This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

Splunk Inc.
8/23/2023
Good afternoon. My name is Krista and I'll be your conference operator today. At this time, I would like to welcome everyone to the Splunk second quarter, 2024 financial results conference call. All lines have been placed on mute to prevent any background noise. After the speaker's remarks, there will be a question and answer session. If you would like to ask a question during that time, simply press star followed by the number one on your telephone keypad. And if you would like to withdraw your question, press star followed by the number one. Thank you. I will now turn the call over to Katie White, Director of Investor Relations. Please go ahead.
Thank you, Krista. Good afternoon, and thank you for joining today's call. With me on the call are Gary Steele, President and CEO, and Brian Roberts, CFO. After market closed today, we issued our earnings press release, which is also posted on our investor relations website, along with supplemental material. This conference call is being webcast live, and following the call, an audio replay will be available on our website. On today's call, we will be making forward-looking statements, including financial guidance and expectations, including our growth and profitability statements, forecast for our third quarter and full year fiscal 2024, and our future expectations of revenue, total ARR, cloud mix, non-GAAP operating expenses, non-GAAP operating margin, free cash flow, free cash flow margin, cloud DBNRR, cloud growth margin, equity compensation usage, and liquidity, as well as trends in our markets and our business, our strategies and expectations regarding our business, AI, acquisitions, products, technology, customers, demand, and regulatory environment. These statements are subject to risks and uncertainties and are based on our assumptions as to the macroeconomic environment and reflect our best judgment based on factors currently known to us. Actual events or results may differ materially. Please refer to documents we file with the SEC, including our Form 10-K and 10-Qs, as well as the Form 8-K filed with today's press release. These documents contain risks and other factors that may cause our actual results to differ from those contained in our forward-looking statements. These forward-looking statements are being made as of today, and we disclaim any obligation to update or revise these statements. If this call is reviewed after today, the information presented during this call may not contain current or accurate information. We will also discuss non-GAAP financial measures, which are not prepared in accordance with generally accepted accounting principles. A reconciliation of GAAP and non-GAAP results is provided in the press release and on our website. So with that, let me turn it over to Gary.
Good afternoon, and thank you for joining today's call. To start, Splunk delivered a solid second quarter. Through our ongoing focus on execution, operational discipline, and customer engagement, we met or exceeded each of our guided metrics in Q2. I'm really pleased with these results and want to thank the entire Splunk team for their hard work and commitment. At the same time, we further accelerated Splunk's innovation to help our customers achieve resilience across their digital systems through a series of important and exciting announcements. I'll cover our financial results first. Since joining Splunk 16 months ago, we've been executing to drive long-term durable growth with increasing profitability. Our Q2 results yet again showcase our ability to deliver on that strategy, particularly through ARR and free cash flow growth, which we believe are the best top and bottom line metrics of the health and strength of our business. In Q2, we grew total ARR to $3.858 billion, a 16% year-over-year increase, exceeding the guidance we shared on our last earnings call by over $30 million. Cloud ARR increased 27% year-over-year to $1.918 billion. And our Q2 total revenue grew to $911 million, a 14% year-over-year increase well above our previously guided range. We delivered our top-line growth while maintaining a sharp focus on operating efficiency and controlling costs. In fact, that focus enabled us to reduce non-GAAP OPEX by 3% year-over-year, which is significant given that we previously anticipated an increase of between 2% and 2.5%. What's more, we exceeded expectations for free cash flow in Q2, delivering positive 4 million, nearly 20 million above our guidance. Given our considerable progress on driving more efficient growth, we are increasing our full-year outlook for free cash flow. Brian will share our updated guidance shortly. We're proud of what we delivered this quarter, even as the uncertain macro environment remained largely consistent with what we've seen throughout this year. Our Q2 performance clearly demonstrates that we have dialed in our ability to navigate the current landscape and execute with consistency to deliver durable growth and profitability. What's also evident is that organizations around the world need Splunk's world-class unified security and observability platform more than ever to underpin the resilience of their digital systems. Since becoming CEO, one of my top priorities has been to increase the pace of our innovation. As the technology landscape evolves and becomes more complex, organizations need to see and understand what's happening in their environments in order to keep their systems safe and reliable. In the simplest sense, if you can't see it, you can't secure it, you can't keep it up and running either. I hear time and again from CISOs, CIOs, and CTOs that Splunk's commitment to providing comprehensive visibility into and across environments is critical in today's hybrid multi-cloud world. I'll spend the next few minutes sharing how we're deepening that commitment by taking you through what we announced in July at Splunk's annual user conference, .conf23. During our last earnings call, I spoke about our enthusiasm that AI would fundamentally transform the way organizations keep their digital systems secure and reliable. Given Splunk's flexible and highly scalable data architecture, our industry-leading security and observability solutions, and our quickening pace of innovation, we are in a unique position to help enterprises bolster resilience by harnessing AI across our product portfolio. During .conf23, we unveiled the next step in how Splunk is bringing AI to bear across security and observability. Splunk AI is a collection of new and existing AI-powered offerings that combines automation with human-in-the-loop experiences so organizations can drive faster detection, investigation, and response while controlling how AI is applied to their data. By optimizing domain-specific large language models and machine learning algorithms built on security and observability data, Splunk AI frees up security, IT, and engineering teams for more strategic work, helping to increase productivity and lower costs. In addition, we're applying AI to help teams accelerate time to value through assisted intelligence. Our new Splunk AI Assistant leverages generative AI to provide an immersive chat experience and helps make our search processing language, or SPL, easier to use by enabling the use of natural language to create SPL queries. We're excited that Splunk AI will continue building on our track record of innovation in AI and ML. This includes our recently launched app for anomaly detection that uses ML and our widely used machine learning toolkit. Looking forward, we see broad opportunities to further apply AI to make our core platform and premium products that much more powerful through advanced functionality. At .conf, we also introduced many new products and features that empower security, IT, and engineering teams with unified experiences and workflows so they can detect, investigate, and respond to threats quickly, accurately, and at scale. In security, we announced multiple new features for our award-winning enterprise security and SOAR products, and we also announced the general availability of Splunk Attack Analyzer, which integrates the capabilities we acquired from TwinWave last year into our unified security operations experience. Splunk Attack Analyzer is already being used by some of the world's largest companies, to analyze threats, including those that employees reported as suspected phishing emails. Through an integration with Splunk SOAR, customers that are using Splunk Attack Analyzer and SOAR can fully automate the threat analysis process to ensure accurate and timely detections while reducing the time and resources typically spent doing manual investigations. We also shared our continued delivery on our Unified Security Operations Center vision which aligns to the threat detection, investigation, and response, or TDIR framework. The cornerstone of our approach is Splunk Mission Control, which brings together security analytics, automation and orchestration, and threat intelligence capabilities under one common work surface, empowering security teams to stay ahead of cyber threats. By unifying, simplifying, and modernizing how Splunk is used in the SOC, We're helping teams overcome the challenge of having too many disparate tools, too little time, and nonstop threats and alerts coming across their console. On the observability side, we were named a leader in the 2023 Gartner Magic Quadrant for application performance monitoring and observability. This recognition builds on our nine consecutive times of being named a leader in the 2022 Gardner Magic Quadrant for security information and event management. Today, Splunk is the only vendor to be named a leader in both of the Gardner Magic Quadrants. Our goal is to create a single unified experience for security, IT, and engineering teams across security and observability. To that end, we continue to unify Splunk Observability Cloud with the Splunk platform. In 2022, we launched Splunk LogObserver Connect, enabling observability cloud users to seamlessly use their Splunk Enterprise and Splunk Cloud platform data. We didn't stop there. In Q2, we previewed the OpenTelemetry Collector as a technical add-on, which provides customers with a unified view of their infrastructure and services. We also launched Unified Identity to give our customers a better user experience as they access data from the Splunk Cloud Platform and Splunk Observability Cloud without the need to authenticate multiple times. Looking ahead, we're continuing to invest in the enterprise-grade observability solutions organizations need to monitor and troubleshoot across the entire tech stack. A guiding factor in our innovation is a belief that organizations shouldn't be locked into one environment and should have choice in how they architect their systems across the multi-cloud hybrid world. We're continuing to find ways to make sure that Splunk is available natively to customers in the cloud environments that work best for them. That's why one of the most exciting announcements at .com was our new strategic partnership with Microsoft to build Splunk's cloud solutions natively on Microsoft Azure. Together, our approach will enable our joint customers to migrate, modernize, and grow their environments with end-to-end cloud and hybrid visibility at scale. In addition, organizations globally can now purchase Splunk Enterprise, Splunk Enterprise Security, and Splunk IT Service Intelligence in the Azure marketplace. We're powering thousands of our joint customers with best-in-class solutions, and I'm glad to share that the first transaction closed in Q2 was a boomerang customer returning to Splunk thanks to the flexibility and value our approach provides. Another area where we're continuing to invest is in driving innovation at the edge. Given the explosion of data, processing information on the edge has become a critical priority, both for Splunk and our customers. Last quarter, we launched Splunk Edge Processor, which helps our customers process data at the edge to increase visibility and control over their data before it leaves their network and helps ensure that it ends up at the right destination in the right format. We know this is an essential capability, and we are proud to offer Edge Processor for free to our Splunk Cloud customers. As Edge Processor is adopted by our customer base, we believe it will significantly reduce the need for customers to leverage external vendors to pre-process their data. Related to this, a few of you have asked us about our ongoing lawsuit against Kribble. Although my ability to comment on active litigation is limited, I can tell you that the litigation is very active and the case is scheduled to go to trial in April of 2024. You may recall that this case is about Kribble taking and illegally using our intellectual property, and indeed, Kribble has conceded that it reverse-engineered features in Splunk software. Our case is strong, and we look forward to continuing to prove it. Shifting back to our Edge innovation, another exciting announcement during the quarter was Splunk Edge Hub. which provides more complete visibility across IT and OT environments by streaming previously hard-to-access data directly into the Splunk platform. For manufacturers, factory floors, server rooms, and more, Edge Hub simplifies the ingestion and analysis of data generated by sensors, IoT devices, and industrial equipment, enabling advanced monitoring, investigation, and response. Edge Hub is sold exclusively through our go-to-market partners who bring deep industry expertise on our customers' OT environments. And I'm pleased to share we're seeing compelling customer use cases from early adopters. For example, a multinational manufacturing company uses EdgeHub to interface with their production systems to collect machine data to classify defects. With over one million annual consumer device production capacity, this organization is continuously looking for incremental quality improvement opportunities to save costs and assess factory expansion needs for increases in customer demand. After deploying EdgeHub, the organization achieved a reduction of approximately 70% in defective parts during their QA process, resulting in more than 20% labor cost savings associated with otherwise scrapped or reworked products. We're excited to have once again broken down a barrier for our customers to gain more visibility into their data and we're looking forward to building on Edge Hub's early success. Let's change gears and highlight the continued demand we're seeing from customers around the world. We ended Q2 with 834 customers with $1 million or more in ARR, up by 24 since just last quarter. This includes 452 customers with cloud ARR over $1 million. which is up by 100 year over year from the 352 cloud customers with ARR over a million dollars in the year-ago period. Our team landed many significant deals in Q2 that illustrate our growth levers and the breadth of value we bring to the largest and most complex global enterprises. I'll start with observability. Since 2018, we've built, acquired and integrated what we believe are the best technologies to help enterprises monitor, operate and improve their hybrid technology environments. Our rapid innovation and investments in observability are paying off for Splunk and our customers. We're continuing to win significant deals and displace leading competitors by offering customers comprehensive observability solutions in a unified experience. During Q2, We were pleased to secure a seven-figure observability deal and extend our footprint within a leading U.S. financial services organization. This customer needs to close their visibility gaps and requires a complete hybrid platform solution that eases resource constraints and consolidates their observability tools and costs as they prepare to move more than 150 applications to the cloud. We were already their trusted security provider, and through a technical proof of concept, we demonstrated not only the observability features needed for their transformation and full visibility, but also the vital platform integration capability to complement their existing use of Splunk and help them avoid tool sprawl, data silos, and waste. In Q2, a U.S.-based multinational conglomerate and longstanding hybrid security customer, significantly expanded their use of Splunk by shifting more of their workload to cloud and through a new seven-figure, three-year observability deal for the new healthcare division and cloud stack. They chose Splunk observability over competitive options because of our ability to drive lower total cost of ownership and because our differentiated capabilities offer full visibility by using not only metrics and traces, but also underlying logs, helping enhance resilience by proactively preventing outages while also monitoring critical infrastructure and applications. The market for observability is growing rapidly, and only Splunk has the integrated, enterprise-grade solutions needed by the IT and engineering teams of the Global 2000 to keep their services up and running. Now, turning to security. Since joining Splunk, I've led the team to deliver better outcomes and more value to our customer security leaders by making the work of their security teams that much more effective and efficient. During the quarter, we continue to see strong demand for industry-leading SIEM and premium security solutions needed in the modern SOC. In Q2, we secured a significant cloud deal with a global leader in transport and logistics. Following a competitive selection process, this European Europe-based organization chose Splunk to support and consolidate its complex security needs on a global level. This seven-figure Splunk Cloud and Splunk Enterprise Security deal displaced a legacy SIM competitor and is a result of our growing strategic partnership to help them drive resilience through our single, unified platform. We also secured a new logo win during Q2 in Europe for Splunk Cloud and Splunk Enterprise Security with a global automotive technology company. The customer chose Splunk over competitors due to limitations in their legacy SIM and because of our ability to provide full visibility across all of its data sources from over 150 sites globally. The organization is expanding rapidly in software development and with 200,000 employees now counts on Splunk to keep their system safe and reliable as they scale. Our public sector momentum also continued in the quarter with an eight-figure security expansion and renewal with a large US federal agency that is all in on Splunk. They have centralized their modernization and cybersecurity operations strategy around Splunk and are also delving into both AIOps and ITOps with us. As of Q2, they ingest 30 times more data per day than they did in 2019, leveraging hundreds of SIM use cases as well as several of our premium applications, including nearly 50 SOAR automation playbooks. Our work with government agencies is incredibly important, and we're proud of our partnership with this agency to advance their security operations to keep public information safe from threat actors while ensuring a world-class user experience across several applications. Looking ahead at security, we fundamentally believe that Splunk will continue to play a critical role in helping organizations navigate the evolving cybersecurity landscape. One important example where innovation and security leadership will be essential is helping our U.S. public company customers comply with the SEC's recently announced rules on cybersecurity incident disclosure that will be effective later this year. With a four business day window to report once a cybersecurity incident is deemed material, timely response is essential. Splunk's strength is detection and response, and the investigative capabilities we provide can help customers quickly gather and analyze telemetry from various tools and sources to classify an event and determine if it's material and requires SEC reporting. Our ability to see across vast quantities of data helps organizations quickly understand not only if something happened, but also how it happened. We believe our security solutions will be even more critical as organizations invest in broader resilience strategies to mitigate future cyber threats and improve visibility into their IT infrastructure and accelerated detection and response. This is yet another dimension of value we bring as a strategic partner to our customers' executives as the cybersecurity landscape evolves. Finally, Our customers can continue to tell us there's incredible value when they utilize both security and observability to solve their complex disability challenges. During the quarter, we deepened our strategic partnerships with many organizations on their path to greater resilience through unified security and observability. We secured a seven-figure security and observability deal in Q2 with a multinational banking and financial services company headquartered in the Asia-Pacific region. This milestone renewal and expansion deal took place in a highly competitive landscape, and it represents the deep-level engagement in our partnership over several years. We previously transitioned this organization from on-prem to the cloud, and now our momentum continues as they double down on our security and implement Splunk Observability to meet their evolving needs. To wrap up, I want to reflect on the journey Splunkers and I have been on for the past 16 months. When I joined Splunk, my thesis was that we could accelerate Splunk's 20 years of industry leadership to deliver even more exceptional customer and shareholder value. I've since led the team to build more executive-level customer relationships. We are a vital strategic partner to customers worldwide, and we are focused on serving their expanding needs by increasing the pace of innovation. Along the way, we have cultivated the leadership and talent needed to drive durable growth with increasing profitability. Our results demonstrate that my thesis is proving out and that Splunk is the key to enterprise resilience. Thank you again for joining today's call. Now over to Brian to walk through our financial results and outlook. Thanks, Gary.
You're reading a preview of the SPLK Q2 2024 earnings call.
Free account.