| Deployment model |
On-premise, air-gapped, or private cloud |
Self-hosted or Elastic Cloud |
SaaS or self-managed Splunk Enterprise |
| Ingestion throughput (per node) |
50 GB/day |
~30 GB/day (Elasticsearch) |
~60 GB/day (heavy forwarder) |
| Search query language |
Lucene-compatible DSL + quick filter |
Lucene + KQL (Kibana) |
SPL (Splunk Processing Language) |
| Dashboard builder |
Drag-and-drop, 12 widget types |
Kibana Canvas / Lens |
Splunk Dashboard Studio |
| Alert channels |
Telegram, Slack, email, webhook |
Webhook, email (via Watcher) |
PagerDuty, Slack, email, SMS |
| Licensing |
Subscription per GB ingested |
SSPL / Elastic subscription |
Per-GB ingestion license |
| Regulatory compliance (RU) |
FSTEC-certified, data residency guaranteed |
No FSTEC certification |
No FSTEC certification |
| Support SLA |
4-hour response (Business), 1-hour (Enterprise) |
Community or paid Elastic support |
24/7 paid support tiers |
| Estimated TCO (100 GB/day, 3 nodes) |
~₽2.1M/year |
~₽1.4M/year (self-managed) + ops overhead |
~₽5.8M/year |