Vendor lineage
Splunk
Named after caving, because that is what searching your own logs felt like.
Michael Baum, Rob Das and Erik Swan founded Splunk in San Francisco in October 2003, having each spent years on infrastructure software and arrived at the same complaint: finding anything in machine-generated logs meant crawling through them by hand. They named the company after spelunking.
The technical decision that made it work was schema-on-read. A relational database demands you decide the shape of your data before you store it, which is impossible when the data is whatever a hundred different systems happen to emit. Splunk indexed the text as it arrived and let structure be applied at search time instead. That inversion is why it could ingest anything, and it is the idea the whole product rests on.
The go-to-market was equally deliberate: a free tier of 500MB a day, adopted by engineers who then brought it into their employers. Bottom-up rather than top-down, years before that was a recognised strategy.
It raised about $40M in total - modest for what it became - was profitable by 2009, and went public in 2012 at roughly $1.6B. Baum had stepped down as chief executive in 2009; he moved to Burgundy in 2014 and bought a winery, which is a more graceful exit than most of this timeline offers.
Cisco announced the acquisition on 21 September 2023 and completed it on 18 March 2024 for approximately $28B, one of the largest software deals ever made. Cisco is a chapter in this site's own career record, so the two ends of that transaction both appear on this page.
Founding stories
Splunk
Three people who had each spent years on infrastructure software and arrived at the same complaint: the data that tells you why a system failed already exists, in logs, and there is no good way to search it. The name comes from spelunking, because that is what working through your own log files felt like.
The timeline
- Founded
In San Francisco, on the observation that machine-generated data was abundant and unsearchable.
- NASDAQ listing
Listed as SPLK at roughly $1.6B, having raised only about $40M in total - unusually little for the scale it reached.
- SignalFx
Acquired for around $1.05B, and the foundation of the observability business: streaming metrics and application performance monitoring alongside the log platform.
- Cisco announces
Announced 21 September at approximately $28B, one of the largest software acquisitions on record.
- Completion, and an unusual direction of travel
Closed 18 March. Gary Steele moved up into Cisco while remaining Splunk's general manager - and Cisco moved its own AppDynamics observability product into Splunk rather than the other way round. An acquirer folding its existing product into the company it just bought is a statement about which platform it considers the survivor.
Steele's dual role and the AppDynamics move per contemporary trade reporting and Wikipedia's summary.
- Talos inside Splunk
Cisco's threat intelligence began shipping inside Splunk Enterprise Security at no additional cost, which is the clearest concrete benefit of the acquisition to an existing customer.
Flagship products and solutions
- Splunk Enterprise and Splunk CloudThe core platform: ingest anything, index it, search it. Sold on data volume per day, on-premises or hosted.
- SPL, the Search Processing LanguageThe query language, and the reason practitioners stay. It correlates across sources in a single search - container crash loops against cloud API failures against directory authentication - which is the capability users cite first and the thing hardest to reproduce elsewhere.
- Splunk Enterprise SecurityThe SIEM, now with user behaviour analytics and automation built in rather than sold alongside, and with risk-based alerting aimed at the volume problem that makes security operations centres unworkable.
- Splunk SOAROrchestration and automated response, built out from the Phantom acquisition, with several hundred prebuilt playbooks and integrations into other vendors' tools.
- Observability Cloud, ITSI and AppDynamicsMetrics, traces and service-level monitoring - the SignalFx line, joined after the acquisition by Cisco's own application performance product.
- SplunkbaseSeveral thousand community and vendor apps and add-ons. The ecosystem is a substantial part of why the platform is where an organisation's data ends up.
Key innovations
- Schema-on-readStore the data first and decide what it means when you query it. That inverts the database assumption, and it is the only workable answer when the question you will need to ask has not happened yet - which is the normal condition of an incident.
- Making logs a first-class data typeBefore this, logs were something you tailed when something broke. Treating them as a searchable corpus with a query language turned an operational nuisance into an analytics category, and the security and observability markets both grew out of that reframing.
- The language as the moatSPL is powerful and proprietary, and those are the same fact. Every saved search, dashboard and detection rule an organisation writes is an asset that only runs here, so leaving means rewriting years of accumulated work rather than exporting data.
- Bottom-up adoptionA free tier that engineers installed themselves, then brought to their employers. Reaching the buyer through the practitioner rather than the other way round was unusual for enterprise infrastructure in the 2000s and is now the standard playbook.
Main markets
Security operations and IT observability, sold to large enterprises - reported in use at more than ninety of the Fortune 100, processing volumes measured in exabytes per day. The customer is an organisation with enough data that finding anything in it has become its own problem.
Two criticisms are consistent enough in customer feedback to belong in any honest description. It is expensive - volume-based pricing at scale is the most frequent complaint, and deployments of a hundred gigabytes a day are quoted in the hundreds of thousands per year. And migrating away is costly for the reason above: the queries do not travel. Competitors including CrowdStrike, whose own SIEM appears elsewhere on this timeline, position explicitly against both.
Analyst standing
- A Leader in Gartner's SIEM Magic Quadrant for more than ten consecutive evaluations, placed highest for ability to execute in 2025, and a Leader in observability platforms for three years running - reportedly the only vendor to hold both simultaneously three times.
- The open question under Cisco is whether a platform whose strength is being vendor-neutral about data sources stays that way inside a networking company, and the early evidence points both ways: Talos intelligence added at no cost is a customer benefit, while AppDynamics moving in is consolidation.
Acquisitions
2013 BugSense and Cloudmeter
Mobile analytics and network data capture, bought within months of each other.
Mobile intelligence and wire-data ingestion.
2018 VictorOps $120M
On-call incident management.
Splunk On-Call.
2019 SignalFx $1.05B
Real-time cloud monitoring, and the largest purchase Splunk made.
Splunk Observability Cloud - the second half of a story that had been only about logs.