LICENSEWARE

Splunk Observability Cloud licensing

This article is about how Splunk Observability Cloud (Infrastructure Monitoring, APM, RUM, Synthetic Monitoring, Log Observer, Database Monitoring), Splunk On-Call and Splunk Agent Observability are measured and enforced. It is not legal advice and does not replace the Order.

On This Page

Splunk Observability Cloud is Splunk’s hosted suite for monitoring infrastructure and applications. The Specific Offering Terms list its services as Splunk Infrastructure Monitoring, Splunk Application Performance Monitoring (APM), Splunk Real User Monitoring (RUM), Splunk Log Observer Connect and Splunk Synthetic Monitoring, sold as a suite or as individual services.[2] Each subscription is defined by the capacity limits in the Order (“Subscription Limits”), measured and enforced under a separate Usage, Subscription Limits Enforcement and Entitlements document.[1] Splunk calls the per-host model “entity pricing” and publishes starting prices per host per month.[4] Splunk On-Call (incident response) and Splunk Agent Observability (monitoring of AI agents) are licensed separately and are also covered here.

Editions

Observability Cloud bundles

Splunk’s pricing page lists three host-based bundles, each billed annually:[4]

Bundle Starting price per host per month Included services 
Infrastructure USD 15 Infrastructure Monitoring, Log Observer Connect, Network Explorer, Synthetic Uptime Monitoring 
App & Infra USD 60 Adds APM (including Always On Profiling) and Synthetic API Monitoring 
End-to-End USD 75 Adds Real User Monitoring and Synthetic Browser Monitoring 

Database Monitoring and Secure Application are optional add-ons. A free edition is also offered.[4] Infrastructure Monitoring, APM and RUM are each sold in Standard and Enterprise editions, which differ in the allowances attached to each unit (see Counting below).[1]

Usage-based options

Instead of hosts, the Purchase Capacity page allows usage-based pricing for several services:[3]

Service Host-based unit Usage-based unit 
Infrastructure Monitoring Hosts, with Containers and Custom Metrics Metric Time Series (MTS) 
APM Hosts, with Containers, Profiled Containers, MetricSets, Trace and Profiling Volume Traces Analyzed Per Minute (TAPM), with MetricSet and volume allowances 
Log Observer Hosts Volume of Indexed Data or Ingested Data 
RUM n/a Sessions per month 
Synthetic Monitoring n/a Browser, API and Uptime Test Runs and Web Optimization Scans per month 
Database Monitoring n/a Database Instances 
Secure Application Hosts, with 8 GB/day of security events n/a 

Log Observer is available only to customers of Infrastructure Monitoring, APM or Observability Cloud, with 30-day retention for Indexed Data that can be extended to 60 or 90 days.[3]

On-Call and Agent Observability

Splunk On-Call is measured by Users, defined as the number of unique email addresses.[3] Additional users can be added in the administrative portal and are charged pro rata for the current term, to a card on file or by invoice.[2] The pricing page lists On-Call from USD 5 per user per month, billed annually, for up to 10 seats (SKU).[4] The Specific Offering Terms note that On-Call has not undergone an independent security audit and holds no SOC 2 or ISO 27001 certification.[2]

Splunk Agent Observability is sold as a package. The cloud edition includes 1.2 million Spans, 500 million Luna Tokens and 5 Luna fine tunes per year, with add-ons of 10K Spans or 10B Luna Tokens; the software (self-hosted) edition includes 30 million Spans and 48 billion Luna Tokens per year.[3] The cloud package starts at USD 100 per month per 1.2 million spans annually (SKU).[4]

Metrics

The vendor definitions are in the Specific Offering Terms: a Host “means a virtual machine or physical server being monitored”; a Container is a stand-alone executable package that shares the underlying operating system with other containers; a Custom Metric is any metric not collected automatically by Splunk’s standard host-based integrations; and a Metric is “any unique combination of a metric name and dimension value reporting data to Splunk within the last hour”. The terms also define Monitoring and Troubleshooting MetricSets, Profiled Containers, Serverless Functions, Spans, Traces, Trace Volume, Profiling Volume and Session Volume.[2]

Counting / floors

Per-unit entitlements

Each host or usage unit carries fixed allowances (rule):[1]

Unit Standard Edition Enterprise Edition 
Infrastructure Monitoring Host 10 Containers or serverless functions, 100 Custom Metrics 20 Containers or serverless functions, 200 Custom Metrics 
APM Host 10 Containers, 3 Profiled Containers, 20 Monitoring and 200 Troubleshooting MetricSets, 10.24 MB/min traces, 5.12 MB/min profiling 20 Containers, 5 Profiled Containers, 40 and 400 MetricSets, 20.48 MB/min traces, 10.24 MB/min profiling 
APM Container Add-on 1 Container, 2 Monitoring and 20 Troubleshooting MetricSets, 1.024 MB/min traces Same 
APM TAPM 0.005 Monitoring and 0.05 Troubleshooting MetricSets, 0.00256 MB/min traces 0.01 and 0.1 MetricSets, 0.00512 MB/min traces 
RUM, per 10,000 sessions/month 20 Monitoring and 200 Troubleshooting MetricSets, 30 GB session volume 40 and 400 MetricSets, 60 GB session volume, Session Replay 

The Digital Experience Analytics option adds 10 Monitoring MetricSets to each RUM edition. One Synthetic Monitoring entitlement covers 1K browser test runs, 10K API test runs and 10K uptime tests per month, and one Database Monitoring licence covers one Database Instance.[1] Splunk’s examples show how test runs multiply: a browser test every 5 minutes from 3 locations uses 36 Browser Test Runs an hour, and a three-request API test each minute uses 180 API Test Runs an hour.[3]

Measurement

Usage is measured per component of the Subscription Limits (rule):[1]

  • Infrastructure Monitoring: hourly; the monthly usage level is the average of all hourly measurements.
  • APM: every minute (Monitoring MetricSets every ten minutes); the monthly usage level is the average.
  • RUM: total Sessions in the month. A Session lasts at most 4 hours and expires after 15 minutes of inactivity.[3]
  • Synthetic Monitoring: total Browser, API and Uptime Test Runs in the month.
  • Database Monitoring: total Database Instances monitored in the month.
  • Secure Application: average daily event volume in GB over the month.
  • Agent Observability (cloud): Spans, Luna Tokens and fine tunes per year.

Monthly metrics follow calendar months and are prorated in the first and last month of the subscription.[1] Because Infrastructure Monitoring and APM use monthly averages, short spikes in hosts or containers are smoothed, while sustained growth raises the monthly level.

Overage

If any monthly usage level exceeds the Subscription Limits, the customer “agrees to pay Splunk an overage fee … calculated as 150% of the effective list price”, or Splunk may instead stop the customer adding new monitors until usage conforms. If usage significantly exceeds the limits at any time, Splunk may limit new monitors regardless of the monthly level (rule).[1]

Virtualization & partitioning

A Host is any virtual machine or physical server being monitored; the terms do not distinguish hypervisor hosts from guests, so each monitored virtual machine is a Host. Containers and serverless functions are counted against per-host allowances rather than as hosts.[2][1]

Cloud / BYOL

Observability Cloud is a Splunk-hosted service with its own service level schedule and security exhibit. It is not PCI-DSS-certified, and customers are responsible for notice and consent for data collected about individuals.[2] A Splunk Business Associate Agreement applies to Observability Cloud.[2] As a hosted service, Customer Content is available for 30 days after termination before deletion.[6]

Programs

Observability Cloud Enterprise Edition qualifies for Success Plan OnDemand Services and Education credits from 200 infrastructure hosts, 100 infrastructure-and-application hosts or 100 end-to-end hosts (Standard plan) and 500, 300 or 300 hosts (Premium plan); a la carte and commercial-edition observability products do not include those credits.[5] Splunk Agent Observability on-premises minor versions are supported for 24 months.[7]

Out of scope

Splunk IT Service Intelligence is covered in Splunk Enterprise Security and ITSI licensing. Splunk AppDynamics licensing is published separately on docs.appdynamics.com.[3] The free edition is governed by separate Splunk Observability Free Edition terms.[2]

References

  1. Observability Cloud Usage, Subscription Limits Enforcement, and EntitlementsLast updated September 2026 (no day stated); prior versions April 2026, February 2024, October 2023. Catalog: Observability Cloud Usage, Subscription Limits Enforcement, and EntitlementsRetrieved 2026-10-02.
  2. Splunk Specific Terms for Splunk Offerings and Hosted ServicesLast updated September 2026 (no day stated); Splunk Observability Cloud definitions. Catalog: Splunk Specific Terms for Splunk Offerings and Hosted ServicesRetrieved 2026-10-02.
  3. Splunk Offerings Purchase Capacity and LimitationsLast updated September 2026 (no day stated). Catalog: Splunk Offerings Purchase Capacity and LimitationsRetrieved 2026-10-02.
  4. Pricing (Splunk)Not date-stamped; starting prices. Catalog: Pricing (Splunk)Retrieved 2026-10-02.
  5. Splunk Success PlansNot date-stamped. Catalog: Splunk Success PlansRetrieved 2026-10-02.
  6. Splunk General TermsLast Updated: May 2026. Catalog: Splunk General TermsRetrieved 2026-10-02.
  7. Splunk Support PolicyLast Updated: August 2026. Catalog: Splunk Support PolicyRetrieved 2026-10-02.

See also

Catalog Rows Cited

5SKUs9Metrics3Rules1Programs

Esc