
Now part of Cisco: the reference for SIEM and observability on logs — security and IT read in the machine data.
Splunk indexes any machine data — logs, metrics, events — and makes it queryable in real time with SPL. On top: Enterprise Security as the SIEM (correlations, risk-based alerting, SOAR) and Observability for applications and infrastructure. With the Cisco acquisition, network and security telemetry converges here.


Splunk is paid (also) by volume: sourcetypes, filters and retention designed upfront save the budget.
The correlations on YOUR environment: authentications, ransomware patterns, exfiltrations — not textbook rules.
The enrichment and containment playbooks: at night the automation answers.
Firewalls, ISE and the network inside: the incident's story complete, not in pieces.
Splunk indexes any log with schema-on-read (SPL to search, correlate, visualize): Enterprise Security is the SIEM (risk-based alerting that aggregates the signals per entity, curated detections), SOAR orchestrates the response with visual playbooks, Observability Cloud unites metrics/traces/logs for APM; the Cisco acquisition brings the network telemetries and Talos TI inside; the deployment is cloud or on-prem, the license by ingest or workload.
The reference SIEM, with our rules.
The cause found by searching, not by rebooting.
Retention and reports for NIS2, PCI, audits.