Splunk

Security OperationsDetection Response acquired also known as Splunk Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2003
Last updated 2026-08-05

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

This analysis is scoped to Splunk security portfolio.

Splunk sells the software many large enterprise security operations centers run on: Splunk Enterprise Security, a SIEM sold with SOAR automation, user-behavior analytics, and automated malware analysis, priced by data ingested or workload. Cisco bought the company for roughly $28 billion in March 2024, a price no earlier Cisco acquisition approached, and still runs it as a distinct brand. Since the deal, Cisco has placed increased strategic emphasis on Splunk's data platform: at the 2025 user conference it introduced the Cisco Data Fabric, an evolution of the Splunk platform, as the data layer for its AI plans. The security line keeps shipping, with Enterprise Security 8.2 released in 2025, a malware reversal agent available, and further AI agents announced to follow.

Sourced Details

Description Splunk sells security and observability software. Its security portfolio centers on Splunk Enterprise Security, a SIEM integrated with SOAR automation, user and entity behavior analytics, and agentic AI for enterprise security operations teams. [f1]
Acquisition Cisco, announced 2023-09-21 [f2]
Founded 2003 [f3]

Products

Product What it does
Splunk Enterprise Security Threat detection, investigation, and response platform that integrates SIEM, agentic AI, SOAR, and native user and entity behavior analytics for security operations teams.
Splunk SOAR Security orchestration, automation and response that connects with over 300 third-party tools and supports over 2,800 automated actions.
Splunk Attack Analyzer Automated analysis of suspected malware and credential phishing threats that follows each step in complex attack chains and renders a verdict for analysts.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Splunk Enterprise Security detects threats across users, devices, networks, applications, and data from ingested telemetry, and Splunk SOAR automates response actions across connected security tools. These products are mapped to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 26 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The threat detection, investigation, and response problem Splunk sells against has a clear buyer, the enterprise security operations team, and analysts maintain dedicated category coverage, but the reviewed sources quantify no buyer pain, which holds the score at three. [s13, s15]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Product pages document a portfolio spanning SIEM, SOAR with integrations to over 300 tools, behavior analytics, and automated malware analysis, and coverage from two independent analyst firms confirms Enterprise Security 8.2 is shipping, the external validation point the four requires. The new AI agents arrive in stages, with the malware reversal agent available at the 2025 conference, and this dimension credits the shipping portfolio rather than announced agents. [s2, s3, s4, s5, s14, s15]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 SIEM is an entrenched budget line, but the cited evidence is conference reporting and analyst commentary on Splunk's own announcements rather than buyer-side demand signals, which holds the score at the credible-timing level. [s13, s14, s15]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 2/5 The reviewed sources record no verifiable security-line leadership background beyond Cisco's management structure since the March 2024 close, plausible but publicly unverified in this record, which places the dimension at two. [s11, s13]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 The security line carries multiple named references on fetched vendor pages, Children's National Hospital using Splunk for threat detection, investigation, and response, Carrefour responding to security threats faster, and Novuna using Splunk SOAR to manage and contain 80,000 events, which keeps the line well above claims-only. All are vendor-displayed with no independent corroboration at the line level, the corpus floor a four requires, so the score holds at three. [s17, s18, s19, s8]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Read at scale as output per capital, the security line shows visible shipping under the new owner, with Enterprise Security 8.2 and new editions released in 2025, but no line-level revenue or margin is disclosed, so efficiency itself is unconfirmed. The acquisition price is a buyer valuation of the whole company, not an efficiency signal. [s11, s14]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Buyers place Splunk in the SIEM category without vendor coaching, and the vendor displays 11 consecutive Gartner Magic Quadrant Leader placements, but a vendor-displayed badge is not independent confirmation, so the score holds at four. [s4, s15]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 4/5 Splunk is itself the incumbent. Its pages document the SIEM workflow surface and SOAR integrations with over 300 tools, and in this analysis's judgment a rival bundle would have to displace the detections and playbooks a deployment accumulates on that surface. Litigation shows a startup copying its data-analysis software rather than displacing it. [s2, s3, s10]
Business Risks Microsoft could pull Enterprise Security accounts into its own SIEM through enterprise licensing bundles that undercut ingest-based pricing…
  • Microsoft could pull Enterprise Security accounts into its own SIEM through enterprise licensing bundles that undercut ingest-based pricing.
  • Data-pipeline and data-lake challengers such as Cribl could move high-volume telemetry out of Splunk, shrinking the data volume its security pricing is built on.
  • Cisco could fold the Splunk security portfolio into Cisco-branded platforms, ending the standalone brand and roadmap.
  • Buyer spend on AI-assisted security operations could shift to rivals before Splunk's own AI agents and new Enterprise Security editions leave controlled availability.
Problem & Market Splunk's security business sells to enterprise security operations teams that need to collect telemetry from across their environment, detect threats in it, investigate them, and respond. That problem definition does not need vendor education. SIEM is a long-established budget line, and analysts maintain dedicated coverage of the category and of Splunk's releases within it. The scope of this analysis is the security portfolio: Splunk Enterprise Security, Splunk SOAR, and Splunk Attack Analyzer. Splunk also sells observability products and the underlying data platform, and the same platform now anchors Cisco's data strategy, so the security line is one consumer of a larger machine-data business…

Splunk's security business sells to enterprise security operations teams that need to collect telemetry from across their environment, detect threats in it, investigate them, and respond. That problem definition does not need vendor education. SIEM is a long-established budget line, and analysts maintain dedicated coverage of the category and of Splunk's releases within it.

The scope of this analysis is the security portfolio: Splunk Enterprise Security, Splunk SOAR, and Splunk Attack Analyzer. Splunk also sells observability products and the underlying data platform, and the same platform now anchors Cisco's data strategy, so the security line is one consumer of a larger machine-data business. [s1, s13, s15]

Product Capabilities The portfolio covers the security operations workflow end to end…

The portfolio covers the security operations workflow end to end. Enterprise Security is the SIEM and the workspace where detection, investigation, and response happen, with Cisco Talos threat intelligence bundled at no additional cost. Splunk SOAR automates response by connecting with over 300 third-party tools and supporting more than 2,800 automated actions. Native user and entity behavior analytics in Enterprise Security applies behavior-based anomaly detection and machine learning to insider threats such as account misuse and compromised credentials, and Splunk Attack Analyzer automates analysis of suspected malware and credential phishing.

The 2025 releases push toward AI-assisted operations. Enterprise Security 8.2 ships in an Essentials edition with the AI assistant and a Premier edition that adds SOAR, behavior analytics, and threat intelligence management. The AI agents arrive in stages: analysts covering the conference describe the malware reversal agent as available with a triage agent announced to follow, and the Enterprise Security page now lists Detection Studio among its shipping capabilities for detection engineers. [s2, s3, s4, s5, s14, s15, s20]

Competitive Positioning Splunk competes as the incumbent SIEM against two kinds of pressure…

Splunk competes as the incumbent SIEM against two kinds of pressure. Platform vendors bundle rival detection and response products into wider agreements attached to clouds and endpoints they already control. Newer challengers sell against Splunk's economics, moving high-volume telemetry into cheaper data stores, and the pressure is concrete enough that Splunk litigated: it won an infringement case in April 2024 against Cribl, a startup it accused of copying its enterprise data analysis software.

The 2025 countermoves meet the economics attack directly. The Machine Data Lake gives customers a lower-cost place to keep data inside Splunk, and federated search reaches data in external stores such as Snowflake, so a customer can cut storage cost without leaving the Splunk workflow layer. [s10, s15]

Go-to-Market & Traction The security line has named references on the vendor's pages…

The security line has named references on the vendor's pages. Children's National Hospital uses Splunk for threat detection, investigation, and response, with its CISO describing telemetry brought into the Splunk environment for visibility, Carrefour's customer story reports responding to security threats three times faster, and Novuna used Splunk SOAR to manage and contain 80,000 events. Broader accounts such as Progressive and Tesco credit Splunk at the company level.

The sales motion is enterprise. Pricing is negotiated rather than published, the customer list skews to large regulated organizations, and the business now sells as part of Cisco. Cisco's roughly $28 billion purchase valued the whole company, so it corroborates company scale rather than security-line traction. [s6, s8, s9, s11, s12, s17, s18, s19]

Team & Credibility Leadership of the security line now sits inside Cisco's management structure, and the reviewed sources record no security-line leadership track record independent of the parent. The company's own record carries the credibility: Splunk displays 11 consecutive Gartner Magic Quadrant Leader placements for SIEM, and channel press covering the 2025 user conference reports the integration proceeding with the Splunk brand and community intact. The practitioner community is a distinct asset. The annual .conf user conference continued under Cisco ownership, and analysts treat it as the centerpiece of a strong practitioner community built over years…

Leadership of the security line now sits inside Cisco's management structure, and the reviewed sources record no security-line leadership track record independent of the parent. The company's own record carries the credibility: Splunk displays 11 consecutive Gartner Magic Quadrant Leader placements for SIEM, and channel press covering the 2025 user conference reports the integration proceeding with the Splunk brand and community intact.

The practitioner community is a distinct asset. The annual .conf user conference continued under Cisco ownership, and analysts treat it as the centerpiece of a strong practitioner community built over years. [s11, s13, s14]

Trust Readiness Splunk publishes substantial trust collateral…

Splunk publishes substantial trust collateral. The Splunk Protects pages describe a cloud security addendum benchmarked against ISO 27001, SOC 2, HIPAA, PCI DSS, and FedRAMP as applicable, and a customer trust portal provides certifications, compliance reports, and standard security questionnaires on demand.

This posture matches the buyer. Regulated enterprises and public sector organizations appear throughout the customer material, and the compliance surface is table stakes Splunk clears rather than a differentiator. [s7, s8]

Competitors Microsoft, Google, CrowdStrike, Panther, Hunters, Cribl…
Company Relationship Note Compare
Microsoft competes with Sells Microsoft Sentinel, a cloud SIEM. N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.
Google competes with Sells Google Security Operations, a cloud SIEM and SOAR line. N/AGoogle is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.
CrowdStrike competes with Sells a next-gen SIEM offering. N/AWe scored these companies at different scopes, so the totals measure different things.
Panther competes with Sells a cloud-native SIEM to enterprise security teams. N/AWe scored these companies at different scopes, so the totals measure different things.
Hunters competes with Sells a SOC platform with SIEM capabilities to enterprise security teams. N/AWe scored these companies at different scopes, so the totals measure different things.
Cribl competes with Data-pipeline vendor that Splunk sued for copying enterprise data analysis software.

Add analyzed competitors to compare them side by side with Splunk.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Splunk's security line creates meaningful friction rather than a durable lock: Enterprise Security anchors the security team's detection, investigation, and response workflow, and the platform documents integrations with over 300 third-party tools, so replacing the product means rebuilding the detections, playbooks, and integrations a deployment accumulates. The line is thinner on data of its own: no cross-customer threat-data asset of the security line's own appears in the reviewed record, and Enterprise Security bundles Cisco's Talos intelligence, and the cited pages also name a Splunk threat research team. Regulated enterprises buy it, and cloud controls Splunk describes as benchmarked against FedRAMP slow an easy replacement and position it for government procurement.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Splunk delivers software the customer's security team configures and operates, detections, playbooks, and analytics are product output, and the customer owns the outcomes, the software-product level.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Enterprise Security anchors the detection, investigation, and response workflow, and Splunk SOAR supports integrations with over 300 third-party tools and over 2,800 automated actions, so replacing a deployment means rebuilding the detections, playbooks, and integrations built on that surface. The reviewed sources document available breadth rather than a named customer deployment, and they establish no network effect, data-residency requirement, or other bespoke-rebuild exit, so the friction sits at the meaningful level rather than the defensible one.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 2/3 Cloud controls are benchmarked against ISO 27001, SOC 2, HIPAA, PCI DSS, and FedRAMP as applicable, with a customer trust portal for reports. Compliance matters to its regulated buyers, but a determined operator could earn the same attestations.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Real-time indexing and search over security telemetry at enterprise scale, machine-learning modeling of user and entity behavior, a detection and response workflow, and automated analysis of suspected malware and phishing sit in one portfolio, a combination that is hard to assemble rather than a single feature to copy.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Regulated enterprises run the product, with cloud controls Splunk describes as benchmarked against FedRAMP among other standards, named security customers in insurance, healthcare, and retail, and public sector listed among the industries served, so procurement and legal sit between Splunk and a replacement.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The scored security portfolio is a platform with application features, the workflow layer where analysts work, sitting on a data platform that other applications and now the Cisco Data Fabric build on, rather than being infrastructure other software depends on itself.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Splunk enforced its intellectual property in court against a startup copying its data-analysis software, but each customer's telemetry stays the customer's own, no cross-customer data asset of the security line's own appears in the reviewed record, and the bundled Talos intelligence belongs to Cisco, which holds the line at the anchor.
Strategic Market Segmentation Splunk's security portfolio targets large, regulated organizations with staffed security operations centers. The customer material shows industry examples in healthcare, insurance, and retail, lists public sector among the industries served, and the published references skew toward large enterprises. Pricing is sales-assisted, with Splunk asking buyers to contact it for pricing details rather than posting list prices. Within Cisco, the segment logic broadened. The security buyer is one consumer of a machine-data platform Cisco now positions as the data layer for its AI plans, so the same account can be sold observability, data storage, and security from one platform…

Splunk's security portfolio targets large, regulated organizations with staffed security operations centers. The customer material shows industry examples in healthcare, insurance, and retail, lists public sector among the industries served, and the published references skew toward large enterprises. Pricing is sales-assisted, with Splunk asking buyers to contact it for pricing details rather than posting list prices.

Within Cisco, the segment logic broadened. The security buyer is one consumer of a machine-data platform Cisco now positions as the data layer for its AI plans, so the same account can be sold observability, data storage, and security from one platform.

Product Capabilities & AI Advantages The portfolio's capability claims are concrete and documented…

The portfolio's capability claims are concrete and documented. Enterprise Security unifies detection, investigation, and response with Cisco Talos threat intelligence bundled at no additional cost, SOAR connects with over 300 third-party tools and supports more than 2,800 automated actions, native behavior analytics in Enterprise Security applies machine learning to user and entity behavior, and Attack Analyzer automatically walks attack chains in suspected malware and phishing.

The AI story is method, not asset. Analysts covering the 2025 releases describe an AI assistant in the new Enterprise Security editions and a malware reversal agent available at the conference, with a triage agent announced to follow, and the Enterprise Security page now lists Detection Studio among its shipping capabilities, so the differentiating AI surface is arriving in stages rather than already deployed at scale.

Sales Engagement & Go-to-Market The motion is enterprise…

The motion is enterprise. Pricing is negotiated, references are curated case studies with published outcomes, channel press documents the business selling under Cisco since the 2024 close, and the annual .conf user conference anchors a practitioner community that functions as a demand channel.

The security line has its own named references on the vendor's pages. Children's National Hospital uses Splunk for threat detection, investigation, and response, Carrefour's customer story reports responding to security threats three times faster, and Novuna used Splunk SOAR to manage and contain 80,000 events. These are vendor-displayed stories, and the reviewed record adds no independent corroboration of the line's scale.

Pricing Model Splunk publishes two pricing plans for its security line, workload pricing and ingest pricing, with the plan structure published and list prices negotiated, an enterprise model. Ingest pricing ties the bill to data volume, which matches how the platform creates value but grows the bill as customer data grows, while workload pricing offers an alternative unit. Data economics is where this analysis sees the pricing pressure: an ingest-priced platform is exposed if customers find cheaper places to keep high-volume data. Splunk's 2025 announcements answer that on two different footings. Forrester describes the Machine Data Lake as a cost-effective way to store data within Splunk, while the federated search announced with Snowflake reaches data the customer keeps in an external store…

Splunk publishes two pricing plans for its security line, workload pricing and ingest pricing, with the plan structure published and list prices negotiated, an enterprise model. Ingest pricing ties the bill to data volume, which matches how the platform creates value but grows the bill as customer data grows, while workload pricing offers an alternative unit.

Data economics is where this analysis sees the pricing pressure: an ingest-priced platform is exposed if customers find cheaper places to keep high-volume data. Splunk's 2025 announcements answer that on two different footings. Forrester describes the Machine Data Lake as a cost-effective way to store data within Splunk, while the federated search announced with Snowflake reaches data the customer keeps in an external store.

Product Delivery & Operations The security products deliver as cloud services and self-managed software the customer's team operates. Splunk Cloud Platform carries the audited controls, and the SOAR integration surface, over 300 tools, means the products slot into existing security stacks rather than replacing them. Operating the platform is real work. The pricing model rewards tuning what data comes in, and the new lower-cost storage tier acknowledges that customers manage data economics as part of running the product…

The security products deliver as cloud services and self-managed software the customer's team operates. Splunk Cloud Platform carries the audited controls, and the SOAR integration surface, over 300 tools, means the products slot into existing security stacks rather than replacing them.

Operating the platform is real work. The pricing model rewards tuning what data comes in, and the new lower-cost storage tier acknowledges that customers manage data economics as part of running the product.

Earning Customers' Trust Trust collateral is mature and public…

Trust collateral is mature and public. The Splunk Protects pages document a cloud security addendum benchmarked against ISO 27001, SOC 2, HIPAA, PCI DSS, and FedRAMP as applicable, and a customer trust portal serves certifications, compliance reports, and standard questionnaires on demand.

For a vendor whose product ingests the customer's most sensitive telemetry, this posture is a requirement its regulated buyers impose, and Splunk clears it rather than differentiates on it.

Platform Strategy & Ecosystem Positioning Splunk's platform position is structural rather than declared…

Splunk's platform position is structural rather than declared. The security products are applications on a data platform that Cisco now brands the Cisco Data Fabric and positions as the foundation of its AI strategy, with the new Machine Data Lake sitting beneath both the security and observability lines.

The ecosystem cuts both ways. The integration surface and practitioner community give the security line reach beyond its own direct sales, while analyst coverage records Cisco's initial security framing of Splunk giving way to a broader cross-functional positioning. That widening could put security roadmap priorities in competition inside a larger data-and-AI strategy, though the reviewed record shows continued security releases rather than such a tradeoff.

Team & Execution Capability Leadership of the security line sits inside Cisco's management structure since the March 2024 close, and the reviewed sources record no security-line leadership track record independent of the parent. The organizational risk a buyer weighs is integration drift rather than startup fragility. Channel press covering the 2025 user conference quotes an IDC analyst who arrived asking whether Splunk would stay distinct or be subsumed, and who reports Splunk executives answering that the brand and community remain critical, while analyst coverage records Enterprise Security 8.2 shipping in new editions. The observable evidence is continued brand visibility, community investment, and product releases, not a verified standalone operating model…

Leadership of the security line sits inside Cisco's management structure since the March 2024 close, and the reviewed sources record no security-line leadership track record independent of the parent. The organizational risk a buyer weighs is integration drift rather than startup fragility.

Channel press covering the 2025 user conference quotes an IDC analyst who arrived asking whether Splunk would stay distinct or be subsumed, and who reports Splunk executives answering that the brand and community remain critical, while analyst coverage records Enterprise Security 8.2 shipping in new editions. The observable evidence is continued brand visibility, community investment, and product releases, not a verified standalone operating model.

Sources

Company Detail Sources (3)
Id Source Tier Accessed
f1 Splunk: Enterprise Security product page official 2026-07-22
f2 Splunk newsroom: Cisco to Acquire Splunk announcement (September 21, 2023) official 2026-07-22
f3 Wikipedia: Splunk press 2026-07-22
Profile Analysis Sources (20)
Id Source Tier Accessed
s1 Splunk homepage
“Complete data. AI you can trust. Security and observability at enterprise scale.”
official 2026-07-22
s2 Splunk Enterprise Security product page
“Accelerate investigations with integrated threat intelligence enrichment and leverage Cisco Talos threat intelligence at no additional cost.”
official 2026-07-22
s3 Splunk SOAR product page
“It orchestrates your security stack by connecting with 300+ third-party tools and supporting 2,800+ automated actions.”
official 2026-07-22
s4 Splunk UEBA product page (Gartner banner displayed by the vendor)
“2025 Gartner Magic Quadrant for SIEM Splunk named a leader 11 times in a row”
official 2026-07-22
s5 Splunk Attack Analyzer product page
“Splunk Attack Analyzer automates analysis of suspected malware and credential phishing threats.”
official 2026-07-22
s6 Splunk security pricing page
“Available Pricing Plans: Workload Pricing Ingest Pricing”
official 2026-07-22
s7 Splunk Protects trust page
“Benchmarked against industry standard requirements (ISO 27001, SOC 2, HIPAA, PCI DSS and FedRAMP, as applicable), the CSA provides details regarding the data security controls in the Splunk Cloud Platform environment”
official 2026-07-22
s8 Splunk customers page
“Progressive Protects Customers and Revenue with Splunk”
official 2026-07-22
s9 Splunk about page (Tesco customer story)
“Splunk is embedded as part of the core nervous system of our operations.”
official 2026-07-22
s10 Wikipedia: Splunk
“In April 2024, Splunk won an infringement case against Cribl Inc, a startup competitor, for copying enterprise data analysis software.”
press 2026-07-22
s11 SEC EDGAR: Cisco Systems 10-K for fiscal 2025 (Splunk acquisition note)
“On March 18, 2024, we completed the acquisition of Splunk Inc. ("Splunk"), a public cybersecurity and observability company. Under the terms of the agreement, we agreed to pay $157 per share in cash, representing approximately $27 billion in merger consideration.”
regulatory 2026-07-22
s12 SiliconANGLE: Cisco completes its $28B acquisition of Splunk
“Cisco Systems Inc. today completed its $28 billion purchase of Splunk, the largest acquisition in the networking giant's four-decade history.”
press 2026-07-22
s13 ChannelE2E: Splunk .conf25 reflections, analysts on the Cisco Data Fabric and agentic AI news
“So, just how is the integration of Splunk going under Cisco, which acquired the data observability vendor in March of 2024 for $28 billion?”
press 2026-07-22
s14 Futurum: Splunk .conf25, forging a data foundation for Cisco's AgenticOps vision
“In security, Splunk launched Enterprise Security 8.2, now available in "Essentials" and a new "Premier" edition that includes UEBA and SOAR capabilities.”
research 2026-07-22
s15 Forrester blog: Splunk .conf25, Cisco, AI, and data
“Some of Splunk's key announcements included the Cisco Data Fabric and its Machine Data Lake. The Cisco Data Fabric is its new way of describing the data journey, from traditional Splunk ingest to federated search (such as on Snowflake, which it also announced)”
research 2026-07-22
s16 Cisco newsroom: Cisco Completes Acquisition of Splunk
“Under the terms of the agreement, Cisco acquired Splunk for $157 per share in cash, representing approximately $28 billion in equity value.”
official 2026-07-22
s17 Splunk customers page (Children's National Hospital Uses Splunk for TDIR story)
“By bringing all that valuable telemetry into the Splunk environment, we gain the visibility needed to protect data, no matter where it lives. Nathan Lesser, CISO, Children's National Hospital”
official 2026-07-22
s18 Splunk customers page (Carrefour security customer story)
“Carrefour Responds to Security Threats 3x Faster”
official 2026-07-22
s19 Splunk SOAR product page (Novuna customer story)
“Novuna has used Splunk SOAR to manage and contain 80,000 events, saving more than $500,000 as a result of licensing savings, increased user efficiency, and reduced on-call hours - within 8 months.”
official 2026-07-22
s20 Splunk Enterprise Security product page (capabilities listing including Detection Studio)
“SIEM Detect and stop threats SOAR Accelerate and automate response UEBA Detect user and entity anomalies Detection Studio Develop and monitor detections”
official 2026-07-22
Deep-Dive Sources (21)
Id Source Tier Accessed
s1 Splunk homepage
“Complete data. AI you can trust. Security and observability at enterprise scale.”
official 2026-07-22
s2 Splunk Enterprise Security product page
“Accelerate investigations with integrated threat intelligence enrichment and leverage Cisco Talos threat intelligence at no additional cost.”
official 2026-07-22
s3 Splunk SOAR product page
“It orchestrates your security stack by connecting with 300+ third-party tools and supporting 2,800+ automated actions.”
official 2026-07-22
s4 Splunk UEBA product page (Gartner banner displayed by the vendor)
“2025 Gartner Magic Quadrant for SIEM Splunk named a leader 11 times in a row”
official 2026-07-22
s5 Splunk Attack Analyzer product page
“Splunk Attack Analyzer automates analysis of suspected malware and credential phishing threats.”
official 2026-07-22
s6 Splunk security pricing page
“Available Pricing Plans: Workload Pricing Ingest Pricing”
official 2026-07-22
s7 Splunk Protects trust page
“Benchmarked against industry standard requirements (ISO 27001, SOC 2, HIPAA, PCI DSS and FedRAMP, as applicable), the CSA provides details regarding the data security controls in the Splunk Cloud Platform environment”
official 2026-07-22
s8 Splunk customers page
“Progressive Protects Customers and Revenue with Splunk”
official 2026-07-22
s9 Splunk about page (Tesco customer story)
“Splunk is embedded as part of the core nervous system of our operations.”
official 2026-07-22
s10 Wikipedia: Splunk
“In April 2024, Splunk won an infringement case against Cribl Inc, a startup competitor, for copying enterprise data analysis software.”
press 2026-07-22
s11 SEC EDGAR: Cisco Systems 10-K for fiscal 2025 (Splunk acquisition note)
“On March 18, 2024, we completed the acquisition of Splunk Inc. ("Splunk"), a public cybersecurity and observability company. Under the terms of the agreement, we agreed to pay $157 per share in cash, representing approximately $27 billion in merger consideration.”
regulatory 2026-07-22
s12 SiliconANGLE: Cisco completes its $28B acquisition of Splunk
“Cisco Systems Inc. today completed its $28 billion purchase of Splunk, the largest acquisition in the networking giant's four-decade history.”
press 2026-07-22
s13 ChannelE2E: Splunk .conf25 reflections, analysts on the Cisco Data Fabric and agentic AI news
“So, just how is the integration of Splunk going under Cisco, which acquired the data observability vendor in March of 2024 for $28 billion?”
press 2026-07-22
s14 Futurum: Splunk .conf25, forging a data foundation for Cisco's AgenticOps vision
“In security, Splunk launched Enterprise Security 8.2, now available in "Essentials" and a new "Premier" edition that includes UEBA and SOAR capabilities.”
research 2026-07-22
s15 Forrester blog: Splunk .conf25, Cisco, AI, and data
“Some of Splunk's key announcements included the Cisco Data Fabric and its Machine Data Lake. The Cisco Data Fabric is its new way of describing the data journey, from traditional Splunk ingest to federated search (such as on Snowflake, which it also announced)”
research 2026-07-22
s16 Cisco newsroom: Cisco Completes Acquisition of Splunk
“Under the terms of the agreement, Cisco acquired Splunk for $157 per share in cash, representing approximately $28 billion in equity value.”
official 2026-07-22
s17 Splunk customers page (Children's National Hospital Uses Splunk for TDIR story)
“By bringing all that valuable telemetry into the Splunk environment, we gain the visibility needed to protect data, no matter where it lives. Nathan Lesser, CISO, Children's National Hospital”
official 2026-07-22
s18 Splunk customers page (Carrefour security customer story)
“Carrefour Responds to Security Threats 3x Faster”
official 2026-07-22
s19 Splunk SOAR product page (Novuna customer story)
“Novuna has used Splunk SOAR to manage and contain 80,000 events, saving more than $500,000 as a result of licensing savings, increased user efficiency, and reduced on-call hours - within 8 months.”
official 2026-07-22
s20 Splunk Enterprise Security product page (capabilities listing including Detection Studio)
“SIEM Detect and stop threats SOAR Accelerate and automate response UEBA Detect user and entity anomalies Detection Studio Develop and monitor detections”
official 2026-07-22
s21 Splunk customer story: Southern Farm Bureau Life Insurance Company (Splunk Attack Analyzer)
“SFBLI Boosts Efficiency and Strengthens Security Posture with Splunk Attack Analyzer”
official 2026-08-05

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.