adds that it only charges for overages "when you consistently exceed your purchased data ingestion or storage capacity".
One discount is written into the pricing pages. Eligible Cisco telemetry counts at a "0.5x weighted ingest rate" on the cloud platform, and at 50% on the self-managed product.
Enterprise (self-managed)
The Enterprise edition is the version you run yourself, in a private cloud or on premises. It is sold on ingest or workload pricing, with workload measured in vCPUs. The licence is only part of the cost: you also pay for the servers, storage and people that run indexers and search heads.
Enterprise Security editions
Enterprise Security (ES), the SIEM layer, comes in two editions, both by quote:
- Essentials includes the SIEM, threat intelligence, Detection Studio, exposure analytics and AI features.
- Premier adds SOAR, user and entity behaviour analytics (UEBA) and automated threat analysis.
If you need automated response or UEBA, price Premier, not Essentials.
Storage and retention: where the hidden costs sit
The cloud platform splits storage into several products. Each has different search rules, and the rules matter as much as the price.
| Storage | What it is | Can you search it where it sits? | Source |
|---|---|---|---|
| Searchable storage (DDAS) | "The primary entry point for newly ingested data" | Yes | Service details |
| Active archive (DDAA) | Vendor-managed archive for data past searchable retention | No: restore first. Restored data is searchable "within 24 hours" and "for up to 30 days" | Service details; archive documentation |
| Self-storage (DDSS) | Aged data exported to your own AWS S3 or Google Cloud Storage | No: it "will no longer be searchable by Splunk Cloud Platform" | Service details |
| Federated Search for Amazon S3 | Search over data in your own S3 buckets | Yes, on a separate licence of Data Scan Units | Federated search documentation |
The archive documentation adds two limits. "The restoration process can take up to 24 hours to complete." And the vendor "will block you from restoring large amounts of data" that could affect performance. Ask how much you can restore at once before you rely on the archive for investigations.
Federated Search for Amazon S3 is licensed separately from SVCs and ingest. You buy Data Scan Units for the data you expect to scan in a year, and "each DSU is equivalent to 10 TB of data scanning capabilities". It is available only on cloud deployments in AWS regions.
The practical effect: a threat hunt that reaches past your searchable retention starts with a restore request or a separately licensed scan. Size searchable retention for the longest window you expect to investigate, not only for compliance.
Free options
There are free trials of the cloud and self-managed products, and a Free licence, which "allows you to index 500 MB per day" on a single instance. It is for learning, not security operations: "Alerting (monitoring) is not available", there are "no users or roles", and search is disabled after repeated licence violations.
How to read a quote
Because there is no list price, the useful work is making two quotes comparable. Ask for these line by line:
- The model. Workload, ingest or activity-based, and why that model suits your search load.
- The unit count. SVCs or vCPUs for workload; GB a day for ingest. For ingest, confirm how many SVCs come with it.
- Enterprise Security edition. Essentials or Premier, and whether SOAR and UEBA are included.
- Searchable retention. Days of searchable storage per index, and the price of extending it.
- Archive and restore. Whether DDAA is included, how much you can restore at once, and how long restored data stays searchable.
- External data. Whether Federated Search is included, and how many Data Scan Units.
- Growth terms. What happens at renewal if your volume or search load grows by half, and how overages are billed.
- Cisco weighting. Which of your sources qualify for the 0.5x ingest rate.
Then add the costs outside the licence line: infrastructure if you self-manage, professional services, and the engineers who write and tune SPL detections. Our SIEM cost calculator sets your quote against Microsoft Sentinel's list price and an indicative SenseOn figure.
How to cut the bill
- Filter before you ingest. Drop fields and events you never search. NIST's log management guide, SP 800-92, asks you to set a purpose and retention for each log source before you collect it.
- Match the model to your search pattern. Workload pricing favours large volumes searched rarely; ingest pricing favours heavy search over a steady volume.
- Stay under the overage limit. On ingest pricing, more than five days over your daily volume in a month is a breach of terms, not just a spike.
- Tier retention by use. Keep searchable storage for the investigation window; archive the rest. Remember the 24-hour restore when you set the window.
- Claim the Cisco weighting for eligible Cisco sources.
- Retire detections that never fire. Every scheduled search consumes compute. Researchers who re-engineered SIEM correlation rules found higher detection rates and fewer false positives, and traced much of SIEM's shortfall to insufficient configuration (Bryant and Saiedian, Computers & Security, 2020).
For levers that apply to any SIEM, see our SIEM price reduction tactics, and for costs outside the licence line, the hidden costs of SIEM.
Why not archive most of your data?
It is the obvious way to cut searchable storage, and the same trade-off appears in Microsoft Sentinel's data lake. Archived data cannot be searched until it is restored, and restored data is searchable for up to 30 days. The sources that go to archive first are the high-volume ones: firewall, DNS, proxy and network flow logs. MITRE ATT&CK notes that for command and control, "adversaries commonly attempt to mimic normal, expected traffic to avoid detection". Our judgement: archiving network logs to save money saves it on the records you need to spot that traffic, and a hunt that reaches back months starts with a wait.
Where SenseOn fits
SenseOn is priced differently. There is no per-GB ingestion charge and no restore step. It is priced as an annual pool of Flex Intelligence Credits, and three things bring the cost down:
- Edge processing removes unnecessary data before it reaches the pipeline.
- Three-pipeline routing, configured by Weave, SenseOn's security engineering agent, sends each source down the right pipeline, with storage separated from compute.
- Compression, with pricing calculated on the compressed storage volume rather than raw ingest.
Together these cut costs by about 40% against a traditional SIEM. The price also covers the Agentic Cybersecurity Team (ACT), SenseOn's AI agents that investigate and resolve cases. That work is charged on the agents' activity, not as an MDR service, and there is no charge when a case is handed to a person.
Detection is not tied to a storage tier. SenseOn detects in real time on the endpoint, in near real time across all log sources on its message queue, and with batch analytics about every five minutes across the data lake. Data rolls between tiers automatically and can be routed straight into any tier. SenseOn's AI agents run queries and threat hunts across every tier for the whole retention period. Because they are long-running agents, a query over older data can take a little longer without anyone waiting on it.
SenseOn is a security platform, not general log analytics: if you also use it for application monitoring, keep an observability tool for that. SenseOn deploys alongside Splunk, so you can run both for a 14 to 28 day proof window and compare on your own data. See our Sentinel vs Splunk vs SenseOn comparison, SenseOn vs Splunk and Splunk alternatives, or the pricing page for SenseOn's credit plans.
Sources
- Splunk pricing models, accessed 23 September 2026
- Platform pricing, accessed 23 September 2026
- Platform pricing FAQ, accessed 23 September 2026
- Pricing calculator, accessed 23 September 2026
- Splunk Cloud Platform service details, updated 6 March 2026, accessed 23 September 2026
- Store expired Splunk Cloud Platform data in a Splunk-managed archive, accessed 23 September 2026
- About Federated Search for Amazon S3, updated 6 March 2026, accessed 23 September 2026
- About Splunk Free, updated 13 January 2026, accessed 23 September 2026
- Splunk Enterprise Security, accessed 23 September 2026
- Blake D. Bryant, Hossein Saiedian, "Improving SIEM alert metadata aggregation with a novel kill-chain based classification model", Computers & Security, 2020, https://doi.org/10.1016/j.cose.2020.101817
- NIST, SP 800-92: Guide to Computer Security Log Management, September 2006, accessed 23 September 2026
- MITRE, ATT&CK Command and Control, TA0011, accessed 23 September 2026
How SenseOn writes, checks and corrects its content: editorial standards.
Frequently asked questions
How much does Splunk cost?
Splunk does not publish a price for Splunk Cloud Platform or Splunk Enterprise Security; every deal is quoted. The quote is sized in Splunk Virtual Compute units (SVCs) on workload pricing, in gigabytes a day on ingest pricing, or on both ingest and search activity on activity-based pricing. Splunk's own pricing calculator estimates SVCs from your daily data volume, not dollars.
What is an SVC in Splunk?
A Splunk Virtual Compute unit. Splunk defines it as "a unit of capabilities in Splunk Cloud Platform that includes compute, memory, and I/O resources". Workload subscriptions are sized in SVCs and do not meter ingestion; ingest subscriptions come with up to 1 SVC for every 10 GB a day.
Is Splunk priced per GB?
It can be. Ingest pricing is "based on gigabytes of data ingested into Splunk". But Splunk's Cloud Platform service details say subscriptions are workload-based by default and ingest-based only by exception. On an ingest subscription you can exceed your purchased daily volume a maximum of five times in a calendar month.
How long does it take to restore archived Splunk data?
Splunk's archive documentation says "the restoration process can take up to 24 hours to complete", and the Cloud Platform service details say restored data is searchable for up to 30 days. Splunk may block restores of large amounts of data that could affect performance.
Is there a free version of Splunk?
Splunk Free lets you index 500 MB a day on a single Splunk Enterprise instance. It has no alerting, no users or roles, and search is disabled after repeated licence violations, so it is for learning rather than security operations. Splunk also offers free trials of Splunk Cloud and Splunk Enterprise.