Quick Answer
Splunk Cloud pricing in 2026 lists at $675 per month for Ingest Pricing 5 GB/day (about $8,100 per year), and $2,000 per month for 20 GB/day (about $24,000 per year). Workload Pricing using Splunk Virtual Compute (SVC) units is custom-quoted. Annual subscriptions include 90 days of indexed data storage and unlimited users (Splunk pricing page, July 2026).
The single most important budgeting decision is whether to commit to Ingest Pricing or Workload Pricing. Ingest Pricing rewards predictable volume; Workload Pricing rewards variable search complexity.
Last verified: Sep 15, 2026.
At a glance
- Ingest Pricing 5 GB/day $675 per month (~$8,100 per year)
- Ingest Pricing 20 GB/day $2,000 per month (~$24,000 per year)
- 10 GB/day approximately $36,500 per year
- Workload Pricing (SVC) custom quote
- 90 days indexed storage included in annual subscriptions
- Unlimited users across all Splunk Cloud plans
Splunk pricing models and what each is best for
Splunk now offers four pricing models: Ingest, Workload, Activity-based, and Entity. Ingest Pricing is the traditional volume-based model: customers pay per GB per day of data sent into Splunk. Workload Pricing uses Splunk Virtual Compute units (SVCs) measured against compute power. Activity-based pricing meters user search activity. Entity pricing meters the number of monitored entities (servers, applications, devices) (Splunk pricing models page, July 2026).
| Pricing model | Unit | Best fit | Indicative price |
|---|---|---|---|
| Ingest Pricing | GB per day | Data-value-aligned strategies; predictable volume | $1,620/GB/yr at 5 GB/day scaling to $432/GB/yr at 100 GB/day |
| Workload Pricing (SVC) | Virtual compute units | Variable search workloads, complex search patterns | Custom quote |
| Activity-based | User search activity | Organizations with high user counts and low search frequency | Custom quote |
| Entity Pricing | Monitored entities | IT operations use cases, asset-based licensing | Custom quote |
The jump from Ingest to Workload Pricing changes the cost structure more than the unit price suggests. Workload Pricing is harder to predict upfront because the SVC calculation is not transparent. Splunk tends to recommend higher SVC counts initially, which can lead to over-buying in year one (costbench.com, July 2026).
Worked examples at 5, 20, 100, and 1,000 GB per day
The effective per-GB rate drops sharply as total daily index volume grows. The table below uses published CostBench data and Splunk's published pricing model scaling rules to estimate annual list cost at four common scales (Splunk + CostBench, July 2026).
| Daily ingest | Per-month cost (Ingest) | Annual list cost | Effective rate per GB/day per year |
|---|---|---|---|
| 5 GB/day | $675 | $8,100 | $1,620/GB/yr |
| 20 GB/day | $2,000 | $24,000 | $1,200/GB/yr |
| 100 GB/day | Custom quote | ~$50,000 to $90,000 | $500 to $900/GB/yr |
| 1,000 GB/day (1 TB) | Custom quote | $400,000 to $900,000 | $400 to $900/GB/yr |
Splunk publishes a 50 percent drop in unit price as daily ingest volume grows from 1 GB/day to 100 GB/day. A 1 TB/day enterprise deployment is typically negotiated between $400,000 and $900,000 per year depending on contract term, product mix, and Cisco security portfolio bundling. Splunk has been part of Cisco since March 2024, and many enterprise contracts now bundle Splunk with Cisco security products (costbench.com, July 2026).
Splunk Enterprise Security and add-on products
Splunk Enterprise Security (ES) is the security-focused SIEM layer that runs on the same ingest or workload meter. ES pricing does not carry a separate per-GB rate; the ES capability is metered through the same pricing model that powers the base Splunk Cloud or Splunk Enterprise subscription. Customers buying ES typically pay the base Splunk platform license plus an ES-specific tier that bundles premium support, threat intelligence, and content updates (Splunk, September 2026).
Other Splunk add-on products include Splunk IT Service Intelligence (ITSI), Splunk User Behavior Analytics (UBA), and Splunk Observability Cloud. Each is sold as a separate line item with its own pricing structure. Cloud Flex is the recommended path for organizations running multiple Splunk products; it lets customers reallocate spend across products without restarting procurement (Splunk, September 2026).
Hidden costs and capacity management
Three predictable line items push the real first-year cost above the per-GB rate. Storage beyond the included 90 days is sold separately; customers needing 180 days or 365 days of indexed storage pay per-GB-per-day for the additional retention window. Premium support tier (24/7 SLA, faster response times) adds 10 to 20 percent to annual costs. Professional services for initial deployment typically run 20 to 40 percent of first-year license cost (Splunk, September 2026).
Splunk's published no-surprise overage policy is meaningful for budget planning: the company only charges overage fees when the customer consistently exceeds purchased capacity. Customers can extend beyond their subscription limits during critical incidents and adjust allocation through the Splunk Support Portal. The practical budgeting discipline is to monitor usage against the purchased tier and request a quota adjustment before the next billing cycle (Splunk, September 2026).
Edge Processors and Federated Search are the modern cost-control features worth evaluating. Edge Processors filter, redact, and route data before it impacts the ingest budget, reducing unnecessary ingestion by up to 60 percent in well-tuned deployments. Federated Search runs analytics against data living in Amazon S3 and other object stores without forcing costly data movement into the Splunk index. Together, these two features routinely save Splunk customers 30 to 50 percent on their annual bill once properly configured (Splunk, September 2026).









