LICENSEWARE

Splunk licensing under Cisco

This article is about how Splunk platform, security and observability offerings are measured under Splunk's Purchase Capacity and Limitations document and product documentation, now published by Cisco. Enterprise Agreement meter names for Splunk are listed in Cisco software subscription and Flex Plan licensing. It is not legal advice and does not replace the executed Order.

On This Page

Splunk licensing determines how much data customers may index, and how much compute they may use, in Splunk’s platform, security and observability products. Splunk is now part of Cisco: its capacity document carries a Cisco header, and one offering in it is described as available exclusively from Cisco Systems.[1] The central contractual document is Purchase Capacity and Limitations, which lists a capacity metric and limitations for every Splunk Offering. The August 2026 edition states that the most current terms are published on Splunk’s licensed-capacity page.[1]

Splunk describes its pricing in three models. Ingest pricing is “based on gigabytes of data ingested into Splunk”. Workload pricing is based on the compute and storage resources needed to run search and analytics. Activity-based pricing is a dual-meter model based on both ingest and search activity.[4] In the Cisco Enterprise Agreement these appear as the meters Ingest, Workload and vCPU, catalogued in Cisco software subscription and Flex Plan licensing. This article covers the definitions and enforcement rules behind those meters.

Editions

The capacity metric depends on the offering and its deployment:[1]

Offering Capacity metric 
Splunk Enterprise Daily Indexing Volume or number of vCPUs 
Splunk Cloud Platform Daily Indexing Volume or number of SVCs 
Splunk Enterprise Security (Essentials, Premier) Daily Indexing Volume and SVCs or vCPUs, as set in the Order 
Splunk IT Service Intelligence Daily Indexing Volume or vCPUs (SVC also available in Splunk Cloud Platform) 
Splunk SOAR (on-premises) Events per 24 hours, or User Seats 
Splunk SOAR (cloud) User Seats 
Splunk User Behavior Analytics Monitored Accounts, or Daily Indexing Volume when bought as an Enterprise Security add-on 
Splunk Attack Analyzer User Seats and Daily Submissions 
Splunk Asset and Risk Intelligence Assets 
Splunk Infrastructure Monitoring Hosts (host-based) or Metric Time Series (usage-based) 
Splunk APM Hosts (host-based) or Trace Analyzed Per Minute, TAPM (usage-based) 
Splunk Synthetic Monitoring Browser, API and Uptime Test Runs, and Web Optimization Scans, per month 
Splunk Real User Monitoring Sessions per month 
Splunk Database Monitoring Database Instances 
Splunk Federated Search (third-party object stores) Data Scan Units 
Splunk On-Call Users (unique email addresses) 

Help documentation adds non-production licenses. The Dev/Test license is available only to customers who hold a commercial, paid Splunk Enterprise license. It cannot be stacked, and installing it replaces other Splunk Enterprise license files (rule). There are also a Developer license, a Trial license and a Free license.[2]

Metrics

Platform metrics

  • Daily Indexing Volume: “the daily aggregate volume of uncompressed data for indexing as set forth in the Order”. Metrics data is converted into GB of daily ingestion at a fixed ratio given in the software documentation.[1] It corresponds to the EA meter Splunk Ingest.
  • vCPU. For Splunk Enterprise infrastructure licenses, vCPUs are the virtual CPUs the software can access. “Each virtual CPU is equivalent to a distinct hardware thread of execution in a physical CPU core” (rule). A physical core with two hardware threads therefore counts as two vCPUs.[1] EA meter: Splunk vCPU.
  • Splunk Virtual Compute (SVC): “a unit of capabilities in Splunk Cloud Platform that includes the following resources: compute, memory and I/O”.[1] Splunk’s pricing page says SVC consumption is driven mainly by search quantity and complexity and by daily indexing volume, and that Splunk Cloud Platform workloads are measured in SVCs while Splunk Enterprise workloads are measured in vCPUs (rule).[4] EA meter: Splunk Workload.

Splunk publishes no fixed conversion between GB per day and SVCs or vCPUs. Its workload calculator gives only an estimate, and Splunk notes that actual provisioning depends on factors such as use cases and the ratio of indexers to search heads.[4]

Security and observability metrics

The catalog holds each product-specific unit as its own row under Splunk’s name: SOAR Event, User Seat, Daily Submissions, UBA Monitored Account, Ransomware Monitored Account, ARI Asset, Metric Time Series, TAPM, Browser Test Run, API Test Run, Uptime Test Run, RUM Session, Database Instance, Span, Daily Processing Volume and Hadoop Node.

Several of these units come with worked examples in the source document. A browser test every five minutes from three locations counts as 36 Browser Test Runs per hour. A three-request API test running once a minute uses 180 API Test Runs per hour. A RUM Session lasts at most four hours and expires after 15 minutes of inactivity. An ARI Asset counts if it has been detected in the last 30 days.[1]

Counting / floors

Stacking

Splunk Enterprise is bought either as volume licenses or as infrastructure (vCPU) licenses, and “customers cannot stack volume licenses and infrastructure licenses”. Premium solutions such as Enterprise Security and IT Service Intelligence must match the license type of the core Splunk Enterprise license (rule).[1] Within one type, licenses can be stacked and divided into pools.[2]

Limited licenses have their own rules:[1]

  • Splunk Enterprise for DNS & Netflow Data covers only named source types. Ingest of those types above its volume “will be counted against the general ingest license capacity” (rule).
  • Splunk Enterprise for Cisco AnyConnect NVM allows 10 MB a day of NVM data per Endpoint, can be stacked on unrestricted licenses, and is sold only by Cisco.
  • Rapid Adoption Packages are capped at 25 GB a day whatever the number of use cases, limited to a single instance, and cannot be stacked (rule).
  • Splunk Data Stream Processor. Data ingested into Splunk Enterprise through DSP still counts against Splunk Enterprise capacity (rule).

Warnings and violations

Splunk Enterprise measures daily indexing from midnight to midnight on the license manager. Exceeding the licensed volume on any calendar day produces a license warning, and too many warnings produce a violation.[3] The thresholds depend on the license type:[3]

License Violation condition Effect 
Enterprise, stack below 100 GB/day 45 warnings in a rolling 60 days (rule) Search disabled for the pool; reset license from Splunk Sales 
Enterprise, stack of 100 GB/day or more None Warnings only; search not disabled (rule) 
Enterprise infrastructure (vCPU) None “does not currently violate” 
Trial 5 warnings in a rolling 30 days Indexing continues, search blocked; no reset 
Dev/Test, Developer 5 warnings in a rolling 30 days Indexing continues, search blocked; reset on request 
Free 3 warnings in a rolling 30 days (rule) Indexing continues, search blocked; no reset 

A license peer that cannot reach the license manager for 72 hours or more is also put in violation, and search on that peer is blocked until it reconnects (rule).[3]

Search blocking applies to Splunk Enterprise 8.1.0 and later for stacks below 100 GB. Splunk’s enforcement FAQ describes a “no enforcement” key that stops the software from turning off search. Licenses bought after 27 September 2016 come with two keys, one for the purchased capacity and one no-enforcement key, which works on license managers running version 6.5 or later (rule).[6] The FAQ adds that exceeding purchased capacity still breaches the Splunk General Terms even when the software does not enforce it.[6]

Seat and consumption rules

  • User Seats in Splunk SOAR and Splunk Attack Analyzer may be used by only one user at a time, and simultaneous logins on one account are not allowed (rule). Each Attack Analyzer seat includes 10 Daily Submissions.[1]
  • Data Scan Units for Federated Search are 10 TB each. Overages are billed per terabyte, rounded up, at one-tenth of the list price of a DSU (rule).[1]
  • Ingest Processor (Essentials tier) is limited to 500 GB a day of processing volume.[1]

Virtualization & partitioning

The vCPU definition makes virtualization straightforward to count: the licensed quantity is the number of hardware threads the software can reach, whether it runs on bare metal or in a VM.[1] Volume licenses do not depend on hardware and can be split into license pools for different indexers. When a pool is in violation, search is disabled only for that pool and its members; other pools remain searchable if their own usage is within allocation.[3]

Cloud / BYOL

Splunk Cloud Platform is the Splunk-managed SaaS version and is offered with activity-based, ingest or workload pricing. Splunk’s pricing page advertises a 0.5x weighted ingest rate for eligible Cisco telemetry in Splunk Cloud Platform, and a 50 percent weighted rate for Splunk Enterprise (rule).[5] The page does not list which sources are eligible, so the Order has to be checked. Splunk Cloud customers on AWS commercial regions with the Victoria Experience also receive a Cisco Data Fabric capacity package at no extra charge. It includes up to 10 TB of Machine Data Lake retention, 10 GB a day promoted to analytics tables, and 100 federated searches a day.[1]

Programs

Out of scope

  • List prices, including the “starting at” prices on the Splunk pricing page.
  • Splunk AppDynamics entitlements. The Purchase Capacity document points to AppDynamics documentation, and the Observability Platform bundles are covered in Cisco software subscription and Flex Plan licensing.
  • Host definitions for Infrastructure Monitoring, APM and Observability Cloud, which sit in Splunk’s Specific Offering Terms.
  • Enterprise Security add-on caps (Automated Threat Analysis, Exposure Analytics, SOAR playbook runs, Triage Agent and UEBA ratios). They are listed in the source table but not catalogued here.
  • Perpetual Splunk licenses and support renewal terms beyond the enforcement FAQ.

References

  1. Purchase Capacity and Limitations, Splunk Offerings (August 2026)Published August 2026 (no day stated); current version is indexed at splunk.com/en_us/legal/licensed-capacity.html. Catalog: Purchase Capacity and Limitations, Splunk Offerings (August 2026)Retrieved 2026-09-26.
  2. Types of Splunk Enterprise licenses (Splunk Enterprise 10.4)Last updated 2026-05-17. Catalog: Types of Splunk Enterprise licenses (Splunk Enterprise 10.4)Effective 2026-05-17. Retrieved 2026-09-26.
  3. About license violations (Splunk Enterprise 10.4)Last updated 2026-05-17. Catalog: About license violations (Splunk Enterprise 10.4)Effective 2026-05-17. Retrieved 2026-09-26.
  4. Pricing Models (Splunk)Not date-stamped. Catalog: Pricing Models (Splunk)Retrieved 2026-09-26.
  5. Pricing (Splunk)Not date-stamped. Catalog: Pricing (Splunk)Retrieved 2026-09-26.
  6. Splunk Enterprise License Enforcement FAQNot date-stamped. Catalog: Splunk Enterprise License Enforcement FAQRetrieved 2026-09-26.

See also

Catalog Rows Cited

15Rules23Metrics2Programs

Esc