Menu

Splunk Deepens Its Security Bench With TruSTAR Acquisition

The News: SAN FRANCISCO – May 18, 2021 – Splunk Inc. (NASDAQ: SPLK), provider of the Data-to-Everything Platform, today announced it has signed a definitive agreement to acquire TruSTAR, a San Francisco-based cloud-native security company providing a data-centric intelligence platform. Read the full release in Splunk’s Newsroom.

Analyst Take: Splunk continues to invest in complementary acquisitions that make its security portfolio more extensible and enable customers to scale their cybersecurity efforts.

TruSTAR isn’t a household name by any means. Still, Splunk’s mission continues to zero in on scaling its security business from SecOps tools to a full-scale cloud-based observability platform that enables enterprises to access all data sources and simplify intrusion detection at scale while also responding to threats using increased automation capabilities.

TruSTAR has recently been actively accelerating its ecosystem. In late March, the company announced a key partnership with ServiceNow to implement its Security Incidence Response (SIR) solution to prepare and normalize security intelligence data from multiple sources to distribute information between teams, industry peers, and other data systems. This partnership sought to accelerate automation to remediate threats more quickly. While this joint effort was only recently announced, TruSTAR has been partnering with ServiceNow for nearly 3 years.

The Challenge is in Network Complexity – Splunk Seeks to Simplify 

A modern network provides the enterprises with what is required to keep it secure, but it isn’t always intuitive as these insights are locked in the data. Furthermore, as networks continue to proliferate, including on-prem, hybrid cloud, and containerized nodes, it adds volume and complexity to the data. In its continued evolution, Splunk is looking to build and scale its solutions to make real-time information more accessible and create an end-to-end workflow that incorporates the latest in automation to quickly identify and remediate issues prior to any business disruption.

I see the acquisition as a layer in Splunk’s security platform, in particular, to support its automation, detection, and response workflows coupling broad data sets of first and third-party intelligence sources to leverage internal and historical intelligence sources.

This acquisition will also provide additional resources for TruSTAR customers, which will also be able to take advantage of community and freemium feeds from several of Splunk’s commercial threat intelligence integration partners, including Intel471, Recorded Future, and Mandiant.

Deal Details in Limited Supply

The Splunk press release didn’t provide much detail on the deal size or terms. I believe this is a strategic puzzle piece for Splunk to enrich the offering, and TruSTAR clearly had capabilities that could quickly and seamlessly incorporate into Splunk’s ecosystem. This type of deal fits the historical pattern at Splunk that has included several smaller acquisitions that add key features and match Splunk’s ambitions to scale its offerings and migrate to meet the complexities of shifting IT requirements and a growing focus on enterprise security.

Futurum Research provides industry research and analysis. These columns are for educational purposes only and should not be considered in any way investment advice.

Other insights from Futurum Research:

Juniper Gets More SASE

Cisco Nexus 400G: Delivering Ecosystem-wide Data Center Networking Innovation

Cisco’s Acquisition of Socio Labs Points to the Future of Hybrid Event Management Solutions

Image Credit: Splunk

 

 

Author Information

Daniel is the CEO of The Futurum Group. Living his life at the intersection of people and technology, Daniel works with the world’s largest technology brands exploring Digital Transformation and how it is influencing the enterprise.

From the leading edge of AI to global technology policy, Daniel makes the connections between business, people and tech that are required for companies to benefit most from their technology investments. Daniel is a top 5 globally ranked industry analyst and his ideas are regularly cited or shared in television appearances by CNBC, Bloomberg, Wall Street Journal and hundreds of other sites around the world.

A 7x Best-Selling Author including his most recent book “Human/Machine.” Daniel is also a Forbes and MarketWatch (Dow Jones) contributor.

An MBA and Former Graduate Adjunct Faculty, Daniel is an Austin Texas transplant after 40 years in Chicago. His speaking takes him around the world each year as he shares his vision of the role technology will play in our future.

Related Insights
Is 2026 the Turning Point for Industrial-Scale Agentic AI?
February 5, 2026

Is 2026 the Turning Point for Industrial-Scale Agentic AI?

VP and Practice Lead Fernando Montenegro shares insights from the Cisco AI Summit 2026, where leaders from the major AI ecosystem providers gathered to discuss bridging the AI ROI gap...
Cisco’s "End of Gold": A High-Stakes Pivot to Skills-First Architecture
February 3, 2026

Cisco’s “End of Gold”: A High-Stakes Pivot to Skills-First Architecture

Tiffani Bova, Chief Strategy and Research Officer at The Futurum Group, examines Cisco’s 360 Partner Program and how its redesigned incentives, designations, and tools aim to align partner profitability with...
ServiceNow Q4 FY 2025 Earnings Highlight AI Platform Momentum
January 30, 2026

ServiceNow Q4 FY 2025 Earnings Highlight AI Platform Momentum

Futurum Research analyzes ServiceNow’s Q4 FY 2025 results, highlighting AI agent monetization, platform consolidation in CRM/CPQ, and a security stack aimed at scaling agentic AI across governed workflows heading into...
Microsoft Q2 FY 2026 Cloud Surpasses $50B; Azure Up 38% CC
January 30, 2026

Microsoft Q2 FY 2026: Cloud Surpasses $50B; Azure Up 38% CC

Futurum Research analyzes Microsoft’s Q2 FY 2026 earnings, highlighting AI-led cloud demand, agent platform traction, and Copilot adoption amid record capex and a substantially expanded commercial backlog....
Commvault Q3 FY 2026 Record Revenue, ARR Guide Trimmed
January 29, 2026

Commvault Q3 FY 2026: Record Revenue, ARR Guide Trimmed

Futurum Research reviews Commvault’s Q3 FY 2026 results, citing Unity-led cross-sell momentum, SaaS cohort scaling, identity resilience partnerships, and a modest ARR guide-down from mix and duration normalization....
As CrowdStrike Buys Seraphic, Is Browser Security Destined to Be Just a Feature
January 15, 2026

As CrowdStrike Buys Seraphic, Is Browser Security Destined to Be Just a Feature?

Fernando Montenegro, VP at Futurum, analyzes CrowdStrike's acquisition of Seraphic Security, a strategic move to secure the browser "blind spot" and extend Falcon's visibility to unmanaged devices....

Book a Demo

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.