Splunk licensing is the set of contract terms, capacity units and pricing models under which Splunk LLC licenses Splunk Enterprise, Splunk Cloud Platform, its security products (Enterprise Security, SOAR, Attack Analyzer and related apps) and its observability products (Splunk Observability Cloud, IT Service Intelligence, On-Call). Every Splunk offering, whether bought from Splunk, a Splunk affiliate distributor, a reseller or a cloud marketplace, is governed by one master agreement, the Splunk General Terms, which grants use “up to the Capacity” stated in the Order.[1] Capacity is measured in the unit that the Purchase Capacity and Limitations page sets for each offering: daily indexing volume or vCPUs for Splunk Enterprise, daily indexing volume or Splunk Virtual Compute (SVC) for Splunk Cloud Platform, hosts or usage meters for Observability Cloud, and product-specific units such as monitored accounts, user seats or assets for the security apps.[2]
Cisco completed its acquisition of Splunk on 2024-03-18.[7] Splunk offerings continue to be sold under the Splunk name and the Splunk General Terms, although the documents now link to Cisco policies (the Cisco Trust Portal for usage-data disclosures and the Cisco Acceptable Use Policy for AI features).[1][3] The meter definitions for each Splunk product, and the Splunk Enterprise licence-warning and violation rules, are catalogued in Splunk licensing under Cisco; this article covers the contract framework that sits above them.
Editions
Splunk groups its portfolio into three families on its pricing pages:[6]
| Family | Main offerings | Deployment | Pricing models offered |
|---|---|---|---|
| Splunk Platform | Splunk Enterprise, Splunk Cloud Platform, Ingest and Edge Processor, Federated Search, Machine Data Lake | On-premises term licence or Splunk-hosted subscription | Ingest or workload (Enterprise); activity-based, ingest or workload (Cloud Platform) |
| Splunk Security | Enterprise Security (Essentials and Premier editions), SOAR, Attack Analyzer, User Behavior Analytics, Asset and Risk Intelligence | Premium apps on the platform, plus hosted services | Activity-based, workload or ingest for Enterprise Security; seats, events or submissions for SOAR and Attack Analyzer |
| Splunk Observability | Observability Cloud (Infrastructure Monitoring, APM, RUM, Synthetics, Log Observer Connect), IT Service Intelligence, On-Call, Agent Observability, AppDynamics | Hosted services; ITSI as a premium app | Host-based entity pricing or usage meters; workload or ingest for ITSI; per user for On-Call |
The editions within each product are described in the deeper articles: Splunk Enterprise license management, Splunk Cloud Platform subscriptions, Splunk Enterprise Security and ITSI licensing and Splunk Observability Cloud licensing.
Contract documents
The Splunk Contracting Hub describes the Splunk General Terms (SGT) as “a single set of terms that applies across all our offerings”, which incorporates the Specific Offering Terms, the Support Terms, and the security and privacy terms.[4] The layers that decide a licence position are:
| Document | What it decides | Version on 2026-10-02 |
|---|---|---|
| Splunk General Terms | Use rights, limits, Third Party Providers, verification, overages, term and renewal | Last updated May 2026 |
| Purchase Capacity and Limitations | The Capacity unit and limits of every offering | Last updated September 2026 |
| Specific Offering Terms | Service descriptions, Observability definitions, Activity Based Pricing, Cloud Flex, Cisco programs | Last updated September 2026 |
| Support Terms and Support Policy | Support Programs, Support Contacts, supported-version timelines | September 2024 and August 2026 |
| The Order | Offering, Capacity, Term, price | Per deal |
The SGT defines Capacity as a “measurement of usage of an Offering” stated in the Order, and points to the Purchase Capacity and Limitations page for the capacities of each offering.[1] Splunk may change the Specific Offering Terms at any time, but changes apply only to offerings ordered or renewed after the change.[1] Neither the SGT, the Specific Offering Terms nor the Purchase Capacity page carries a day-level effective date; each shows only a month and lists dated prior versions.
Metrics
Splunk publishes four pricing models.[5]
- Ingest pricing charges for gigabytes ingested per day (Daily Indexing Volume). It is available for Splunk Cloud Platform, Splunk Enterprise, Enterprise Security and ITSI, with no charge for additional users or search activity.
- Workload pricing charges for compute: Splunk Virtual Compute (SVC) units in Splunk Cloud Platform and vCPUs for Splunk Enterprise. It is offered for the same four products.
- Activity-based pricing is a dual meter of ingest and search, available for Splunk Cloud Platform. Contractually it is the Activity Based Pricing (ABP) Offer: an annual dollar commitment drawn down by Search and Ingest consumption.[3]
- Entity pricing charges by number of hosts or servers and is used for Observability Cloud, where tiers start at USD 15, 60 and 75 per host per month billed annually.[6]
Splunk Enterprise volume and vCPU licences cannot be stacked with each other, and premium licences such as Enterprise Security and ITSI must match the licence type of the core Splunk Enterprise licence.[2] The full list of product-specific units (UBA monitored accounts, SOAR events and seats, Attack Analyzer submissions, ARI assets, MTS, TAPM, test runs, sessions, database instances, spans, Data Scan Units) is on the Purchase Capacity page and in the Cisco-published catalog rows linked from Splunk licensing under Cisco.
Counting / floors
Use rights and limits
The SGT grants a non-exclusive, worldwide, non-transferable and non-sublicensable right to use acquired offerings “only for your Internal Business Purpose during the Term, up to the Capacity” (rule).[1] Internal Business Purpose means analysing or monitoring the customer’s own IT infrastructure or operations from its own systems; it excludes ingesting or monitoring third parties’ systems, networks, devices or application data, so a managed-service provider needs a different agreement (rule).[1] The SGT lists eleven separate limits, including no reverse engineering, no resale or sublicensing, no circumvention of licence keys, no competitive benchmarking or building of competing or commercial extensions, and no exceeding the Capacity; “each of the foregoing subsections imposes a separate and independent limit”.[1] The interpretation of these limits was tested in Splunk v. Cribl.
Contractors and outsourcers may use the offerings on the customer’s behalf as Third Party Providers, but the customer is liable for them and “the aggregate use by you and all of your Third Party Providers must not exceed the Capacity” (rule).[1]
Trial, free and non-production use
Trials continue only on payment of fees after the trial term; beta offerings are limited to internal testing for the stated period or, if none, until general availability or one year; offerings marked “Test and Development” on the Order may be used only on non-production systems (rule); free offerings may have limited features. All of these are provided as-is, without warranty, support or service levels, and may be terminated without notice unless the Order says otherwise.[1] Where no end date is specified, or there is no Order, the Term is limited to 60 days (rule).[1]
Verification and overages
On request the customer must provide a certification, signed by an authorised representative, that its use complies with the SGT and the Order. For on-premises products Splunk may additionally ask, not more than once every 12 months, to verify usage and adherence to the Capacity with reasonable access to the installed product, including where a Third-Party Provider hosts it (rule).[1] If a verification or usage report shows use above the Capacity, Splunk may invoice the excess “using the applicable Fees at list price then in effect”, and may invoice the customer directly even when the offering was bought through a reseller or marketplace (rule).[1] The 12-month liability cap does not limit Splunk’s right to recover amounts for use above purchased Capacity or outside Internal Business Purpose, and the cap does not apply at all to violations of the use-right limits.[1]
Hosted services have their own enforcement: Splunk Cloud Platform ingest subscriptions may exceed the daily volume no more than five times a calendar month, and Observability Cloud charges 150% of the effective list price for monthly usage above the subscription limits.[11][12]
Term, renewal and termination
Unless the Order says otherwise, each offering acquired through an Order renews automatically for a period equal to the preceding Term unless either party gives notice of non-renewal “at least 1 day before the expiration” (rule).[1] Fees are non-cancellable and non-refundable except as stated, and on expiry the customer must stop using the offering and return or destroy on-premises copies. For hosted services Splunk keeps Customer Content available for 30 days after termination and then deletes it (rule).[1] The SGT is governed by California law with exclusive venue in the Northern District of California.[1]
Virtualization & partitioning
The SGT has no partitioning rules. For workload licences the Purchase Capacity page defines a vCPU as a virtual CPU to which the software has access, each equal to “a distinct hardware thread of execution in a physical CPU core”, so virtual machine sizing determines the count.[2] How Splunk measures vCPUs on search heads and indexers is described in Splunk Enterprise license management.
Cloud / BYOL
Splunk Cloud Platform is a Splunk-hosted subscription with its own Capacity; the SGT contains no clause converting on-premises Splunk Enterprise licences into Splunk Cloud Platform capacity.[1] On-Premises Products are defined as software “deployed and operated by you, or on your behalf, on hardware designated by you”, a definition that does not restrict where that hardware is, and the 12-month verification right expressly covers products “hosted by your Third-Party Provider”.[1] Subscriptions bought through a digital marketplace remain governed by the SGT; if the customer does not pay the marketplace, Splunk may collect directly.[1]
Programs
- Splunk Cloud Flex lets customers reallocate committed value between eligible Splunk products during the initial term, as an even exchange of value at the Order unit prices; Splunk says it covers platform, security, observability, AI, storage and federated search products.[3][5]
- Activity Based Pricing is an annual dollar commitment per Splunk Cloud Platform instance, consumed by search and ingest.[3]
- Integrated Enterprise Value counts eligible Cisco-generated data at a 0.5x weighted ingest rate, and the Cisco Firewall Promotional Splunk Capacity Offer gives free capacity to Cisco Secure Firewall customers who hold at least as much paid Splunk capacity.[3]
- Splunk Success Plans (Standard or Premium) are included with licence purchases and bundle support, OnDemand Services credits and Education credits; credits require a minimum purchase of 250 GB, 50 vCPU or 20 SVC for Standard and 1 TB, 100 vCPU or 50 SVC for Premium (rule).[10]
Support
Support is provided under the Support Program named in the Order and the Support Terms. Only designated Support Contacts may open cases, and their number depends on the offering Capacity and Support Program (rule).[8] Splunk Extensions labelled “Splunk Supported” on Splunkbase get P3-level support; “Not Supported” and third-party extensions get none.[8] Under the Support Policy each minor version of Splunk Enterprise, Enterprise Security, ITSI and SOAR is supported for 24 months from release, Splunk Cloud Platform versions for 12 months and Universal Forwarder versions for 60 months, and no support is given on operating systems past mainstream vendor support (rule).[9]
Out of scope
This article does not cover AppDynamics licensing (published on docs.appdynamics.com and linked from the Purchase Capacity page), partner and MSP agreements, Splunk’s data protection agreement and security exhibits, or Cisco Enterprise Agreement meters for Splunk, which are described in Cisco’s own articles.[2] Prices shown are Splunk’s published starting prices, not quotes.