SentinelOne vs Splunk

SentinelOne — Application · Public · $7.5B mkt cap · 4 of 4 figures sourced  |  Splunk — Infrastructure · Acquired · 1 of 1 figure sourced

Relationship

SentinelOne's FY2026 10-K Competition section lists 'SIEM providers such as Cisco Systems, Inc. (which acquired Splunk) and Elastic' among the companies it competes with. The actual competing SIEM product is Splunk Enterprise Security, which Cisco now owns.

3 of 4 capabilitiesShared product typeNamed in filingDetect and respond to security threats

3 of 4 capabilities — Shares data analysis, data security and threat detection and response.

Ludbee capability tags · from the product records

Shared product type — Both ship application and platform.

Ludbee product records

Named in filing — “SIEM providers such as Cisco Systems, Inc. (which acquired Splunk) and Elastic”

sec.gov · checked 2026-09-19

Detect and respond to security threats — Rivals on this job — Spot attacks across endpoints, email, cloud and identity, then triage and contain them.

Ludbee needs vocabulary · the scope on the sourced edge

Aligned comparison

FieldSentinelOneSplunk
Size$7.5B mkt capnot disclosed
Employees2,900—
Founded20132003 10 yrs earlier
StatusPublicAcquired
CategoryApplicationInfrastructure
Stack layerAI agent, Application, Data service, PlatformApplication, Developer tool, Platform
HeadquartersMountain View, USASan Jose, USA

Capability overlap

Shared · 3

Data analysisData securityThreat detection and response

Not verified for Splunk · 1

Guardrails and safety

Recorded for SentinelOne. Splunk’s product records say nothing either way — a missing record is not a missing capability.

Not verified for SentinelOne · 3

Agent orchestrationEvaluation and observabilityModel training

Recorded for Splunk. SentinelOne’s product records say nothing either way — a missing record is not a missing capability.

Products, side by side

Hand-checked pairing

SentinelOne

Application

Prompt SecurityApplication

Discovers and governs employee and developer use of AI services, redacts sensitive data in prompts, controls autonomous agents and MCP servers, and defends custom AI applications against prompt injection, jailbreaks and data poisoning.

Singularity Cloud SecurityApplication

Cloud-native application protection platform that defends production workloads, cloud and AI infrastructure and the data stores feeding models, detecting and responding to threats autonomously across the cloud estate.

Singularity EndpointApplication

AI-powered endpoint security that combines endpoint protection, detection and response, and automated remediation and rollback in a single agent across Windows, macOS, Linux and cloud workloads.

Singularity IdentityApplication

Identity-security module of the Singularity Platform that protects against credential misuse and identity-based attacks.

Singularity MobileApplication

On-device mobile threat defense for iOS, Android and ChromeOS that stops phishing, malware and risky apps with an on-device model and needs no cloud connection to detect.

Wayfinder TDRApplication

Managed AI-assisted threat detection and response (MDR-style) service delivered by SentinelOne's global services team.

Platform

Singularity AI SIEMPlatform

A security information and event management platform that ingests and normalizes cloud, identity, endpoint and third-party telemetry, correlates signals into incidents via Purple AI, and executes containment from the investigation console.

Singularity PlatformPlatform

Umbrella platform that runs SentinelOne's endpoint, cloud, identity and mobile protection on one agent and console with autonomous detection, response and rollback; the modules a buyer licenses are recorded separately.

Splunk

Application

Splunk Enterprise SecurityApplication

Integrated threat detection, investigation and response platform with agentic AI, SOAR, UEBA and SIEM unified into one SecOps experience.

Splunk IT Service IntelligenceApplication

AIOps and service-intelligence solution that uses AI-driven field discovery and AI-generated event correlation, summaries and root-cause guidance to connect IT events to business service health.

Splunk Observability CloudApplication

Observability platform where AI agents correlate signals across domains, propose remediation actions such as rollbacks or capacity changes, and provide dedicated agent/AI-system observability alongside infrastructure monitoring.

Platform

Splunk AI AssistantPlatform

Assistant inside Splunk Cloud Platform that turns plain-English questions into SPL, the query language Splunk searches machine data with, and explains existing searches back to an analyst.

No counterpart

SentinelOne sells these in a stack layer with no product recorded for Splunk yet — nothing on the other side to compare them against.

AI agent

Purple AIAI agent

An agentic AI security analyst embedded in the Singularity Platform that auto-triages alerts, runs investigations and threat hunts, and recommends or executes response actions over OCSF-normalized SentinelOne and third-party telemetry.

Data service

Singularity AI Data PipelinesData service

A security telemetry pipeline service that filters low-value logs, normalizes heterogeneous sources into OCSF, and enriches events before they reach a SIEM, built on technology from SentinelOne's acquisition of Observo AI.

Splunk sells these in a stack layer with no product recorded for SentinelOne yet — nothing on the other side to compare them against.

Developer tool

Splunk AI ToolkitDeveloper tool

Platform for building, deploying and running agentic AI systems on Splunk data.