Splunk
A software brand for machine-data analytics, cybersecurity, observability, and operational intelligence.
Last updated August 27, 2026
Overview
Splunk is an American enterprise software brand whose platform collects, indexes, searches, and analyzes machine-generated data from applications, infrastructure, networks, endpoints, cloud services, and industrial systems. Its technology was initially associated with log management and troubleshooting, but the business expanded into a broader data platform serving IT operations, application performance monitoring, security information and event management, security orchestration, incident response, compliance, and business operations. Michael Baum, Rob Das, and Erik Swan founded the company in 2003. Early financing came from venture firms including August Capital, Sevin Rosen, Ignition Partners, and JK&B Capital. Splunk raised approximately $40 million by 2007 and became profitable in 2009. Its 2012 initial public offering on Nasdaq made Splunk one of the most visible independent companies in the emerging machine-data and log-analytics market. During the 2010s, Splunk broadened its portfolio through organic development and acquisitions. It added cloud services, analytics for Hadoop and other external data stores, IT service intelligence, industrial monitoring, security analytics, orchestration, application performance monitoring, infrastructure monitoring, and real-time data-stream processing. Acquisitions including Cloudmeter, Caspida, Phantom Cyber, VictorOps, SignalFx, and Omnition helped move the brand beyond conventional log search toward security operations and full-stack observability. Splunkbase, its community marketplace, further expanded the platform through third-party apps, integrations, and add-ons. The company increasingly emphasized cloud delivery. Splunk Cloud provided a hosted alternative to on-premises Splunk Enterprise, while Splunk Observability Cloud combined infrastructure monitoring, application performance monitoring, digital experience monitoring, log investigation, and incident-response capabilities. Partnerships with Google Cloud and Amazon Web Services supported cloud migration, machine learning, multicloud operations, and government deployments. Splunk also received moderate-level FedRAMP authorization, enabling sales to qualifying United States federal agencies. Splunk became a major cybersecurity vendor through products such as Splunk Enterprise Security, user-behavior analytics, Splunk Mission Control, and Splunk SOAR. These offerings were designed to correlate telemetry, prioritize threats, automate response workflows, and support investigation across on-premises, cloud, and hybrid environments. Its customer base has included organizations in finance, transportation, manufacturing, retail, government, telecommunications, and professional services. Cisco announced an agreement to acquire Splunk for $28 billion in cash in September 2023. The transaction closed on March 18, 2024, making it the largest acquisition in Cisco's history and ending Splunk's status as an independent publicly traded company. Splunk continued to operate from San Francisco under the Cisco group, with Gary Steele continuing in a leadership role during integration. Cisco subsequently positioned Splunk as a central component of its security, observability, data, and enterprise-artificial-intelligence strategy. The integration also brought Cisco AppDynamics-related observability development into the broader Splunk organization.
History
Splunk was founded in 2003 by Michael Baum, Rob Das, and Erik Swan to address the difficulty of understanding large volumes of machine-generated data. Early users adopted its software to search application and infrastructure logs, troubleshoot distributed systems, and create operational dashboards and alerts. August Capital, Sevin Rosen, Ignition Partners, and JK&B Capital were among the venture investors that supported the company. Splunk had raised about $40 million by 2007 and reached profitability in 2009. The company went public on Nasdaq in 2012 under the symbol SPLK. Its original enterprise product was installed on customer infrastructure and combined data collection, indexing, search, reporting, visualization, and alerting. Splunk subsequently introduced managed and cloud-oriented services, including Splunk Storm and later Splunk Cloud. Storm was eventually discontinued, while Splunk Cloud became the principal hosted form of the platform. From 2013 through 2019, Splunk expanded through a series of acquisitions. BugSense and Cloudmeter strengthened analytics and data-ingestion capabilities; Caspida added security analytics; Phantom Cyber added security orchestration and automated response; VictorOps contributed incident management; and SignalFx and Omnition expanded application and infrastructure observability. Other acquisitions, including Metafor, Rocana, KryptonCloud, Drastin, and SignalSense, supported the company's broader data and monitoring ambitions. Splunk also developed Hunk for Hadoop analytics, Splunk IT Service Intelligence, Industrial Asset Intelligence, Data Fabric Search, Data Stream Processor, Connected Experiences, and Mission Control. Security became one of Splunk's most important growth areas. Splunk Enterprise Security provided SIEM functions by correlating data from networks, endpoints, identities, vulnerabilities, malware systems, and access controls. Splunk SOAR and the former Phantom product supported workflow automation and incident response. Mission Control brought several security capabilities into a more unified operational experience. In parallel, Splunk developed observability offerings spanning infrastructure, applications, digital experience, logs, traces, and incident response. The company pursued partnerships and public-sector credentials as it moved toward cloud and multicloud operations. Google Cloud integration connected Splunk data with cloud analytics, machine learning, Anthos, and security services. Amazon Web Services supported migration of on-premises workloads to Splunk Cloud. Splunk received moderate-level FedRAMP authorization in 2019, helping it sell eligible services to United States federal customers. In 2015 it formed a cybersecurity alliance with Booz Allen Hamilton, and in 2016 it announced a ten-year commitment involving software, training, education, support, and volunteer efforts for nonprofits and schools. Leadership changed during the company's cloud transformation. Doug Merritt stepped down as president and CEO in November 2021, after which chairman Graham Smith served as interim chief executive. Gary Steele, previously associated with Proofpoint, was named CEO in March 2022 and took the role the following month. Cisco announced its agreement to acquire Splunk for $28 billion in cash on September 21, 2023. Splunk disclosed workforce reductions during the transaction period, while Steele stated that the reductions were unrelated to the deal. The acquisition closed on March 18, 2024, ending Splunk's independent public-company status. Splunk retained its San Francisco base and continued as a Cisco business. Gary Steele moved into a Cisco executive role while continuing to lead Splunk as general manager during integration. Cisco also aligned its AppDynamics observability development with Splunk. Following the integration, Splunk became a major part of Cisco's security, observability, data, and enterprise-AI strategy.
- 2024Acquisition closes
Cisco completes the acquisition on March 18, ending Splunk's independent public-company status.
- 2023Cisco announces acquisition
Cisco announces an all-cash agreement valued at $28 billion to acquire Splunk.
- 2022Gary Steele becomes CEO
Gary Steele succeeds Graham Smith as chief executive during Splunk's cloud and security transformation.
- 2020Splunk Ventures launches
The company establishes investment programs for early-stage technology companies and social-impact initiatives.
- 2019FedRAMP authorization
Splunk receives moderate-level FedRAMP authorization, supporting sales to United States federal agencies.
- 2015Security and IT operations expansion
Splunk adds products and partnerships focused on IT service intelligence, security, and enterprise operations.
- 2012Initial public offering
Splunk lists on Nasdaq under the symbol SPLK.
- 2009Company becomes profitable
Splunk reaches profitability as adoption of its machine-data analytics platform grows.
- 2003Splunk is founded
Michael Baum, Rob Das, and Erik Swan establish Splunk to develop software for searching and analyzing machine-generated data.
Products and positioning
An enterprise data platform connecting observability, security operations, and machine-data analytics across on-premises, cloud, and hybrid environments.
Splunk EnterpriseMachine-data analytics platform
Splunk Enterprise is the core platform for collecting, indexing, searching, visualizing, and alerting on machine-generated data. It can ingest logs and events from files, network protocols, scripts, applications, infrastructure, and security technologies. Customers use it for troubleshooting, operational dashboards, reporting, compliance analysis, and real-time monitoring across distributed environments.
Splunk CloudCloud analytics and log management2013
Splunk Cloud provides hosted delivery of Splunk's data-ingestion, search, analytics, visualization, and alerting capabilities. It is designed for organizations that want Splunk functionality without operating the full platform on their own infrastructure and supports cloud, hybrid, and multicloud operating models.
Splunk Enterprise SecuritySecurity information and event management
Splunk Enterprise Security is a security analytics and SIEM product that correlates telemetry from networks, endpoints, identities, access systems, vulnerabilities, and malware controls. It helps security teams investigate events, prioritize risk, monitor threats, and support incident-response and compliance workflows.
Splunk Observability CloudObservability2020
Splunk Observability Cloud brings together infrastructure monitoring, application performance monitoring, digital experience monitoring, log investigation, tracing, and incident-response capabilities. It is intended to provide engineering and operations teams with a unified view of services and dependencies across cloud-native and distributed environments.
Splunk SOARSecurity orchestration and response
Splunk SOAR helps security teams automate repetitive response tasks, orchestrate workflows, and connect security tools across cloud, on-premises, and hybrid deployments. Its community edition provides limited daily action capacity for organizations evaluating security automation.
Splunk IT Service IntelligenceIT operations management2015
Splunk IT Service Intelligence uses data from the Splunk platform to monitor service health, identify anomalies, investigate probable causes, and show the business impact of IT incidents. It is aimed at service-management and operations teams responsible for complex enterprise environments.
Splunk Mission ControlSecurity operations2019
Splunk Mission Control unifies security monitoring and response functions, including SIEM, user-behavior analytics, and orchestration capabilities. It is designed to help analysts triage alerts, investigate incidents, coordinate response actions, and manage security operations across multiple data sources.
SplunkbaseSoftware marketplace and ecosystem
Splunkbase is Splunk's community marketplace for apps, add-ons, integrations, and extensions. These components connect Splunk with vendor products and specialized use cases, helping customers expand ingestion, dashboards, analytics, and workflows without building every integration themselves.
Flagship businesses
- Splunk Enterprise
- Splunk Cloud
- Splunk Enterprise Security
- Splunk Observability Cloud
- Splunk SOAR
- Splunk IT Service Intelligence
Marketing campaigns
- 2020McLaren Racing technology partnership
International motorsport
Splunk became McLaren Racing's official technology partner after working with the organization on data from race cars and broader team operations. Splunk analyzed telemetry from hundreds of sensors and supported performance insight across McLaren Racing and esports activities.
Outcome. The partnership provided a prominent demonstration of Splunk's observability and analytics capabilities in high-performance, real-time environments.
- 2018Trek-Segafredo technology partnership
International professional cycling
Splunk became technology partner of the Trek-Segafredo professional cycling team, with the partnership beginning in 2019. Splunk provided data analysis involving riders, coaches, mechanics, and team operations, while its branding appeared on team equipment and vehicles.
Outcome. Expanded Splunk's visibility in sports and demonstrated data-analysis applications outside conventional enterprise IT.
Brand decisions
- 2024Integration into Cisco's observability and security portfolioStrategy
Following the acquisition, Cisco sought to combine Splunk's data and security platform with its networking and application-observability assets.
What changed. Cisco aligned Splunk with its wider software portfolio and moved Cisco AppDynamics observability development into the Splunk organization.
Aftermath. Splunk remained a distinct operating brand while becoming a central component of Cisco's security, observability, data, and AI strategy.
- 2023Agreement to be acquired by CiscoM&A
Splunk and Cisco sought to combine security, observability, networking, and data capabilities as enterprise infrastructure became increasingly distributed.
What changed. Cisco agreed to acquire Splunk in an all-cash transaction valued at $28 billion.
Aftermath. The transaction closed on March 18, 2024. Splunk became a Cisco subsidiary and was integrated into Cisco's software, security, observability, and enterprise-AI strategy.
Announced transaction value. $28 billion (September 2023 acquisition announcement)
- 2019Launch of Splunk Mission ControlProduct launch
Splunk was consolidating security information, user-behavior analytics, and automated response capabilities.
What changed. The company introduced Mission Control as a more unified experience for security detection, investigation, and response.
Aftermath. The move strengthened Splunk's positioning as a security-operations platform rather than only a log-analysis product.
- 2015Introduction of Splunk IT Service IntelligenceProduct launch
Customers increasingly needed service-level visibility and root-cause analysis across complex IT environments.
What changed. Splunk launched IT Service Intelligence to apply its data platform to service monitoring, anomaly detection, and impact analysis.
Aftermath. The product became part of Splunk's broader IT operations and observability portfolio.
- 2011Launch of Splunk StormProduct launch
Splunk began testing a hosted, cloud-based form of its core machine-data platform.
What changed. The company introduced Splunk Storm as a managed service for collecting and analyzing machine data.
Aftermath. Splunk later shifted emphasis toward Splunk Cloud and discontinued Storm in 2015.
Leadership
| Name | Title | Tenure |
|---|---|---|
| Gary Steele | Chief Executive Officer; later Cisco executive and Splunk general manager | 2022– |
| Graham Smith | Interim Chief Executive Officerformer | 2021–2022 |
| Doug Merritt | President and Chief Executive Officerformer | 2015–2021 |
| Erik Swan | Co-founderformer | 2003– |
| Michael Baum | Co-founderformer | 2003– |
| Rob Das | Co-founderformer | 2003– |
Recent events
- 2024Cisco completes acquisition of Splunk
Cisco completed the acquisition on March 18, 2024. Splunk became a Cisco subsidiary and ceased operating as an independent public company.
M&A - 2024Splunk prevails in software infringement case against Cribl
A jury found in Splunk's favor in an infringement dispute involving Cribl and awarded one dollar in damages.
Lawsuit - 2023Cisco announces $28 billion acquisition of Splunk
Cisco announced an all-cash agreement to acquire Splunk for $28 billion, subject to closing conditions and regulatory review.
M&A - 2023Splunk announces workforce reductions
Splunk disclosed workforce reductions during the period surrounding the Cisco transaction. Gary Steele said the cuts were not caused by the acquisition agreement.
Other - 2022Gary Steele appointed chief executive
Splunk selected Gary Steele, formerly chief executive of Proofpoint, as successor to interim CEO Graham Smith.
Leadership change - 2021Doug Merritt steps down as chief executive
Doug Merritt left the chief executive role, with chairman Graham Smith becoming interim CEO.
Leadership change - 2020Splunk launches Splunk Ventures
The company created venture programs focused on early-stage technology investment and social impact.
Other - 2012Splunk completes initial public offering
Splunk began trading publicly on Nasdaq under the ticker SPLK, supporting its expansion as a machine-data software company.
Other
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/splunk · Editorial policy · How profiles are compiled