Splunk logo

AI visibility report

Splunk ranks #3 in Observability & Monitoring AI search.

Outside the top three on 20 of the 25 prompts buyers actually ask.

New Relic is cited on 10 of those losses.

25 prompts
6 platforms
Updated Jul 15, 2026 - refreshed weekly
Track Splunk daily

Free trial. Setup comes pre-filled for Splunk.

Track Splunk across these prompts daily.

Start free trial
12percent
Presence Rate
Low presence

#3 among 14 vendors · still absent from 88% of tracked prompt responses

Top-3 citations across 150 prompt × platform pairs

+0.43
Sentiment
-1.00.0+1.0
Positive
#3of 14

Peer Ranking

#1#14
Above averagein Observability & Monitoring

Key Metrics

Presence Rate12.0%
Share of Voice11.7%
Avg Position#19.7
Docs Presence0.7%
Blog Presence8.7%
Brand Mentions37.3%

Platform Breakdown

Grok
24%6/25 prompts
ChatGPT
16%4/25 prompts
Gemini Search
12%3/25 prompts
Google AI Mode
8%2/25 prompts
Bing Copilot
8%2/25 prompts
Perplexity
4%1/25 prompts

Visible, but narrative can improve. Splunk ranks #3 on presence but #10 on sentiment. The brand appears relatively often, but competitors may be getting more favorable language when they appear.

Where Splunk is losing

Prompts where competitors are visible and Splunk is not.

These prompt-level losses are the first prompts to track and repair.

Where Splunk is winning2

  • What log shipping tools work best for getting structured logs from containerized applications to an observability platform without code changes?

    Avg # 1.0 · 1 platform

  • Which observability platforms have the best alert management features to help teams reduce alert fatigue through smart routing and thresholds?

    Avg # 7.0 · 1 platform

Where Splunk is losing5

  • Which observability platforms support real user monitoring alongside backend APM for correlating frontend and backend performance?

    Competitors on 4 platforms

    Track this prompt
  • Which APM tools integrate best with cloud provider managed databases and serverless functions for end-to-end visibility?

    Competitors on 3 platforms

    Track this prompt
  • What observability platforms can a small engineering team realistically get to meaningful dashboards and alerting on quickly?

    Competitors on 3 platforms

    Track this prompt
  • Which monitoring platforms have the best anomaly detection — automatically surfacing regressions without manual threshold tuning?

    Competitors on 2 platforms

    Track this prompt
  • Which observability platforms have the best ad-hoc query experience for high-cardinality log data during an active incident?

    Competitors on 2 platforms

    Track this prompt

Track Splunk daily before the next report refresh.

Track these gaps
Research dossierCapabilities, use cases, sources, reviews, pricing, and FAQ

Overview

Splunk is an enterprise data analytics and observability platform, originally founded in 2003 and acquired by Cisco in March 2024 for approximately $28 billion. It enables organizations to collect, index, search, analyze, and visualize machine-generated data from virtually any source at scale. Its platform spans security information and event management (SIEM), security orchestration and automated response (SOAR), full-stack observability, IT service intelligence, and application performance monitoring. Serving over 15,000 customers across 110 countries—including 89 of the Fortune 100—Splunk is deployed across on-premises, cloud, and hybrid environments. It is recognized as a Gartner Magic Quadrant Leader in both SIEM and Observability Platforms, positioning itself as a unified platform for enterprise digital resilience.

Splunk delivers a unified data platform spanning observability and security. Core offerings include Splunk Enterprise (self-managed), Splunk Cloud Platform (SaaS), Splunk Observability Cloud (full-stack APM, infrastructure, RUM, synthetic monitoring), Splunk Enterprise Security (SIEM), Splunk SOAR, and IT Service Intelligence (ITSI with AIOps). Post-Cisco acquisition, AppDynamics was merged into the Splunk observability unit. The platform is built on a schema-on-read architecture with OpenTelemetry-native support, AI/ML analytics, and a 2,000+ integration ecosystem via Splunkbase.

Key Facts

Founded
2003
HQ
San Francisco, CA, USA
Founders
Michael Baum, Rob Das, Erik Swan
Employees
5001-10000
Funding
~$40M (pre-IPO VC); acquired by Cisco fo
Customers
15,000+
Status
Subsidiary of Cisco (NASDAQ: CSCO)

Target users

Enterprise security operations center (SOC) analysts and CISOsIT operations and SRE teams managing hybrid or multi-cloud infrastructureDevOps and platform engineering teams monitoring distributed applicationsCompliance and risk management teams in regulated industriesFortune 500 and large public-sector organizations requiring scalable data governanceManaged security service providers (MSSPs) building SOC platforms

Key Capabilities9

  • Search Processing Language (SPL) for ad-hoc machine data search and analytics
  • Full-stack observability: APM, infrastructure monitoring, RUM, synthetic monitoring, distributed tracing (NoSample™)
  • SIEM with real-time threat detection, correlation, and MITRE ATT&CK mapping (Splunk Enterprise Security)
  • SOAR for automated security orchestration and response playbooks
  • AIOps with anomaly detection, alert noise reduction, and predictive analytics (IT Service Intelligence)
  • Log management at petabyte scale with schema-on-read indexing
  • Customizable dashboards, visualizations, and compliance reporting
  • AI/ML-powered analytics including natural language query and GenAI assistant
  • Hybrid and multi-cloud deployment (on-premises, SaaS, or private cloud)

Key Use Cases8

  • Security operations center (SOC) monitoring and incident response
  • Application performance monitoring and microservices troubleshooting
  • IT infrastructure monitoring and AIOps-driven outage prevention
  • Compliance reporting (PCI-DSS, HIPAA, GDPR, NIST, ISO 27001)
  • Fraud detection and behavioral analytics
  • Cloud migration monitoring and hybrid-cloud observability
  • Digital experience monitoring (real user and synthetic)
  • Log aggregation and root-cause analysis across distributed systems

Splunk customer outcomes

Singapore Airlines

75%+ faster issue detection; 90% fewer backend issues

Deployed Splunk to improve system monitoring and reduce application-layer failures, enabling faster detection and resolution of customer-facing issues.

Specsavers

10x faster MTTR; 25,000 hours saved per month

Adopted Splunk for observability and automation, dramatically reducing mean time to resolution and freeing engineering capacity.

Carrefour

3x faster threat response times

Consolidated legacy SIEM tools into Splunk Cloud Platform, enabling the SOC to detect and respond to security threats significantly faster.

Rent the Runway

94% faster MTTR for SLA-impacting incidents; 50% increased developer efficiency during incidents

Increased adoption of Splunk Observability Cloud eliminated outages and dramatically reduced time to resolve SLA-impacting incidents.

PXP

99.996% uptime sustained over 4 years

Used Splunk Cloud Platform to correlate performance data across a complex payment infrastructure, maintaining industry-leading uptime standards.

Recent Trend

Visibility-1.2 pts
Avg position-2.62
Sentiment+0.09

How AI describes Splunk3

Splunk Observability Cloud delivers full-stack observability with support for integrating high-volume business events to monitor the health of critical customer-facing transactions.

What's the quickest distributed tracing platform to set up across a microservices architecture on a container orchestration platform?

google-ai-modeDirect Splunk mention
Splunk : Supports OTLP and contributes to the OTel ecosystem. * Elastic (ELK) : Supports OTLP through their Elastic Agent or directly into Elasticsearch.

Which observability platforms integrate with deployment pipelines to correlate performance regressions with specific code changes?

google-ai-modeDirect Splunk mention
Splunk Observability Cloud : Considered the go-to for petabyte-scale stream processing and high-volume, real-time log analysis.

Which monitoring platforms have the best anomaly detection — automatically surfacing regressions without manual threshold tuning?

google-ai-modeDirect Splunk mention

Alternatives in Observability & Monitoring6

Splunk, now a Cisco subsidiary, positions itself as the enterprise-grade unified platform for both security and observability—the only vendor named a Gartner Magic Quadrant Leader in both SIEM and Observability Platforms simultaneously.

  • Its differentiation rests on decades of machine-data expertise, the proprietary Search Processing Language (SPL), a 2,000+ app Splunkbase ecosystem, and Cisco network/telemetry integration.
  • It targets large enterprises and regulated industries that require deep data governance, hybrid/on-prem deployment flexibility, and combined SecOps + ITOps workflows under one platform—areas where cloud-native-only rivals like Datadog or Honeycomb typically do not compete.
View category comparison hub

Reviews

Praised

  • Powerful SPL search and query flexibility
  • Real-time log correlation across disparate sources
  • Highly customizable dashboards and visualizations
  • Broad data source integrations via Splunkbase
  • Scalability for enterprise-scale data volumes
  • Strong SIEM and compliance reporting capabilities
  • Reliable Universal Forwarder architecture
  • Active community and extensive documentation

Criticized

  • High and unpredictable cost as data ingestion scales
  • Steep SPL learning curve for new users
  • Complex initial setup requiring significant expertise
  • Uncertainty around product roadmap post-Cisco acquisition
  • Limited dashboard customization for non-technical users
  • Risk of budget overruns during high-traffic spikes with ingest pricing
  • Heavy reliance on internal SMEs or professional services

Splunk receives consistently high marks for its powerful search capabilities (SPL), data ingestion breadth, and dashboard flexibility, with G2 reviewers rating Splunk Enterprise 4.3/5 and Gartner Peer Insights users awarding 4.4/5 across 842 SIEM reviews. Enterprise Security earns 4.5/5 from 390+ Gartner reviews. TrustRadius reviewers rate Splunk ES at 8.4/10. Common praise focuses on real-time visibility, log correlation, and compliance automation; common criticisms center on high and unpredictable costs at scale, a steep SPL learning curve, complex initial setup, and some post-Cisco acquisition uncertainty around roadmap and pricing strategy.

Pricing

Splunk does not publish standard list prices and requires contacting sales for all paid tiers. The platform offers three core pricing models: Ingest Pricing (charged per GB/day of data indexed, estimated at ~$1,800–$18,000/year for 1–10 GB/day), Workload Pricing (charged per compute unit, suited for variable search workloads), and Entity Pricing (per-host for observability products). A free tier is available capped at 500MB/day with limited features. Observability Cloud offers a 14-day free trial. Enterprise contracts are annual or multi-year; multi-year commitments can yield 20–30% discounts. Third-party data suggests a median customer pays approximately $60,000/year, with significant variance. Implementation, infrastructure, and professional services add 30–50% to total cost of ownership.

Limitations

  • Splunk's ingest-based pricing model is widely cited as expensive at scale—costs rise sharply with data volume, making it cost-prohibitive for smaller organizations or those with high-cardinality telemetry.
  • The Search Processing Language (SPL) has a steep learning curve, often requiring dedicated expertise.
  • Initial implementation and ongoing administration can demand significant internal resources or third-party services.
  • Some users report limited customization in dashboarding and query UI for non-power users.
  • Post-Cisco acquisition, some customers and partners have raised uncertainty about long-term product roadmap and pricing direction.

Frequently asked questions

Topic coverageCoverage by buyer topic

Topic Coverage

Capability3/5DevEx2/5Integrations &Ecosystem4/5Performance &Reliability1/5Setup & First Run1/5

Prompt-Level Results

Brand citedCompetitor citedNot cited
PromptGoogle AI ModeGemini SearchBing CopilotChatGPTPerplexityGrok
Capability3/5 cited (60%)

Which observability platforms support business-level metrics like conversion funnels alongside infrastructure and application telemetry?

Which monitoring platforms have the best anomaly detection — automatically surfacing regressions without manual threshold tuning?

I'm evaluating observability platforms — which ones are best suited for a logs-first approach versus a traces-first approach?

Which enterprise observability platforms handle multi-tenant environments with isolated views per team or service best?

Which observability platforms support real user monitoring alongside backend APM for correlating frontend and backend performance?

Developer Experience2/5 cited (40%)

Which observability platforms have the best ad-hoc query experience for high-cardinality log data during an active incident?

Which observability platforms have the best alert management features to help teams reduce alert fatigue through smart routing and thresholds?

Which observability platforms make it easiest for developers new to OpenTelemetry to adopt a trace-first workflow?

Which observability platforms make it easiest to correlate a user-reported error with the right trace and log lines in a distributed system?

Which monitoring platforms offer the best on-call experience — from alert firing through to root cause identification?

Integrations & Ecosystem4/5 cited (80%)

Which APM tools integrate best with cloud provider managed databases and serverless functions for end-to-end visibility?

Which observability backends support receiving OpenTelemetry data simultaneously to avoid vendor lock-in?

Which observability platforms integrate with deployment pipelines to correlate performance regressions with specific code changes?

Which observability platforms integrate best with incident management and on-call scheduling tools for a seamless response workflow?

What log shipping tools work best for getting structured logs from containerized applications to an observability platform without code changes?

Performance & Reliability1/5 cited (20%)

What observability platforms offer the best tail-based sampling for high-throughput systems to control costs without losing important traces?

Which SaaS monitoring platforms have the lowest ingestion lag during high-volume log bursts so alerting stays fast?

Which observability platforms handle data retention and query performance best as log volume grows into terabytes per day?

Which cloud observability platforms have the most reliable synthetic monitoring checks with the lowest false positive rates?

Which distributed tracing platforms add the least overhead to latency-sensitive APIs — safe to run in production at full sampling?

Setup & First Run1/5 cited (20%)

What's the quickest distributed tracing platform to set up across a microservices architecture on a container orchestration platform?

What are the best cloud-hosted observability platforms for migrating from a legacy self-hosted logging stack without losing historical data?

What observability platforms support unified metrics, traces, and logs instrumentation for Node.js and Python polyglot applications?

What observability platforms can a small engineering team realistically get to meaningful dashboards and alerting on quickly?

Which APM tools have the best day-one onboarding to get immediate value without drowning in noise?

Turn this matrix into daily prompt monitoring.

Track prompt changes

Vertical Ranking

#BrandPres.SoVDocsBlogMent.PosSentiment
1New Relic21.3%19.2%2.0%19.3%58.0%#14.7+0.44
2Datadog15.3%18.5%4.7%9.3%76.0%#16.2+0.38
3Splunk12.0%11.7%0.7%8.7%37.3%#19.7+0.43
4Grafana10.0%10.0%5.3%3.3%8.7%#26.1+0.50
5Honeycomb8.7%10.3%2.0%5.3%38.0%#24.3+0.55
6Dynatrace8.0%12.5%6.0%3.3%53.3%#40.9+0.35
7Better Stack6.7%5.7%0.7%0.7%8.0%#13.5+0.42
8Logz.io4.7%2.8%0.0%4.0%4.7%#9.6+0.45
9Coralogix4.0%2.8%0.0%0.0%5.3%#6.6+0.62
10Elastic4.0%3.9%0.7%1.3%26.7%#28.4+0.53
11Chronosphere1.3%1.1%0.0%0.0%4.7%#21.7+0.55
12Axiom0.7%1.1%0.0%0.7%4.0%#74.7+0.80
13Mezmo0.7%0.4%0.7%0.0%0.7%#75.0+0.80
14Sentry0.0%0.0%0.0%0.0%6.7%

Turn this into your team dashboard

Sign up to unlock project-level analytics, daily tracking, actionable insights, custom prompt configurations, adoption tracking, AI traffic analytics and more.

Free trial. Setup comes pre-filled from this report.

Get started free