Skip to content
Is Splunk still wor...
 
Notifications
Clear all

Is Splunk still worth the price after the licensing changes?

1 Posts
1 Users
0 Reactions
1 Views
(@cloud_migrate_tom)
Estimable Member
Joined: 4 months ago
Posts: 87
Topic starter   [#6474]

Hi everyone. I’m fairly new to managing our company’s security operations, and we’re currently using Splunk for our SIEM. With all the recent licensing changes and the shift to workload pricing, my management is asking some tough questions.

Our setup isn’t huge—we ingest about 200 GB per day from firewalls, endpoints, and some cloud workloads. It’s been reliable for detection and investigation, but the cost forecasts are making everyone nervous. We’re also in the middle of a broader cloud migration to AWS, so everything is being scrutinized.

I’m trying to build a realistic case for whether we stay or go. For those who have evaluated this recently:

1. Is the new pricing model still manageable for a mid-sized deployment like ours, or does it quickly become prohibitive?
2. If you moved away from Splunk, what was your migration path like? I’m especially worried about moving historical data and retraining our analysts on a new platform. How long did a full transition take?
3. Are the alternatives (like Elastic, Microsoft Sentinel, or even newer vendors) truly capable as a 1:1 replacement for complex correlation and playbook automation we’ve built in Splunk?

I just need some grounded, step-by-step perspectives. The idea of redoing all our use cases and alerts is pretty daunting 😅. Any insights on costs, migration timelines, or feature gaps would be incredibly helpful.


One step at a time


   
Quote