Splunk
Compliance
- FedRAMP
- Splunk Cloud Platform for FedRAMP High Authorized High · 8 agency authorizations · since Sep 13, 2024
- Splunk Cloud Platform for FedRAMP Moderate Authorized Moderate · 21 agency authorizations · since Oct 11, 2019
FedRAMP status from the FedRAMP Marketplace (evidence)
No tracked subprocessors.
Documents
| Document | Verified | Changed | Evidence |
|---|---|---|---|
| Trust center | snapshot | ||
| Terms | snapshot | ||
| Security page | snapshot | ||
| security.txt | snapshot | ||
| Status page | snapshot |
Subprocessors
None extracted.
Listed as a subprocessor by (14)
Purposes as each company states them.
Adobe adobe.com Splunk assists with security event logging and monitoring via the collection of system data. Logs are generated through Adobe’s software applications and are analyzed and inspected for bugs or system failures in an Adobe-managed Splunk environment. Splunk may process data about Adobe’s operating environment and configuration. This in turn can include user interactions, and sessions related to Adobe’s use of Splunk in which information and related metadata about Adobe’s network and systems architecture configurations is accessible. From a customer data perspective, Splunk may process the number and types of searches, errors, and number of active and licensed users. Additionally, Splunk offers support services to Adobe for troubleshooting which may involve access to user/customer identifiable information. Finally, there is also a possibility of certain customer data (such as IP addresses, names, contact information,) being processed as part of a security investigation, threat detection, or incident monitoring.
Blackbaud blackbaud.com
Culture Amp cultureamp.com All PII fields collected by Culture Amp may be captured and processed by Splunk for the purposes of security monitoring, threat detection, investigation, incident response, and maintaining the security of Culture Amp systems.; Splunk is a security information and event management (SIEM) and analytics platform used to collect, index, search, monitor, and analyse security and operational event data. Splunk Enterprise Security provides additional security monitoring, correlation, alerting, and investigation capabilities to support threat detection, incident response, and security operations.
Digicert digicert.com Support security logging, monitoring, and compliance
Kasten kasten.io Security and observability of Veeam cloud services
Klaviyo klaviyo.com Logging Tool
Notion notion.com Security and application logging
Notion notion.so Security and application logging
Okta okta.com Business analytics
PayPal US paypal.com Application logging and performance monitoring
Pluralsight pluralsight.com Security Management Tool
Salesloft salesloft.com Analyzes telemetry data to increase product availability, performance and reliability; Service provider
UKG ukg.com
Veeam Software veeam.com Security and observability of Veeam cloud services
Security record
What public security catalogs list for Splunk, in their words.
Known exploited vulnerabilities
1 vulnerability in Splunk's software that CISA lists as exploited in the wild.
| CVE | Product | Vulnerability | Listed |
|---|---|---|---|
| CVE-2026-20253 | Enterprise | Splunk Enterprise Missing Authentication for Critical Function Vulnerability |
Source: CISA Known Exploited Vulnerabilities catalog (evidence)
Changes
None since tracking began.