Short answer: Splunk does not publish a price for Splunk Cloud Platform or Splunk Enterprise. It quotes them. The closest public reference is reseller listings on AWS Marketplace. One lists a 12-month Splunk Enterprise term license with Standard Success Plan at $2,277 per GB/day for 1 GB/day, falling to $759 per GB/day at 100 GB/day and $575 per GB/day at 5,000 to 9,999 GB/day. At those list prices, a 100 GB/day license is $75,900 a year before any discount. The only Splunk products with prices on splunk.com are Observability Cloud, AppDynamics and On-Call.
This guide explains the four pricing models Splunk sells, exactly what the ingest meter counts, the list prices you can verify yourself, and a worked example of the cost math. Figures were checked against Splunk’s own pages and the AWS Marketplace listing on 27 September 2026. Your quote will differ; list prices are where a negotiation starts.
Splunk’s Four Pricing Models
Splunk’s pricing models page describes four ways to buy:
| Model | What it meters | Sold for |
|---|---|---|
| Ingest | Gigabytes of data ingested per day | Splunk Cloud Platform, Splunk Enterprise, Enterprise Security, ITSI |
| Workload | Compute and storage needed to run search and analytics | Splunk Cloud Platform, Splunk Enterprise, Enterprise Security, ITSI |
| Activity-based | Both ingest and search activity | Splunk Cloud Platform |
| Entity | Monitored hosts, containers and protected devices | Splunk Observability Cloud, Splunk AppDynamics |
Splunk’s own guidance on fit: workload pricing is “ideal when you need to store data that you search and analyze rarely”, ingest pricing is “ideal when your data strategy aligns to data value”, and activity-based pricing suits “users with more complex, unpredictable workloads”. All three platform models allow unlimited users.
The model you choose decides which lever lowers your bill. Under ingest pricing, the lever is data volume. Under workload pricing, it is compute.
Ingest Pricing: What the Meter Counts
Ingest pricing charges for a daily volume entitlement, bought as a term contract. Splunk’s documentation on how Splunk Enterprise licensing works is specific about what counts:
- The meter measures “the raw data that is placed into the indexing pipeline”, not compressed data on disk.
- Data “filtered and dropped prior to indexing does not count against the license volume quota.”
- Splunk’s internal logs (
_internal,_introspection), summary indexes and metric rollups do not count. - Each metrics event counts as its size plus 18 bytes, capped at 150 bytes.
Daily volume is measured midnight to midnight on the license manager’s clock.
Going over your entitlement
The two platforms treat overages differently.
Splunk Cloud Platform. The service description says you “can exceed your purchased daily index volume a maximum of five times in a calendar month.” Past that, your Splunk sales representative may work with you to reduce usage or buy an increase.
Splunk Enterprise. Each day over the limit generates a license warning. For license stacks under 100 GB/day, 45 warnings in a rolling 60-day window is a license violation, and search is disabled until it clears; indexing continues. Stacks of 100 GB/day or more get warnings, but search is not disabled.
Storage on Splunk Cloud
An ingest-based Splunk Cloud Platform subscription is sized on uncompressed daily volume and includes enough searchable storage (DDAS) to keep up to 90 days of that data. Splunk’s example: 100 GB/day comes with 9,000 GB of DDAS. Longer retention means buying more DDAS, or adding the optional archive tier (DDAA), in 500 GB increments.
Published List Prices per GB/day
The AWS Marketplace listing referenced above is one of the few places where Splunk platform prices are public. It is sold by a reseller, BYNET, on a 12-month contract, and covers Splunk Enterprise (self-managed) with the Standard Success Plan. Treat it as a list-price reference, not a quote.
| Licensed volume | Price per GB/day | Annual cost at tier minimum |
|---|---|---|
| 1 GB/day | $2,277.00 | $2,277 |
| 10 to 19 GB/day | $1,265.00 | $12,650 |
| 50 to 99 GB/day | $961.40 | $48,070 |
| 100 to 199 GB/day | $759.00 | $75,900 |
| 200 to 499 GB/day | $733.70 | $146,740 |
| 500 to 999 GB/day | $644.00 | $322,000 |
| 1,000 to 1,999 GB/day | $621.00 | $621,000 |
| 5,000 to 9,999 GB/day | $575.00 | $2,875,000 |
The listing also has tiers for 2 to 4, 5 to 9, 20 to 49 and 2,000 to 4,999 GB/day. The listing’s own default offer, 50 GB/day, is priced at $48,070.
Two things stand out. The unit price falls steeply up to about 100 GB/day and flattens after that. And the tier boundaries matter: as the listing presents it, 99 GB/day at $961.40 costs $95,178.60, while 100 GB/day at $759.00 costs $75,900. Check where your volume sits against the tiers in your own quote before you negotiate.
Splunk Cloud Platform is not priced on that listing. Splunk’s own AWS Marketplace listing for Splunk Cloud offers custom pricing through a private offer only.
Workload Pricing: SVCs and vCPUs
Workload pricing stops metering ingest and charges for capacity instead.
On Splunk Cloud Platform, capacity is sold in Splunk Virtual Compute units. Splunk defines an SVC as “a unit of cloud compute, memory and I/O resources”, mainly driven by search quantity and complexity and by daily indexing volume. The service description is explicit: “Workload-based subscriptions do not meter ingestion.” You can raise ingest or search load until your SVC entitlement is fully used.
On Splunk Enterprise, workload licensing counts vCPUs. The licensing documentation says the total vCPU count across all Splunk Enterprise search heads and indexers counts toward licensed capacity, where a vCPU is any logical core the operating system reports.
Splunk does not publish an SVC or vCPU price, so there is no public figure to model with. What you can model is the trade: workload pricing favors heavy ingest with light search, and it removes the daily-volume ceiling. Under workload pricing, cutting ingest lowers cost only to the extent it lets you run on fewer SVCs or vCPUs, or buy less storage.
Add-Ons, Observability and Free Options
Premium apps are licensed separately. Splunk Enterprise Security and IT Service Intelligence (ITSI) are licensed on top of the platform. The same AWS Marketplace listing prices ITSI from $3,162.50 per GB/day at 1 GB/day to $600.88 per GB/day at 50 to 99 GB/day. No comparable public list price exists for Enterprise Security; it is quoted.
Observability Cloud uses entity pricing and is the one line Splunk publishes. The pricing page lists Infrastructure from $15, App and Infra from $60, and End-to-End from $75 per host per month, billed annually.
Free and trial options. A new Splunk Enterprise install runs a 60-day Enterprise Trial license, and a Splunk Cloud Platform trial runs 14 days. After that, Splunk Free indexes up to 500 MB per day. It has no alerting, no user authentication or roles, no distributed search and no clustering, and three license warnings in a rolling 30 days blocks search.
A Cost Model You Can Reuse
For ingest pricing, the license line of the budget is simple:
Annual license = licensed GB/day × price per GB/day at that tier
The total cost of ownership adds everything around the license:
- Premium apps such as Enterprise Security or ITSI, each with its own meter.
- Retention beyond the included amount. On Splunk Cloud that is extra DDAS or DDAA; on Splunk Enterprise it is your own storage.
- Infrastructure for Splunk Enterprise: indexers, search heads, forwarder management and the storage behind them. Workload licensing counts the vCPUs on the indexers and search heads.
- People to run it, and support beyond the tier in your contract.
- Growth. A license is an entitlement for the contract term, so today’s volume sets the price until the next purchase.
Worked example
Assumptions: a Splunk Enterprise customer licensed at 500 GB/day, priced at the list rates in the table above with no discount. An audit of their searches, alerts and retention rules finds that 40% of daily volume is DEBUG logging, load balancer health checks and duplicate events that nothing uses. The 40% is an assumption for the example, not a benchmark. Your own number has to come from your own data.
| Licensed volume | Tier price | Annual license | |
|---|---|---|---|
| Today | 500 GB/day | $644.00 | $322,000 |
| After removing the unused 40% | 300 GB/day | $733.70 | $220,110 |
The license falls from $322,000 to $220,110 a year, a 32% reduction for a 40% cut in volume. The saving is smaller than the volume cut because 300 GB/day drops into a tier with a higher unit price. It also arrives only when you buy the smaller entitlement, which on a term license means at renewal.
Run the same exercise on the terms of your own contract. The ROI calculator takes your node count, volume per node, license rate and the share of data that is worth indexing, and projects the difference over one, three and five years. Its license rate is dollars per TB ingested per year, so divide an annual price per GB/day by 0.365 (the $644 tier is about $1,764 per TB per year). The calculator applies one flat rate, so it will not show the tier effect the worked example shows.
Lowering the Bill: Where the Volume Goes
Because data dropped before indexing is not metered, the most direct way to lower an ingest-priced bill is to decide, per source, what Splunk actually needs to index. The options sit at different points in the pipeline:
- Inside Splunk: retention tuning per index, summary indexing for repeated reports, and fixing sourcetype line-breaking so events are not duplicated or fragmented.
- At Splunk’s edge: routing events to
nullQueuewithprops.confandtransforms.confon heavy forwarders or indexers, Ingest Actions, or the Edge Processor solution, which Splunk describes as providing “filtering, masking, and routing functionality.” - Before the data reaches Splunk at all: a pipeline running next to the source that filters, samples or summarizes events and sends only what is needed to the HTTP Event Collector.
How to Reduce Splunk Costs Without Losing Visibility walks through each of these in detail, and Splunk Edge Processor vs Upstream Data Control compares the last two.
Whichever you use, the rule is the same: filtering must not remove events that detections, investigations, audits or retention obligations depend on. List those event classes first, and have the teams that own them approve the change.
Measure It With Expanso Before You Commit
Expanso runs data pipelines on nodes you choose, including next to the log source, so a filter can drop noise before it crosses the network or reaches Splunk. It is priced per node, not per GB: the first five nodes are free, and Pro is $50 per active node per month with no volume charges.
The job below reads an application log once and then stops (restart_policy: never), drops DEBUG lines and /healthz checks, and sends everything else to Splunk’s HTTP Event Collector in batches of up to 100 events. It uses only the documented file input and http_client output. HEC accepts several JSON event objects stacked in one request and authenticates with an Authorization: Splunk <token> header, as described in Splunk’s HEC event format documentation.
name: splunk-hec-filter
type: pipeline
restart_policy: never
selector:
match_labels:
pipeline_role: splunk_filter
config:
input:
file:
paths: ["/var/log/app/app.log"]
scanner:
lines: {}
pipeline:
processors:
- mapping: |
let line = content().string()
let noise = $line.contains(" DEBUG ") || $line.contains("GET /healthz")
root = if $noise { deleted() } else {
{"event": $line, "sourcetype": "app:log", "host": hostname()}
}
output:
http_client:
url: "${SPLUNK_HEC_URL}/services/collector/event"
headers:
Authorization: "Splunk ${SPLUNK_HEC_TOKEN}"
Content-Type: application/json
batching:
count: 100
period: 1s
processors:
- archive:
format: lines
To use it:
- Replace
/var/log/app/app.logwith a real log on the node, and change the two match conditions to the noise in your own source. - Start the Expanso Edge agent on that node with
SPLUNK_HEC_URL(for examplehttps://your-splunk-host:8088) andSPLUNK_HEC_TOKENset in its environment. The${...}values resolve on the node when the job runs. Give the node the labelpipeline_role: splunk_filter, or change the selector to a label it already has. - Check the job, deploy it, and confirm an execution was assigned to your node:
expanso-edge validate splunk-hec-filter.yaml
expanso-cli job deploy splunk-hec-filter.yaml
expanso-cli execution list --job-id JOB_ID
The Deploy to Cloud guide covers creating a workspace, starting a node and connecting the CLI.
What we ran. We ran this job, with only the file path changed, on an expanso-edge v2.1.21 node in local mode against a stub HEC receiver that required the token. The input was a synthetic 1,000-line log built to be 50% DEBUG lines and 25% health checks. The receiver got 250 events in three batched requests: all 200 API request lines and all 50 errors, and no DEBUG or health-check lines. Because the log was built to be 75% noise, that ratio is the input’s, not a result. We did not send it to a live Splunk instance.
Check the count in Splunk, not the job state. In a second run with a wrong token, every request was rejected with 401, and the job still ended completed. The agent logged each failure, but a finished job is not proof of delivery. Compare the lines kept against the events in the index your HEC token writes to, for example with sourcetype=app:log | stats count.
The log reduction recipe goes further: it keeps every error as its own event and collapses successful requests into per-minute counts.
Start with one source and a baseline. The Splunk cost-optimization page sets out how to run a bounded evaluation: record source volume and current Splunk cost, measure what is retained, validate alerts and searches, then decide whether to expand. If you want help scoping it, book a data consultation and bring your daily ingest by sourcetype.
Related Articles
- How to Reduce Splunk Costs Without Losing Visibility
- Splunk Architecture Explained: Components, Data Flow, and Optimization
- Splunk Edge Processor vs Upstream Data Control
- What Is an Observability Pipeline?
- SIEM Cost Comparison: Why Your Bill Keeps Growing
FAQ
How much does Splunk cost?
Splunk quotes its platform prices rather than publishing them. One public reference, a reseller’s 12-month Splunk Enterprise term license on AWS Marketplace, lists $2,277 per GB/day at 1 GB/day, $759 per GB/day at 100 GB/day and $575 per GB/day at 5,000 GB/day or more. That puts a 100 GB/day license at $75,900 a year at list price. Premium apps, infrastructure and extra retention cost more.
How much does Splunk cost per GB?
Under ingest pricing, Splunk charges per GB of daily volume for the contract term, not per GB stored. On the public AWS Marketplace listing, the annual price per GB/day ranges from $2,277 at 1 GB/day down to $575 at 5,000 to 9,999 GB/day. The unit price falls with volume, so the effective rate depends on your tier.
What is Splunk workload pricing?
Workload pricing charges for the compute and storage needed to run searches and analytics instead of for ingest. On Splunk Cloud Platform it is sold in Splunk Virtual Compute units (SVCs), and workload subscriptions do not meter ingestion. On Splunk Enterprise it counts the vCPUs on search heads and indexers. Splunk does not publish SVC or vCPU prices.
Is Splunk Cloud cheaper than Splunk Enterprise?
There is no public answer, because Splunk Cloud Platform is priced by private quote. Splunk Cloud includes the infrastructure and up to 90 days of searchable storage in an ingest subscription. Splunk Enterprise needs your own indexers, search heads, storage and administrators on top of the license. Compare quotes on the same volume, retention and apps.
Is there a free version of Splunk?
Yes. Splunk Free indexes up to 500 MB per day, without alerting, authentication, distributed search or clustering. Splunk Enterprise includes a 60-day trial license, and Splunk Cloud Platform offers a 14-day trial.
Does filtered data count against my Splunk license?
Not if it is dropped before indexing. Splunk’s documentation states that data “filtered and dropped prior to indexing does not count against the license volume quota.”
