Skip to main content

Is Splunk Down?

No — Splunk is up

Reachable from all 8 checked regions

Average response time: 316ms

Last checked · checks run every 6 hours

Official status page: https://status.splunkcloud.com

Splunk uptime

100%
Last 7 days
100%
Last 30 days
100%
Last 90 days
436ms
Avg response, 30 days

Measured from multiple regions every 6 hours. Percentages count only checks that returned an availability answer — 20 days measured so far. A dash means that window does not yet hold enough measured days to publish a figure.

30-day history

20-day clean streak
Jul 25: no data
Jul 26: no data
Jul 27: no data
Jul 28: no data
Jul 29: no data
Jul 30: no data
Jul 31: no data
Aug 1: no data
Aug 2: no data
Aug 3: no data
Aug 4: 100.00% uptime, 16 checks
Aug 5: 100.00% uptime, 32 checks
Aug 6: 100.00% uptime, 32 checks
Aug 7: 100.00% uptime, 32 checks
Aug 8: 100.00% uptime, 32 checks
Aug 9: 100.00% uptime, 40 checks
Aug 10: 100.00% uptime, 32 checks
Aug 11: 100.00% uptime, 32 checks
Aug 12: 100.00% uptime, 32 checks
Aug 13: 100.00% uptime, 32 checks
Aug 14: 100.00% uptime, 40 checks
Aug 15: 100.00% uptime, 32 checks
Aug 16: 100.00% uptime, 24 checks
Aug 17: 100.00% uptime, 31 checks
Aug 18: 100.00% uptime, 39 checks
Aug 19: 100.00% uptime, 32 checks
Aug 20: 100.00% uptime, 32 checks
Aug 21: 100.00% uptime, 31 checks
Aug 22: 100.00% uptime, 32 checks
Aug 23: 100.00% uptime, 32 checks
Jul 25 Today
No downtime Partial Downtime Not measurable No data

Reachability by region

Each region runs its own request from a different part of the world. A service can be up for one continent and down for another, which is usually the first sign of a routing or CDN problem.

ams
337ms
DNS 241ms TCP 2ms TLS 6ms TTFB 314ms
lax
311ms
DNS 246ms TCP 1ms TLS 6ms TTFB 300ms
lhr
346ms
DNS 299ms TCP 0ms TLS 17ms TTFB 339ms
nrt
397ms
DNS 337ms TCP 1ms TLS 14ms TTFB 388ms
ord
235ms
DNS 95ms TCP 2ms TLS 5ms TTFB 224ms
sin
279ms
DNS 82ms TCP 1ms TLS 3ms TTFB 176ms
sjc
260ms
DNS 204ms TCP 1ms TLS 4ms TTFB 233ms
syd
448ms
DNS 412ms TCP 0ms TLS 2ms TTFB 440ms
yyz
233ms
DNS 171ms TCP 0ms TLS 3ms TTFB 217ms

What Splunk does

Splunk collects machine data such as logs, metrics and events, indexes it, and makes it searchable for operations and security teams. It is the system people open during someone else's outage, which is why its own availability matters more than its traffic volume suggests. Splunk Cloud Platform is the hosted version; many organisations also run Splunk Enterprise on their own infrastructure.

What an outage looks like

Searches hang, return partial result sets, or fail outright. Dashboards and scheduled reports render empty panels. New data stops appearing, so recent events are missing from search even after indexing recovers and older data still queries fine. Alerts built on saved searches may not fire at all, which is the failure mode security teams notice last.

What to do about it

Check status.splunkcloud.com, which covers Splunk Cloud Platform and lists Login, Search, Index and Infrastructure as separate components, along with Detection Studio, Threat Intel Management, Ingest Processor and Edge Processor. Search failing while Index is healthy means a different problem from ingestion stopping. If you run Splunk Enterprise on your own infrastructure, that status page does not describe your deployment and the fault is likely local.

Is it down for everyone, or just you?

If this page says Splunk is up but it is not loading for you, the problem is between you and them. Run a check against any URL from all 18 regions to find out where it breaks.

Test it yourself

Related services

Splunk outage FAQ

Does status.splunkcloud.com cover self-hosted Splunk Enterprise?
No. That page reports on Splunk Cloud Platform, the hosted service. If you run Splunk Enterprise on your own servers, an incident there says nothing about your deployment, and a search failure is almost certainly local: indexer capacity, a search head problem, licensing, or the forwarders feeding it. Checking a vendor status page for a self-hosted install is a common way to lose the first ten minutes of an investigation.
Is data lost during a Splunk ingestion outage?
Usually it is delayed rather than lost, because forwarders buffer and retry, but the buffer is finite. The Index and Ingest Processor components are listed separately from Search, so ingestion can stall while existing data stays searchable. The practical risk is a long incident overrunning the queue on the sending side. After recovery, compare event counts for the outage window against a normal period.
Will my alerts fire once Splunk recovers?
Not necessarily for the window that was missed. Alerts run on scheduled searches, so if Search was degraded at the scheduled time, that run may simply have been skipped rather than queued. This is the quiet risk in a Splunk incident: the outage ends, dashboards look normal, and nobody notices that a detection did not evaluate. Re-run the relevant searches over the outage window manually.
Is Splunk down, or is my search just slow?
Check the Search component on status.splunkcloud.com first. Splunk searches over large time ranges are genuinely slow under normal conditions, so a query that takes minutes is not by itself evidence of an incident. Compare against a narrow search over recent data: if that returns quickly while a broad one does not, you are most likely looking at query cost rather than an outage.

How we measure this

  • We request Splunk's public endpoint every 6 hours from Fly.io regions across six continents — 8 of them answered the most recent check.
  • A region counts as down only when it gets no usable HTTP response. A 403 or 429 means the origin answered and refused us, which we report as blocked, never as an outage.
  • A single failing region is treated as probe noise. We only change the verdict when two consecutive cycles agree.
  • Response times average only the regions that actually served the page, so a timeout never inflates the number.
  • Where Splunk publishes an official status feed we read it too. An all-clear from the vendor can soften an unconfirmed degradation; a vendor-declared outage only worsens our verdict when our own checks corroborate it.

Get alerted when Splunk goes down

This page refreshes every 6 hours. Your own monitors run as often as every 30 seconds, from the same 18 regions, and tell you the moment something breaks.

Start Free Monitoring
Free plan available No credit card required