Compare · Splunk

Kloudfuse vs Splunk

Splunk Platform, Splunk Observability Cloud and Splunk AppDynamics have different deployment models, pricing and compliance coverage, so a comparison depends on which product is doing the observability work. Kloudfuse runs inside your cloud and prices on one axis: telemetry ingested.

Why teams switch from Splunk.

The biggest differences come down to how the platform is deployed, how usage is priced, and what happens as data volume and complexity grow.

Observability and the platform are two contracts

Splunk Observability Cloud is priced per host — $15 for infrastructure, $60 for app and infrastructure, $75 end-to-end.

Cardinality limits can drop new series

A metric time series can carry at most 36 dimensions, and invalid datapoints are dropped without an error. New MTS creation is throttled at 6,000 per minute; past that limit, new series are dropped, again without an error.

Full-fidelity ingest does not mean unlimited retention

Splunk ingests full-fidelity traces rather than sampling them. Raw traces are kept for 8 days by default, and extended retention applies only to traces opened in the UI within 7 days and 20 hours.

What Splunk charges for, meter by meter
Infrastructure$15 per host / monthObservability Cloud
App + infrastructure$60 per host / month
End-to-end$75 per host / month
APM standaloneFrom $55 per host / month
RUMFrom $14 per 10,000 sessions
Custom metrics100–200 MTS per hostEntitlement, not a price; histograms bill as 8 MTS each
LogsNot publishedBilled on a separate Splunk Cloud Platform or Enterprise licence, on workload (SVC) or ingest pricing — neither has a public list price

Splunk list pricing, August 2026. View current pricing →


Splunk and Kloudfuse, line by line.

Where the data plane runs, what each meter charges for, and what each platform will and will not do. Where a vendor does not publish something, the table says so.

 SplunkKloudfuse
Where it runs
Data plane locationSplunk Observability Cloud is SaaS only. Splunk Enterprise is self-hosted and Splunk AppDynamics offers an on-premises option, but those are different products with different contracts — the observability platform itself has no customer-hosted deployment.Inside your VPC. Ingest, storage, query engine and the AI runtime all deploy into your own cloud account, writing to your object storage under your keys. Only metadata reaches Kloudfuse.
AWS, GCP and AzureYes. AWS · GCP · AzureYes. AWS · GCP · Azure
Drop-in migration from their agentNot published. Splunk OTel distributionYes. Datadog and OpenTelemetry agents accepted
What it costs
What you are billed onPer host, in three tiers, plus RUM sessions. Logs are billed separately under a Splunk Cloud Platform or Enterprise licence, on workload (SVC) or ingest pricing — neither of which Splunk publishes a list price for, so the largest line in most observability bills cannot be modelled from public information.One axis: terabytes ingested, across every signal. Storage and compute land on your own cloud bill because the platform runs in your account.
High cardinalityHard limits with silent failure. Maximum 36 dimensions per metric time series; invalid datapoints dropped without error. MTS creation throttled at 6,000 per minute, with new series dropped past the limit. Custom metric entitlements are 100–200 MTS per host; histograms bill as 8 MTS each.No cardinality premium, no active-series cap, no per-custom-metric charge. Adding a label does not change the bill.
RetentionMetrics 13 months at 1-minute resolution, 8 days below it. Raw traces 8 days by default. RUM spans 8 days. Extended trace retention only applies to traces viewed in the UI within 7 days and 20 hours.Your bucket, your lifecycle policy. Long retention is a storage decision rather than a pricing tier.
Your data
SamplingFull-fidelity trace ingestion — genuinely no sampling at ingest. Retention is where the fidelity is lost, not collection.No forced sampling. Full fidelity across metrics, logs, traces, events, RUM and profiles.
Every signal in one storeNo. Logs sit on a separate platform licenceYes. One data lake
Log pattern reduction at ingestNot published. Not published as an ingest controlYes. Fingerprinting at ingest
Works with existing Grafana dashboardsNot published. No first-party datasourceYes. Kfuse datasource
PortabilitySPL and the Splunk agents, though the Splunk Distribution of the OpenTelemetry Collector is the supported collection path for Observability Cloud.Built on OpenTelemetry, with Grafana-compatible dashboards through the Kfuse datasource and support for TraceQL and PromQL. Your data stays in your object storage. Your instrumentation and dashboards remain portable and independent of Kloudfuse.
AI
Agents and assistantsSplunk AI Agent Monitoring for LLM and agent observability, GA in 2026. Pricing is not on the public pricing page.Dexter runs inside your boundary, on the model you choose, including a local one. Prompts and completions stay inside the boundary. A human stays in control.
Inference inside your own boundaryNo. Splunk-hostedYes. Dexter runs in your VPC
Security and compliance
Government and regulatedSplunk Observability Cloud holds no FedRAMP authorisation at any level — not Moderate, not High — per Splunk’s own compliance matrix; it is listed as In Process for Moderate. Splunk Cloud Platform holds Moderate and High, and AppDynamics GovAPM holds Moderate. Observability Cloud also does not hold PCI.The data plane runs inside whatever boundary you have already had authorised. FIPS 140-3 validated cryptography (CMVP #5186, #5209); FedRAMP-targeted installations run with EBS encryption.
SOC 2 Type IIYes. Type IIYes. Type II
HIPAANot published. Not stated for Observability CloudPartly. In progress
FIPS-validated cryptographyNot published. Not publishedYes. 140-3 · CMVP #5186, #5209
Data residencyPartly. Region choice, inside their boundaryYes. Structural — your own VPC

YesPartlyNoNot published


Common questions when comparing Splunk and Kloudfuse.

Splunk is FedRAMP authorised, isn’t it?

Splunk Cloud Platform is, at both Moderate and High. Splunk Observability Cloud is not — no module of it holds an authorisation at any impact level, and Splunk’s own blog describes it as In Process for Moderate. The two are commonly conflated because they share a brand. If your requirement is a FedRAMP-authorised APM from Splunk today, the answer is AppDynamics GovAPM at Moderate.

Is AppDynamics being sunset now that Cisco owns Splunk?

No. Cisco consolidated AppDynamics, Splunk Platform, Observability Cloud and ITSI into one portfolio and renamed Cisco AppDynamics to Splunk AppDynamics. Splunk states explicitly that no migration is required and that AppDynamics remains a critical component.

What does the 6,000 MTS per minute throttle mean in practice?

It means a bad deploy that adds a high-cardinality tag does not page you and does not bill you — it quietly stops creating new time series, and the dashboards you would use to diagnose it have gaps. Existing series keep accepting datapoints, which makes the failure harder to spot, not easier.

We use Splunk for security as well as observability. Does that change things?

It changes the comparison. Splunk Enterprise Security holds a FedRAMP High authorisation, and if SIEM and observability share one platform licence for you, the two workloads are not separable on price. The question becomes whether observability should be the workload that sets that licence.

Bring an incident. We'll bring the platform.

Run Kloudfuse against your own telemetry, in your own cloud, and see what a single correlated view does to your mean time to resolution.