Excellent. Thank you everyone for joining. My name is Keith Weiss. I run the U.S. Software Research Team here at Morgan Stanley, and very pleased to have with us this afternoon both Gary Steele, CEO, and Brian Roberts, the newly minted CFO over at Splunk. A little six weeks on the job. Thank you. Getting thrown right into the fire. Before we get started, I do have a brief research disclosure. For important disclosures, please see the Morgan Stanley Research Disclosures website at www.morganstanley.com/researchdisclosures. If you have any questions, please reach out to your Morgan Stanley sales representative. Brian, you want to do a quick safe harbor? Sure. Safe harbor, please. We will make forward-looking statements today. Please look at our SEC documents and actual results may vary. Excellent. With that, out of the way, Gary, I want to start with you. Thank you for coming back to the Morgan Stanley TMT Conference. Great to be here. I think this is the just about your one-year anniversary. April is kind of when you started at Splunk. Yep. What have we learned about Splunk over the past year? Like last year you're excited about the opportunity, you're excited about sort of the enterprise customer base and the ability to drive higher cash flows. What's evolved in terms of your thinking on Splunk over the past year? Yeah, I think, a number of things. Mm-hmm. I think, one, you know, obviously, I spent a lot of time with customers over the course of last year. The mission-critical nature that we play for our customers is second to none. Our customers want to do more with us, and I think we can be a very good partner as they continue to evolve their drive for resilience, both on the cyber side as well as on the observability side. The one thing when I joined that I made clear is I believe in balanced growth and profitability. While the company had done a great job of being very growth centered, it was clear to me there was an opportunity to balance continued long-term durable growth with increasing cash flow and profitability. We've been on that journey basically since the day I joined, and I'm really proud of the progress we've made over the course of last year. Finally, I feel like we're well-positioned to drive long-term durable growth in this business. One of my observations early on was that we weren't close enough to our buyers. Specifically, there's more that we could do in security. We could get closer to CISOs, get closer to practitioners. We were very early in our journey from an observability standpoint, and we made some very good progress over the course of last year. I think we have a really good setup coming into this new fiscal year, and I'm super excited about the prospects. Got it. I want to dig into that for a second. When you started at Splunk, the balance and growth of profitability was very evident from kind of day one, and I think investors have seen the yields on that focus. The outlook that you guys gave for the fourth fiscal year in terms of free cash flow definitely surprised guys to the upside. The investments in go-to-market, the investments in product strategy take longer to sort of play out, so it's a little harder for us to get visibility. Can you talk to us about what are some of the key strategic investments that you've made over the past year in the product, in the go-to-market strategy that we should be looking to yield over the next couple of years? I think one of the most important changes we made from a go-to-market perspective, we moved to a single seller model. Historically, we made that change at the beginning of our Q4. Effectively what we had in the past was there were multiple salespeople with different product specialties calling on a single customer. We moved to having a single seller owning that customer, supported by technical strategists, technical people that could then help that sales rep navigate the various deals. This was a big move forward. It's great for customers, and frankly, it improved our cost effectiveness with respect to go-to-market. From an innovation standpoint, one of the things that's really clear to me coming in is that we needed to increase the pace of innovation. That there had been criticism of Splunk that we had slowed down. Through new leadership, we hired a gentleman by the name of Tom Casey. Tom has really reinvigorated growth potential. We've got some exciting things coming out this year and we feel like we're really well-positioned to go continue to drive additional use cases for Splunk, both on the security side as well, more broadly across IT and observability. We think those platform enhancements, the security capabilities, we think will be well received by our buyers. Got it. Got it. Brian, to bring you into the conversation, I think it's always interesting, talking to a new CFO at a company. CFOs definitely see the business most similarly to investors. You're making an investment decision when you decide to join Splunk. What was it that you liked about this investment, that this is the sort of next stop for Brian Roberts? Yeah, absolutely. The Splunk story is one that I've followed for a number of years. When you look at this company, it's an iconic company with like perfect product market fit. Then, when I started to, you know, have an interview for this job, I put myself in your shoes. I try to analyze this company from the outside, and I have a ton of empathy. It is really hard to model. I spent a lot of time. Coming in, one of my key priorities is just how do we simplify it in terms of the story? 'Cause I mean, there's as anyone who looks at term licenses in terms of AIS under ASC 606, it's just very challenging to look at the story. You'll hear Gary and I talk a lot today about ARR and free cash flow. We think those are absolutely the right metrics to track. Got it. Got it. Yeah. I definitely agree with you on the, on the difficulty of the model side of the equation. We call Splunk our associate killer. If you could get Splunk model down, you. It's been a test. You guys- There's a clear route to promotion on team software. If we're thinking about, Brian, if we're thinking about the underlying growth rate, it's ARR. How do you think about the underlying growth rate of the business today, and where do you guys think you could get it to in the medium term? Sure. In terms of the long term, stay tuned for Analyst Day coming later this year. I think when you look at this year, last year, we put up 18% ARR growth. You look at this year, we took the month of January, that's how we built our outlook today, right? What we got into this year was a range of $4.125 billion-$4.175 billion. Net New ARR of roughly $450 million-$500 million, and that's based on what we saw in January. What we did say in part of the earnings call is assuming an economic recovery, which I hope we all agree is coming at some point, along with some of the new product innovation, the resumption of cloud migration, we can see an acceleration in that growth rate next year. Got it. That next year being, like, a calendar 20. Fiscal 2025. Okay. Perfect. Perfect. I want to dig into the product side of the equation. Start on security. Security's now grown to be the majority of the business. How should we think about the penetration of kind of the core SIEM use case for Splunk within your large enterprises? Is there a potential to sort of broaden that more for more fully in the marketplace? Yeah. One of the really interesting things about Splunk is there's a lot of security departments that buy the Splunk platform for their security use cases, but they haven't necessarily bought into our premium apps. Mm-hmm. like our SIEM solution, our SOAR solution. One of the opportunities that we have this fiscal year is going back to those very loyal security customers and selling them our premium solutions. You know, at a very simple level, by getting, again, closer connected to our security buyers and practitioners, being able to go back and sell those premium apps is a pretty straightforward process for us. We're enthusiastic about that and the opportunity that exists there. Got it. One of the industry debates that we've been talking about a lot, we definitely hear a lot is SIEM versus XDR, right? Extensible detection and response. Yeah. Do you look at XDR as a adjacent sort of complementary capability of what you could do with sort of the data in the SIEM or is it gonna prove to be more competitive and you guys have to evolve the SIEM to be more of an XDR? I think, if you look at what do people want to do, they want to be able to detect and respond, but they also want to be able to understand what's happening more broadly across their attack surface. I think where people get confused is XDR is not a replacement for SIEM because you still have to understand broadly what happened. What time did Keith log on? Was Keith compromised? Did he log on to Office 365 at the same time he was logged on to Salesforce? Like, all of those questions you can't answer in XDR. XDR gives you the ability to detect and respond. I fundamentally believe that you're gonna continue to see both of those capabilities be aligned and supportive of one another. Got it. Almost similar to the premium services. Right. XDR becomes an extension of what you're doing on that underlying data set. Maybe just to dig in there a little bit more, 'cause you mentioned SOAR. That's something that you guys had acquired. Yeah. . several years ago. Not to be too flippant, but, like, it was a leading SOAR vendor that you acquired, and we haven't heard a lot about it within the Splunk portfolio. Was it a product issue? Was it just a sort of sales motion issue? Does that need to be solved first before you can extend into stuff like XDR? I think automation's a key theme for all security buyers because they're trying to do more with less. That's what SOAR accomplishes for the buyer. I think at the time we bought the best product in the market, and I don't think their execution was as good as it could have been. Right . frankly, with that. Having said that now, we're starting to see through some of the short-term innovation that we've had and then extending it with these capabilities like we just acquired with TwinWave, which is really threat analysis. I think we can reinvigorate the growth in that, going back to this opportunity of going back to our buyers and selling them premium apps. frankly, I just think we slowed down. I think there's an opportunity to reaccelerate that. Got it. It sounds like it's more on the execution side of the equation. I believe so, yeah. than the go-to-market side of the equation. It seems like, and just taking a couple of the data points from the discussion thus far, part of sort of the initiatives you're putting into place is cleaning up some of the M&A that has been done historically. Good sort of assets brought on board, perhaps not particularly well put into the go-to-market motion. Yeah. I think, there's opportunity just to streamline how we bring products to market and put them in the hands of our customers. There's a lot of very simple, straightforward things that I feel like we can do to, frankly, accelerate the pace at which we're delivering premium capabilities to our customers, that they need, that they demand, and that they wanna buy from Splunk. Got it. Got it. Just to round up the SIEM discussion, we've definitely been hearing a lot more from non-traditional kind of SIEM competitors in this marketplace. Datadog and Dynatrace have been talking about it from the observability space. Some of the traditional network security guys, even some of the endpoint security guys are coming more into that space. What have you seen in your kind of day-to-day operations? Like, are these new competitors emerging to the level of where you're competing, or is it more sort of background noise from your perspective? Yeah, we really don't see those emerging companies as playing a significant competitive role. I think the reality of where we play in the market, let's just remind folks where we are, we're really at the Global 2000 level. Right. . and some of the most significantly large organizations with really complex requirements. It's very difficult to come in the market with an entry-level solution and displace something like a Splunk, which customers have grown dependent upon those broad scale capabilities. Got it. Got it. Switching gears to the inverse, the observability market, where you guys are looking to sort of make more of a push into that space. SignalFx, again, another really well-regarded asset and really interesting technology, particularly on what they're able to do in serverless. You guys brought that on board. Can you talk to us about where you are in integrating that asset? Into the broader Splunk platform and the go-to-market behind it? You bet. We're super excited about the opportunity that Observability brings to the company. If you're not familiar with what had transpired in the past, we bought SignalFx, and we bought 5 other companies. Sure . all broadly in the Observability market. The engineering team's done a phenomenal job of bringing together those five companies, taking the sharp edges off, and delivering something that's very compelling. The one thing we realized in the middle part of last year is we needed to be closer to the core, that loyal Splunk customer could then extend their reach and leverage the Observability Cloud. We made tremendous progress in that core integration over the course of the last six months. I would say we have more work to do, what I'm very encouraged by is, we noted this in our most recent earnings call, the number of very strategic marquee Splunk customers that are adopting Observability Cloud, they did that by looking at everything in the market. Doing hardcore bake offs against us and all the competitors and choosing Splunk. I feel like we're on a very good path, and we're much improved from where we were, say, a year ago. Got it. Got it. Just to double-click on that to make sure I understand. You guys acquired SignalFx, but then there was Flowmill and Plumbr and Omnition. It lets you get into all the different areas that have been converged into the Observability space. It's network monitoring and real user monitoring, and now you have all of those capabilities. They're integrated with SignalFx. What does it mean to be closer to the core? Does that mean it has to sort of better leverage the core, like, log data that you're bringing up? Yeah, simple things like being able to leverage the same way in which you get data in. Okay. Making it just that much easier for that customer that had embraced Splunk in a very significant way to be able to extend that reach to get to metrics and synthetics and everything that a customer would want. Okay. Got it, got it. Shifting gears to cloud migrations. I would say prior to you joining, cloud migration was the big initiative of Splunk. Mm-hmm. I'll just lay it out there candidly. It seems to me that perhaps Splunk pushed a little too hard on their customers to sort of migrate to the cloud. It may have off-put some of the larger enterprises that weren't ready to move to the cloud. Yeah. It seems like you've taken off some of that onus, and reinforced the idea for your large customers that say, "Listen, we're gonna be developing on both sides of the equation. It's gonna be a hybrid story on a go-forward basis." Can you talk to us, one, how you've changed sort of the approach to cloud migration? Sure. Two, what should investors be expecting on a go-forward basis in terms of the progression of cloud, growing within the overall Splunk business? I think, one of the observations I had, after my first 90 days in the company is that we had not been clear with our very loyal on-prem customers. Because we'd been so focused on pushing them to the cloud, I felt like we were pushing them away from the company, and customers were looking for alternatives. One of the things that I've been doing is reinforcing our long-term commitment to on-premise, our ability to help our customers manage a complex multi-cloud hybrid environment, and delivering a set of capabilities that truly differentiate us in this world where customers still have applications running in their data centers. They have applications in the cloud, and they need a single way to do that. I think there's no better company than Splunk to help our customers do it, and I think we were frankly just twisting our customers' arms when we didn't need to. We've recommitted from a product development standpoint. We'll continue to have really interesting features coming out in on-prem. If you look across our large customers, this is a very common theme. We feel like resetting that was a very important move for us. I'm gonna let Brian comment on how we think about cloud ARR growing and its percentage of pull. If you look at Q4, we had cloud grow at 33% year-over-year. For this coming year, what we said was in terms of new software bookings, we thought it would vary each quarter between 55%-65%. In terms of just the overall ARR breakdown, that cloud will begin to generate more than 50% in the second half of this year. Got it. Just to be clear, the 55%-65%, that was the percentage of cloud bookings? Of new bookings, software bookings. Of new bookings going into cloud. Yeah. Right. That compares to, I think you ended Q4 at 58%? We said in the second half of the year we'd be north of 50%. Okay. I would encourage investors not to though take 31st January of, 2024 and do 50% of what our guidance range and assume that's cloud. That would be ultra-conservative. Got it. To be clear, Gary, the change in focus doesn't mean Splunk Cloud is no longer. No, not at all. available by enterprises. You're not trying to sort of bifurcate enterprises by enterprise and cloud is a different market environment. No, we see customers having this blend. A really common occurrence is that customers can leverage Splunk in a really interesting way. I'll give you a simple example. I was with a CISO who was dealing with data privacy rules around the globe. They have a very big instance of Splunk Cloud. They're going to be setting up application stacks in some of these countries that require data residency, for example, India. The cool thing about Splunk is you can run Splunk to Splunk. You can basically run searches globally across Cloud and on-prem, and do it all from a single Splunk search bar. It's actually really cool in the way in which we can help customers deal with complexity around data privacy, complexity around how their environment has evolved from on-prem to cloud. Got it. It wasn't an issue that Splunk Cloud isn't applicable to the enterprise customers, it was more of a go-to-market that you're pushing too aggressively on customers that weren't ready to go to the cloud. I think it's where customers are. We wanna make sure that we're not getting ahead of customers and forcing them somewhere where they're not ready to be, and we allow them to leverage the power of the product in a way that best supports their current environment, which is hybrid. Got it. If we take that one more step, one of the really interesting dynamics that Splunk had talked about historically with the move to cloud was the ability to really jumpstart the net dollar expansion. Splunk customers going to the cloud tended to expand faster. It sounds like you're trying to have that motion be better on both sort of the on-premise side of the equation and Splunk Cloud. Can you remind us where we are today in terms of net expansion into the cloud? Has that held up as well? Can you get on-premise to look something like that on the go forward basis? I'll let Brian comment on the numbers, and I'll talk a little bit about the use cases. Oh, sure. You might borrow that. In terms of some of the numbers, I think when you look at DBNRR, that in the Q4, we were at 123%, which is still quite strong. I think when you look at overall what we've been trying to share in terms of on enterprise, the cloud migrations is just a matter of when, not if. A lot of these projects have been just slowed right now in the current economic environment. CIOs are going to CFOs, and the CFOs are saying, "Not this year." When you look at that type of metric, which is a trailing 12-month metric, it will. You need expansions, obviously, to grow that number. When, you know, projects are put on hold, customers continue to then to lean in on hybrid, and we're just not seeing it yet in cloud. Again, we believe we're set up in terms of when we talk about fiscal 2025, that you can see this acceleration as the economy rebounds and cloud migrations come back. The thing we're focused on from a go-to-market standpoint this year is continuing to drive additional use case adoption. A very specific example, and we referenced this in our prepared remarks for the quarter, is we'll be announcing capabilities that give us access to data that lives in an OT environment, so a manufacturing floor. Capabilities that can give visibility to security leaders of what's happening with respect to those systems and that environment, as well as taking broad operational data that then can be combined broadly with their IT data. This is an example, it could be used on-prem, it could be used in the cloud. We don't care, as long as you can get that information in Splunk, and then derive better decisions from it. Understood. I got 2 guidance-related questions I'm gonna ask to Brian, but then I'm gonna open up the questions to the audience. If you have your questions, get them prepared now, and we'll have some mic runners running around. Brian, I wanted to talk about the FY 2024 guide. The question I get after every earnings call for the past, I would say year is: Is the forward guide de-risked? Can you talk to us about some of the underlying assumptions and the methodology you used in setting that FY 2024 guide? How do we garner confidence that that's a de-risked guide, if you will? Is it a conservative enough guide given the environment? Yeah. When I made the guidance, I think I was five weeks into the job. I would say we took what we saw in January and extended it for the full year. In terms of ARR growth, $4.125 billion-$4.175 billion, that's $500 million-$500 million of net new ARR. That's what we thought, you know, again, based on the environment in January. Could the second half be faster? Yes, if there's an economic recovery. We think for this year, we're planning for the current economic cycle to persist through this year. What we shared on the call in terms of the free cash flow, because I think this is a place where investors were very surprised. We guided well above consensus to $775 million-$795 million of free cash flow. We said we're very confident in that number regardless of, you know, operating scenario. We feel we can hit that number. Got it. Then Gary, maybe if you could help us sort of put January into context. It's unfair to ask Brian to do this since he wasn't here. How did January feel from a macro and spending environment perspective versus sort of earlier in the year, maybe if you went back a quarter or two before? Yeah. We first saw signs of economic change in July. Mm-hmm. We saw cloud migrations and expansions slow down in that period. We saw that continue through our final two quarters. What was different in Q4 for us, and specifically in January, is we saw more financial deal scrutiny, CFOs looking harder at deals. That was new as we got to Q4. We obviously closed our fiscal year at the end of January, you know, most of our quarter is very back-end weighted. We don't know whether that was a January effect or that was more broadly across the quarter, but it was definitely apparent that there was more deal scrutiny. Got it. Got it. Then, one for Brian on the sort of margin side of the equation. Like we were talking about earlier, this is a hard model because of ASC 606 and revenue recognition. I think that makes operating margins a tough metric to look at because it depends on sort of what comes through as term licenses. When you think about the overall efficiency of the business, what are you looking to in terms of the key metric? Then more holistically, what are the sort of dials you still have left to turn to sort of increase the leverage of the overall business? When you look at Splunk, again, these term licenses we recognize upfront. You can have a quarter like Q4, where our term license revenue increased over 50%, right? You have this huge jump in top line. Your expenses are relatively fixed, so it just drops to operating margin. I think some investors got confused looking at last year's operating margins versus this guide. Operating margins are gonna be very subject to top line, and it's all back to rev rec as opposed to, like, the fundamentals of the business. I would look at OpEx growth, but I think the best metric to look at is free cash flow margin. Like, you will hear it over and over from us, we're focused on free cash flow, and you can then measure in terms of free cash flow margin and growth. If you look at last year, we were 11.6%, sorry, 11.8% in terms of free cash flow margin, and then we guided this year to 18.8%-19%. Got it. That's the material thing. That's where you're gonna watch this improvement. Right. We believe we're set up for, you know, multiple years of free cash flow margin improvement. It's not just a one-year move. Right. Can you point to a couple of particular levers that are sort of driving that? Yeah . expansion in free cash flow margin? Gary, you know, when Gary came in last year, he started this motion in terms of really looking at operating efficiency. There's lots of different ways to drive that. You can look at the workforce structure and spans and controls, where you can, you know, try to remove some spans to, quite frankly, increase decision-making and just execution velocity. We started to look at tapping. If you look at the Splunk population base in terms of employee population, we were very heavy in the Bay Area. We're looking at tapping some of the, just the emerging talent pools around the world. You know, R&D is a good example this year, where we think we can hold in terms of non-GAAP OpEx, like the dollar amount, fixed, while we increase headcount as we tap some of these new regions. Got it. That was some classic sell-side inflation. My two questions expanded into 5. Some questions from the audience. Thanks for taking the question. You talked a little bit about competition from a couple different angles. You talked about observability, and you kind of thought it was less critical, and you also talked about the XDR competition from the other cyber security players. I was curious what you thought about like the Snowflake of the world and kind of like a data security lake. We've just been hearing out there, you know, talking to customers and they'll say, "Hey, I've got like a $10 million-$20 million Splunk bill. Maybe it's possible I could do this, I don't know, with 30 with a data lake for $X million, even if I have more overhead." Have you, have you been seeing that, and do you have any thoughts on that? Yeah, you know, we haven't. The thing that has always been unique about Splunk is that what has always differentiated us is our ability to take unstructured data, be able to read it in, and drive decisions from it. That is, if you think about Snowflake and the other kinds of products like that, they work really well on structured data. It's why we always excel, and we have customers doing insane volumes of data that you just can't do in other environments because it is machine data that's truly unstructured. I was with a customer last week. They ingest 3 petabytes a day into Splunk, and they can do real-time decision-making on that. Those are really hard problems that are just technically oriented towards what we have built. We don't see, like, the classic use of structured data with Snowflake or other capabilities like that as moving into our world. Any additional questions from the audience? Get a mic up front. While we're waiting for the mic. Right there. . just Yeah. Interject one question. Sure. The question that he asked, it, like, it talks to, a persistent sort of expectation in the marketplace that we continue to hear, and it almost surprises me how persistent around pricing, around the idea that Splunk is expensive. There's been various efforts by the company over the years to sort of counter that expectation. Right . and changes in pricing. Can you talk to us about sort of where you think we are in the, in the market in terms of convincing the market that there's good value here, there's good price performance? Yeah behind Splunk? Yeah. Just quickly to catch people up, traditionally, Splunk had an ingest pricing model, meaning that you paid a toll to Splunk for all the data you brought into Splunk. Mm-hmm. Fast-forward, when we launched cloud, we launched workload pricing, meaning only if you're getting value from that data, you're doing queries, you're getting value, do you pay Splunk a toll. Okay. We were probably, bluntly put, we were probably slow in getting that workload pricing out. We've made tremendous progress, and customers that are on workload pricing, I think, feel very much like their value is driven to price. I think there's a good match there. We still have some customers on ingest, and we have work to do to get those people over. I think the model's right, the direction's right, and we've made great progress. We just have some more work to do. Perfect. Sorry. A question up front. Yeah. Thank you for taking the question. I guess you've talked a bit about the puts and takes on what's been driving cloud migration, slowdowns in cloud migration. It seems that you've taken the approach to be a little bit more accommodating. That's not necessarily the case across the board. Can you talk about, not with you, but with other cloud service providers? Is there sort of a dynamic where you have one potential cloud service provider actually still retiring on-prem services that's benefiting cloud migrations overall on your end? You know, is cloud migration typically disaggregated across the service stack where you might, you know, adoption of cloud services from other companies elsewhere in the stack, but might see them, those customers still use on-prem services? Yeah, I think, I think our customers, you have to go back to who our customers are, which is really Global 2000. Most of those customers have some on-prem footprint. They're going to have for a long time. There will be applications that live in their data centers for a long time. As a result of that, they're gonna want to be able to bring all that information together, either on-prem or in cloud. I think what what you'll see as the economy begins to improve, you'll see customers move more aggressively to, again, as Brian described, make those cloud migrations happen. For us, our target environment has to be multi-cloud hybrid. It has to be, because that's where our customers are. Outstanding. Unfortunately, that takes us to the end of our allotted time slot. Gary and Brian, thank you so much for joining us. Thank you. Appreciate it. Great conversation.
Loading workspace