Company Overview
Splunk was founded in 2003 by Michael Baum, Rob Das, and Erik Swan in San Francisco, California, pioneering the machine data analytics and Security Information and Event Management (SIEM) market. Splunk's mission is to make machine data accessible, usable, and valuable — by ingesting, indexing, searching, and analyzing data from servers, networks, applications, cloud services, and security devices to deliver real-time operational and security intelligence.
Splunk went public on NASDAQ in 2012 (ticker: SPLK), becoming the first publicly traded company focused exclusively on machine data analytics. In 2024, Cisco completed its acquisition of Splunk for approximately $28 billion, integrating Splunk's security and observability capabilities into Cisco's full-stack product portfolio.
Related providers: Splunk Observability
Core Products
- Splunk Enterprise: Core machine data platform with high-speed indexing, SPL search, dashboards, alerting, and reporting. Supports on-premises and self-hosted deployments
- Splunk Cloud: Fully managed cloud service running on AWS, providing the full Splunk Enterprise feature set with compliance support and elastic scalability
- Splunk Security (SIEM): Enterprise-grade SIEM solution including Splunk Enterprise Security (ES) — the market-leading SIEM product offering threat detection, incident investigation, compliance reporting, and User Behavior Analytics (UBA)
- Splunk SOAR (formerly Phantom): Security Orchestration, Automation and Response platform using playbooks to automate security incident investigation and response workflows
- Splunk IT Service Intelligence (ITSI): AI-driven IT operations analytics (AIOps) platform using machine learning for service health scoring, anomaly detection, and intelligent alerting
- Splunk Observability: Full-stack observability combining infrastructure monitoring, APM, log management, and digital experience management (gained through SignalFx and Omnition acquisitions)
- Splunk User Behavior Analytics (UBA): User and entity behavior analytics using machine learning to detect insider threats and account compromise
- Splunk Data Stream Processor (DSP): Real-time data stream processing engine for filtering, routing, and enriching data before it reaches Splunk
- Splunk Add-on Ecosystem: Thousands of pre-built integrations and data onboarding add-ons covering major IT, security, and cloud platforms
Core Strengths
Machine Data Pioneer: 20+ years of machine data collection, indexing, and search analysis with the most mature SPL (Search Processing Language)
SIEM Market Leader: Splunk ES has been a Gartner SIEM Magic Quadrant Leader for many consecutive years, widely deployed in SOCs
Cisco Ecosystem Integration: Post-acquisition, deeply integrated with Cisco's security portfolio (Cisco SecureX, Cisco XDR, Duo, Cisco Firewall)
Powerful Search Language: SPL (Search Processing Language) delivers highly flexible data querying, correlation, and visualization
Enterprise-Grade Reliability: Splunk Cloud offers 99.9% SLA, SOC 2 and FedRAMP certifications for stringent compliance requirements
SOAR Automation: Phantom (Splunk SOAR) provides 350+ out-of-the-box playbooks for automated security incident response
Key Milestones
- 2003: Founded by Michael Baum, Rob Das, and Erik Swan in San Francisco; developed the first machine data indexing engine
- 2006: Released Splunk 1.0, achieving real-time search and indexing of machine data
- 2007: Splunk 2.0 released, introducing the SPL search language
- 2009: Surpassed 1,000 customers; secured venture funding
- 2012: NASDAQ IPO (SPLK), raising $230M
- 2013: Annual revenue exceeded $100M; released Splunk Enterprise 6.0
- 2015: Launched Splunk Cloud managed cloud service
- 2018: Acquired Phantom (SOAR automation) and VictorOps incident management
- 2019: Acquired SignalFx and Omnition, entering the observability market
- 2020: Annual revenue surpassed $2B; launched Splunk Data Stream Processor
- 2021: Introduced Splunk Observability Cloud and unified observability solution
- 2023: Cisco announced $28B acquisition of Splunk
- 2024: Cisco completed acquisition; Splunk became a wholly owned subsidiary of Cisco
- 2026: Operating as the core brand of Cisco's Security and Observability business, continuing to serve global enterprises
Market Position
Splunk competes with the following providers in the machine data analytics and SIEM market:
- Elastic: The Elastic Stack (ELK) competes directly with Splunk in log analytics and search. Elastic attracts technical teams with its open-source strategy and lower TCO, while Splunk leads with mature enterprise features and SIEM capabilities
- Datadog: SaaS observability platform leader competing with Splunk Observability in infrastructure monitoring, APM, and log management. Datadog has grown rapidly in cloud-native observability market share
- Dynatrace: AI-driven observability platform competing with Splunk in APM and full-stack observability. Dynatrace differentiates with automation and Davis AI causal analysis
- CrowdStrike: Cloud-native endpoint security and SIEM platform (CrowdStrike Falcon). In SIEM and security analytics, CrowdStrike's Falcon Next-Gen SIEM competes with Splunk ES
- Sumo Logic: Cloud-native machine data analytics and SIEM platform serving mid-to-large enterprises with log management and security analytics, competing with Splunk Cloud in the cloud SIEM space