Skip to content
Notifications
Clear all

Has anyone successfully negotiated the ES license down from list price? What % off?

3 Posts
3 Users
0 Reactions
0 Views
(@annie82)
Estimable Member
Joined: 6 days ago
Posts: 61
Topic starter   [#18293]

Hi everyone,

I’m currently evaluating Splunk Enterprise Security for my organization. We’re about a 150-person team, and the security team pushing for this is relatively small. I’ve been tasked with helping to evaluate the cost side of things alongside the technical folks.

We’ve gotten the initial quote, and honestly, it’s a bit of a sticker shock 😅. I’m used to dealing with more straightforward SaaS subscriptions where you might get 10-20% off just by asking, but this feels like a different league.

My question is for those who have gone through a purchase: is there any room to negotiate on the ES license price from Splunk? I know list price is often just a starting point for enterprise deals, but I have no frame of reference.

* What’s a realistic discount percentage to aim for?
* Does it depend heavily on the commit term or total data volume?
* Are there specific times of the year (like end of quarter) when they’re more flexible?

Any insight into the process would be so helpful. I don’t want to go in completely naive, but I also don’t want to ask for something unrealistic.

Thanks in advance,

✌️ annie



   
Quote
(@jackb2)
Eminent Member
Joined: 3 days ago
Posts: 26
 

Yeah, there's always room. The initial quote is just their opening move.

Aim for at least 25% off list to start. It depends heavily on your commit term and the data volume you're putting on the table. A 3-year commit for a specific, large daily ingest will get you a much better rate than a 1-year with a vague range.

End of quarter, especially Q4, is when their sales team has the most pressure to hit targets. That's your best leverage. Have an alternative product name ready to mention.


Benchmark or bust


   
ReplyQuote
(@cost_optimizer_elle)
Estimable Member
Joined: 2 months ago
Posts: 91
 

Yep, 25% is a good opening target, but you're right to ask about the levers.

The biggest one is commit term. Splunk sales *hate* annual deals. Pushing to 3 years, especially bundled with a commitment to ingest more data over that term, gets you the real concessions. Don't just ask for a discount, structure the deal for growth (even if it's theoretical). Something like "We'll commit to 100GB/day year one, 150GB/year two on a 3-year term" gives them a future-upsell story to justify the lower price today.

Also, that sticker shock is a feature, not a bug. It sets the anchor high. They'll expect you to counter. Have an alternative (like Sentinel or a SIEM aggregator) queued up, even if you're not serious. The phrase "we're running a bake-off" works magic in Q4.


- elle


   
ReplyQuote