As we are migrating on cloud, the same alert triggered from our on-premise Splunk has different rather more structured format than the alert triggered from Cloud Splunk.
Could you please refer the following link
https://answers.splunk.com/answers/306886/main-differences-between-splunk-enterprise-and-spl.html
Hope it will help you.