Splunk Cloud Platform is the Splunk-managed software-as-a-service version of the Splunk platform, hosted on AWS, Google Cloud or Microsoft Azure. Splunk’s service description states that a subscription “is workload-based and is sized for resource capacity. By exception, you may be on an ingest-based subscription that is sized for data volume ingested.”[1] The Purchase Capacity page measures Splunk Cloud Platform by Daily Indexing Volume or by Splunk Virtual Compute (SVC), a unit of compute, memory and I/O.[3] A third model, Activity Based Pricing, sells a yearly dollar balance consumed by search and ingest.[2] The service is a Hosted Service under the Splunk General Terms, so the overview in Splunk licensing also applies.
Editions
Subscription types
| Type | Meter | What is metered | Storage |
|---|---|---|---|
| Workload-based (default) | SVC | Compute capacity; ingestion is not metered | Bought separately by retention need |
| Ingest-based (by exception) | GB per day | Uncompressed data indexed per day (GMT) | DDAS for 90 days of ingest included |
| Activity Based Pricing | Dollar balance per instance | Searches (weighted by GB scanned) and GB ingested | As quoted |
A workload subscription “does not meter ingestion”: the customer can increase ingest or search load until its SVC entitlement is fully used, then buy more SVC.[1] An ingest subscription governs how much data can be loaded per day and includes compute allocated by Splunk: up to 1 SVC for every 10 GB/day, plus 1 SVC for every 10 GB of licensed peak daily ingest when Enterprise Security is bought and 1 SVC for every 20 GB when ITSI is bought; Splunk says these ratios may change as the infrastructure evolves (rule).[1] Both workload and ingest subscriptions include a Standard or Premium Success Plan.[1]
Regulated environments
Optional subscriptions place the service in regulated environments: DoD Impact Level 5, FedRAMP Moderate and FedRAMP High (AWS GovCloud), HIPAA, PCI DSS, IRAP (AWS Sydney) and ISMAP (AWS Tokyo). Encryption at rest is enabled by default in each of these environments.[1] The Splunk General Terms forbid storing protected health information, payment card data or ITAR data in a hosted service unless the matching regulated environment was bought.[5]
Premium solutions
Enterprise Security, IT Service Intelligence and the Splunk App for PCI Compliance can be added as premium solution subscriptions that Splunk installs and upgrades; SOAR, User Behavior Analytics, Observability Cloud and On-Call are separate subscriptions.[1] The premium solution uses the platform’s unit: “With workload-based subscriptions, the unit of measurement is in SVC for both entitlements. With ingest-based subscriptions, the unit of measurement is in GB for both entitlements” (rule).[1] Details are in Splunk Enterprise Security and ITSI licensing.
Metrics
- Splunk Virtual Compute (SVC): workload subscriptions and the compute behind ingest subscriptions.
- Daily Indexing Volume: ingest subscriptions.
- Search and Ingest: the two Activity Based Pricing meters.
- Dynamic Data Active Searchable (DDAS) and Dynamic Data Active Archive (DDAA): storage, each sold in 500 GB increments.[1]
- Data Scan Unit: Federated Search over customer-managed object stores, with overage billed per TB at one-tenth of the DSU list price.[3]
Counting / floors
Ingest overage
Under an ingest subscription the daily index volume may be exceeded “a maximum of five times in a calendar month” (rule). Beyond that, Splunk sales may work with the customer to reduce usage or buy an increase, and a customer “unable or unwilling to abide by the applicable usage limit” pays any invoice for excess usage under its terms of service.[1] The Specific Offering Terms incorporate this data ingestion and daily license usage policy by reference.[2] Usage is shown in the Cloud Monitoring Console license usage dashboards. Splunk Cloud Platform “does not support licensing pooling” (rule).[1]
Data filtered or routed away by ingest actions before it reaches an index does not count against an ingest licence; on a workload licence, ingest-actions processing outside the indexing tier does not count.[7] Eligible Cisco data counts at a 0.5x weighted rate on Splunk Cloud Platform ingest licences under Integrated Enterprise Value, but the weighting does not change SVC consumption.[6]
Storage
Ingest subscriptions include enough DDAS to keep up to 90 days of uncompressed ingest (9 TB for 100 GB/day) (rule); workload subscriptions buy DDAS according to retention needs, for example 365 TB for 1 TB/day kept for 365 days.[1] If ingest exceeds the storage entitlement, storage expands elastically to keep data for the configured retention, and the service description refers to the Splunk General Terms “for Splunk’s policy for Overages”, which allows excess use to be invoiced at list price.[1][5]
A DDAA subscription adds DDAS equal to 10% of the total DDAS entitlement, reserved for restores; restores that push usage above the DDAS entitlement “may incur a true-up cost”, and overlapping restores within 30 days accrue against the extra 10% (rule).[1] Dynamic Data Self-Storage exports aged data to the customer’s own cloud storage account, at the customer’s cost, where it is no longer searchable by Splunk Cloud Platform.[1]
Activity Based Pricing
Under the ABP Offer the customer commits to an annual dollar amount derived from committed daily ingest and search volumes; it becomes a separate ABP Subscription Balance for each Splunk Cloud Platform instance, pooled across search and ingest within an instance but not across instances.[2]
- Search counting. A search that scans less than 10 GB counts as 1 Search, 10 GB to 100 GB as 5, and more than 100 GB as 25 (rule). Each Search deducts the Core Search unit price plus a proportional share of quoted Premium App prices; Splunk’s example is a USD 1 core search plus USD 1 premium-app share, so USD 2 per Search. Searches for Splunk Cloud operations and maintenance are excluded.[2]
- Ingest counting. Each GB of uncompressed data indexed consumes one GB of Ingest Capacity, and eligible Cisco data under IEV consumes 0.5 GB.[2]
- Usage above commitment. Use more than 20% above the daily commitment may degrade performance; if consistent, the customer agrees to optimise or buy more capacity at the Order’s annualised unit rates. Splunk provides monthly usage reports.[2]
- Rollover and carry forward. Up to 20% of a period’s quoted ABP value may roll to the next annual period of the same instance (rule). At the end of the initial term, a renewal of all instances for an equal or longer term at an equal or higher annualised commitment carries forward up to one-twelfth of the final-year commitment; any other positive balance is forfeited and a negative balance may be invoiced.[2]
Virtualization & partitioning
Not applicable: the customer does not size hardware. Splunk defines SVC as a unit of “compute, memory and I/O” and benchmarks SVC performance with a Splunk Search Benchmark.[1] Workload management pools are configuration, not licensing.
Cloud / BYOL
Data stays in the region chosen; storing data in more than one region requires multiple subscriptions.[1] Splunk Cloud customers on AWS commercial regions with the Victoria Experience receive a Cisco Data Fabric included capacity package: 10 TB in Machine Data Lake, 10 GB/day promoted to Analytics Table and 100 federated searches per day, with add-on capacity required above those limits.[3] Ingest Processor Essentials is capped at 500 GB/day of processing volume.[3]
Programs
Cloud Flex
Splunk Cloud Flex lets a customer reallocate Capacity between reallocation-eligible products bought on the Order during the initial term. Reallocations are an even exchange of value at the annualised unit prices in the Order (excluding one-time discounts), rounded up to whole units, and the rates stay fixed for the initial term.[2] Requests open 90 days into the initial term, are limited to one executed request per rolling 90 days, and are not processed in the last two weeks of January, April, July and October (rule). New instances created by a reallocation must keep the original’s end date, cloud provider, experience type, Success Plan level, compliance type and unit of measure; reducing an instance to zero terminates it; free offerings and instances on temporary capacity increases are excluded; and data migration is not included.[2] On an ABP order, ABP Premium App capacity must always equal ABP Search quantity (rule).[2] Splunk’s pricing page says Cloud Flex covers platform, security, observability, AI, storage and federated search products.[4]
Expansion, renewal and termination
Subscriptions can be expanded at any time during the term (higher workload or ingest level, storage, encryption, regulated environments, premium solutions). Renewal notices start 60 days before the end date. If a subscription expires without a temporary extension it is treated as terminated: search stops immediately, ingestion stops after 30 days and data is deleted after 30 days (rule).[1] The Splunk General Terms renew orders automatically for the same term unless notice is given at least one day before expiry, so an expiry normally requires an explicit non-renewal.[5]
Out of scope
Splunk Enterprise on premises is covered in Splunk Enterprise license management. Splunk Observability Cloud is a separate hosted service; see Splunk Observability Cloud licensing. Service limits (search concurrency, app counts, HEC payload sizes) are operational and not licence terms.