Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI) are Splunk’s two main premium apps: ES is a security information and event management (SIEM) and security operations application, and ITSI an AIOps and service-monitoring application. Both run on top of Splunk Enterprise or Splunk Cloud Platform and are licensed against the same data and compute as the platform. Splunk’s ES documentation states that a customer “must have Splunk Enterprise or Splunk Cloud Platform along with a Daily Indexing Volume or vCPU usage license” to download the app.[2] The Purchase Capacity page requires premium licences “such as Enterprise Security and IT Service Intelligence” to match the licence type of the core Splunk Enterprise licence.[1]
Editions
Enterprise Security Essentials and Premier
Enterprise Security is sold in two editions. Splunk’s pricing page describes Essentials as “Human-led, AI-accelerated defense” and Premier as “Adaptive, autonomous defense”, listing SIEM, threat intelligence, Detection Studio, Exposure Analytics, SOAR, UEBA and Automated Threat Analysis among ES capabilities.[5] The Purchase Capacity page shows which capabilities each edition includes and how each is metered; SOAR is in both editions, while Automated Threat Analysis, Exposure Analytics, Triage Agent and UEBA are Premier only:[1]
| Capability | ES Essentials | ES Premier | Limit (volume, vCPU or SVC licence) |
|---|---|---|---|
| Ingest | Daily Indexing Volume and SVCs or vCPUs, as in the Order | Same | Volume on Splunk Cloud Platform or Splunk Enterprise; vCPU on Splunk Enterprise; SVC on Splunk Cloud Platform |
| SOAR | Per playbook run | Per playbook run | Max 250k playbook runs per day |
| Automated Threat Analysis | Not included | Per submission | Max 2K submissions per day |
| Exposure Analytics | Not included | Per asset | Max 1M assets per tiered licence |
| Triage Agent | Not included | Per finding | Max 200 findings per day |
| UEBA | Not included | Daily Indexing Volume and SVCs or vCPUs | Max 0.5 UEBA GB per ingested GB; 2.5 per vCPU GB; 5.0 per SVC GB |
Splunk publishes no list price for either edition; ES can be bought with activity-based, workload or ingest pricing.[5]
IT Service Intelligence
ITSI “requires a separate ITSI license in addition to your Splunk Enterprise license”, and both licences are installed on the license manager.[3] It is measured by Daily Indexing Volume or vCPUs as set in the Order, with SVC also available when consumed within Splunk Cloud Platform.[1] Splunk sells ITSI with workload or ingest pricing.[5]
Related security products
Other Splunk security products carry their own units and are listed on the Purchase Capacity page:[1]
- Splunk SOAR (on-premises): number of Events per 24-hour UTC period or number of User Seats; each account may be used by one user at a time; limited to the end user’s internal security purposes. Splunk SOAR (cloud): User Seats.
- Splunk User Behavior Analytics: monitored user and service accounts in Active Directory, LDAP or similar, or Daily Indexing Volume when bought as an add-on to ES.
- Splunk Attack Analyzer: User Seats, each with 10 Daily Submissions, plus optional supplemental submissions.
- Splunk Asset and Risk Intelligence: per Asset seen in the inventory within the last 30 days; one licence is a single instance deployment.
- Splunk App for PCI Compliance: Daily Indexing Volume, or SVC in Splunk Cloud Platform.
- Splunk Enterprise for DNS and Netflow Data and Splunk Insights for Ransomware: limited-source or limited-use licences; the DNS and Netflow licence is also available for ES and ITSI.
The meter rows for these products are listed under Splunk licensing under Cisco.
Metrics
ES and ITSI are licensed on the platform metrics: Daily Indexing Volume, vCPU on Splunk Enterprise, or SVC on Splunk Cloud Platform. ES license usage “is measured on Daily Indexing Volume for data sources, vCPUs, and SVC”.[2] ES Premier adds the capability meters in the table above. In Splunk Cloud Platform under Activity Based Pricing, a premium app is not metered separately: each Search deducts a proportional share of the quoted Premium App price in addition to the Core Search price.[6]
Counting / floors
No extra ingest
Buying ES does not add ingest capacity. Splunk’s example: with a 1 GB Daily Indexing Volume licence plus ES, “you can only ingest 1 GB of data to use in Splunk Enterprise and Enterprise Security. You do not receive any additional ingestion capacity” (rule).[2] Splunk monitors daily indexing volume and the use of that data for security use cases, and monitors vCPU usage from data summarised in ES-specific summary and metrics indexes. To calculate premium-app consumption on ingest licences Splunk points to the Splunk App for Chargeback.[2]
ITSI meters Splunk indexes “for ingest-based license usage and capacity consumption calculations”, measured on the data sources and indexes ITSI uses; workload consumption is shown in ITSI’s SVC Statistics dashboard.[3]
Matching licence types
Premium licences must match the core licence type, and volume and vCPU licences cannot be stacked, so a customer on a vCPU Splunk Enterprise licence buys ES or ITSI by vCPU.[1] In Splunk Cloud Platform the premium solution uses SVC on a workload subscription and GB on an ingest subscription (rule).[4] On ingest subscriptions, buying ES adds 1 SVC of compute for every 10 GB of licensed peak daily ingest and ITSI 1 SVC for every 20 GB.[4] Under ABP with Cloud Flex, Premium App capacity must always equal the ABP Search quantity (rule).[6]
ITSI internal licence stack
ITSI Event Analytics generates many notable events. ITSI ships an internal licence stack, “IT Service Intelligence Internals DO NOT COPY”, so that the sourcetypes for notable events and episodes are counted there “with no impact on your Splunk Enterprise license”; Splunk tells customers to disregard this stack when calculating daily licence use (rule).[3] Because every installation receives the same auto-generated internal stack, an indexer that serves two environments with separate license managers raises a duplicate licensing error, which Splunk resolves by replacing the internal licence with a secondary one.[3]
Virtualization & partitioning
On vCPU licences, ES and ITSI follow the Splunk Enterprise vCPU count: every vCPU of every search head and indexer counts.[1] Splunk Cloud Platform gives premium solutions additional search processes reserved for them, which is a service limit rather than a licence entitlement.[4]
Cloud / BYOL
In Splunk Cloud Platform, ES, ITSI and the App for PCI Compliance are premium solution subscriptions installed and upgraded by Splunk; customisation is the customer’s job or a Professional Services engagement. SOAR Cloud, UBA, Mission Control, Security Essentials, Observability Cloud and On-Call are separate subscriptions or apps.[4] Under the Specific Offering Terms the customer grants Splunk the right to extract and use “Threat Data”, the threat intelligence, detection and security event information derived from data submitted to the hosted ES service, to provide and improve Splunk offerings, subject to Splunk’s confidentiality obligations.[6]
Programs
ES and ITSI can be included in Splunk Cloud Flex reallocations and in Activity Based Pricing orders.[6][8] Each minor version of ES and ITSI is supported for 24 months from release.[7]
Out of scope
Splunk SOAR licence installation, UBA capacity limits and Attack Analyzer service levels are documented in their own product guides.