Skip to content
    AIOps & ObservabilityLeaderCisco Platform

    Splunk (Cisco)

    Enterprise observability and security acquired by Cisco 2024

    Mkt Cap / ValAcq. $28B
    Revenue$3.7B Rev
    Growth+18% YoY
    May 2026: Cisco Q3 rev $15.8B +12%; AI orders raised to $9B; Splunk 500 H1 logos
    The broadest SIEM + observability + IT operations data platform under one roof — and now with Cisco's networking telemetry, Splunk can correlate infrastructure, application, and security signals across the entire enterprise stack.
    Analyst take · Competitive edge

    SWOT Analysis

    Strengths
    • Unmatched data ingestion breadth: any machine data, any format, at petabyte scale
    • SPL (Search Processing Language) gives power users extreme flexibility for custom analytics
    • Cisco acquisition brings network telemetry, TAC intelligence, and AppDynamics into the platform
    • ITSI (IT Service Intelligence) provides mature service-health and glass-table views
    • Dominant installed base — most Fortune 500 security and ops teams already have Splunk
    Opportunities
    • Cisco + Splunk full-stack platform could displace point solutions across security and observability
    • Galileo acquisition (Apr 2026): adds AI agent observability and guardrails for multi-agent system monitoring
    • AI-powered SPL copilot to democratize search for non-technical operations staff
    • Federal and critical infrastructure: Splunk's compliance certifications are industry-leading
    • ITSM + observability convergence: Cisco ThousandEyes + Splunk ITSI + AppDynamics bundle
    Weaknesses
    • Total cost of ownership is extremely high — licensing, infrastructure, and admin overhead
    • SPL has a steep learning curve; non-power users struggle to self-serve
    • Cloud migration from on-prem Splunk is complex and often takes 18–36 months
    • Product integration between Cisco and Splunk assets is still maturing post-acquisition
    Threats
    • Cloud-native competitors (Datadog, Dynatrace) winning new workloads before Splunk migration completes
    • Elastic and OpenSearch eroding SPL lock-in with open alternatives
    • Microsoft Sentinel gaining share as M365 customers consolidate on Microsoft security
    • Complexity and cost causing enterprise renewals to be contested

    User Sentiment

    Synthesized from G2, Gartner Peer Insights, and analyst review data.

    What users love
    • Splunk can ingest and search literally any data source — the flexibility is unmatched
    • ITSI glass tables give executives a clear real-time health view of IT services
    • Alert action framework allows rich automated responses tied to any search
    • Extensive app marketplace (Splunkbase) with thousands of community-built integrations
    • Battle-tested at scale: teams trust it for mission-critical 24/7 ops
    Common complaints
    • Licensing and infrastructure costs are extremely high — sticker shock is common at renewal
    • SPL requires significant training investment; casual users rarely become proficient
    • Search performance degrades on large datasets without careful index optimization
    • Heavy admin overhead: index management, forwarder upgrades, and capacity planning are time-consuming

    Pricing & TCO

    Analyst-synthesized pricing signals — directional only, contact vendor for current terms.

    ConsumptionVery High TCOContact Sales Free Trial / Tier

    Typical ACV (Mid-Enterprise)

    $250K–$3M ARR for enterprise security + observability

    Market Segments

    EnterpriseFortune 500

    Deployment

    SaaSOn-PremHybrid

    Key Cost Drivers

    • Daily log ingest volume (GB/day) is the primary cost driver
    • Workload pricing adds compute charges on top of ingest
    • Post-Cisco acquisition — licensing complexity and premiums increasing

    Industry benchmark with enterprise complexity — expect multi-year negotiations.

    Full comparison

    Customer Profile

    Who buys this

    Typical segments

    Fortune 500 EnterpriseGovernment & DefenseLarge FSI, Healthcare, and Retail

    Typical buyer

    CISO, VP IT Operations, SOC Director, or Enterprise Architect

    Top use cases
    1. 1Enterprise SIEM and security threat detection at scale
    2. 2IT service intelligence and business service health monitoring
    3. 3Compliance reporting and audit log retention for regulated industries

    Future Focus Areas

    1

    Galileo integration: real-time observability and guardrails for multi-agent AI systems in Splunk Observability Cloud

    2

    Splunk AI: natural-language search assistant to democratize SPL for all users

    3

    Full Cisco platform integration: merging ThousandEyes, AppDynamics, and Splunk data planes

    4

    Federated search across on-prem, cloud, and edge without centralizing all data

    5

    Mission Control: unified AIOps workspace combining observability and security in one view