Compatibility and regional availability
Splunk Enterprise Security version 8.x is compatible with Splunk Enterprise (on-premises) version 9.2.0 and higher.
As of release 8.5.1, Splunk Enterprise Security Essentials and Splunk Enterprise Security Premier Edition are FedRAMP compliant. For current, specific compliance information, see Compliance at Splunk.
For more information on the compatibility of Splunk Enterprise Security with Splunk Platform, Splunk IT Service Intelligence (ITSI), and Splunk IT Essentials (ITE) Work, see Splunk products version compatibility matrix.
Regional availability for Enterprise Security Editions
lists geographical region availability for ES features
Enterprise Security Essentials Edition regional availability
The following AWS regions are available for Splunk Enterprise Security features. All components are available in all regions, unless otherwise noted.
For a list of components included in Enterprise Security Essentials Edition, see Overview of Splunk Enterprise Security Editions.
| AWS region | Geographic area | Exception |
|---|---|---|
| ap-northeast-1 | Tokyo | |
| ap-northeast-2 | Seoul / Korea | |
| ap-south-1 | Mumbai / India | |
| ap-southeast-1 | Singapore | |
| ap-southeast-2 | Sydney | |
| ap-southeast-3 | Jakarta / Indonesia | |
| ca-central-1 | Montréal | |
| ca-west-1 | Calgary |
Splunk Security Assistant Splunk Agentic SOC |
| eu-central-1 | Frankfurt | |
| eu-north-1 | Stockholm |
Splunk Security Assistant Splunk Agentic SOC |
| eu-south-1 | Milan |
Splunk Security Assistant |
| eu-west-1 | Ireland / Dublin | |
| eu-west-2 | London | |
| eu-west-3 | Paris | |
| sa-east-1 | Sao Paulo | Splunk Security Assistant |
| us-east-1 | N. Virginia | |
| us-west-2 | Oregon | |
| us-gov-east-1 | US GovCloud (East) |
Splunk Security Assistant Splunk Agentic SOC |
| us-gov-west-1 | US GovCloud (West) |
Splunk Security Assistant Splunk Agentic SOC |
Enterprise Security Premier Edition regional availability
The following AWS regions are available for Splunk Enterprise Security Premier Edition features. All components are available in all regions, unless otherwise noted.
For a list of components included in Enterprise Security Premier Edition, see Overview of Splunk Enterprise Security Editions.
| AWS region | Geographic area | Exception |
|---|---|---|
| ap-northeast-1 | Tokyo | Splunk Attack Analyzer |
| ap-northeast-2 | Seoul / Korea | Splunk Attack Analyzer |
| ap-south-1 | Mumbai / India | |
| ap-southeast-1 | Singapore | Splunk Attack Analyzer |
| ap-southeast-2 | Sydney | |
| ap-southeast-3 | Jakarta / Indonesia | Splunk Attack Analyzer |
| ca-central-1 | Montréal | |
| ca-west-1 | Calgary |
Splunk Security Assistant Splunk Agentic SOC |
| eu-central-1 | Frankfurt | |
| eu-south-1 | Milan |
Splunk Attack Analyzer Splunk Security Assistant |
| eu-west-1 | Dublin / Ireland | Splunk Attack Analyzer |
| eu-west-2 | London | |
| eu-west-3 | Paris | Splunk Attack Analyzer |
| me-central-1 | UAE | AWS services disrupted |
| us-east-1 | N. Virginia | |
| us-west-2 | Oregon | |
| us-gov-east-1 | US GovCloud (East) |
Splunk Attack Analyzer Splunk Security Assistant Splunk Agentic SOC |
| us-gov-west-1 | US GovCloud (West) |
Splunk Attack Analyzer Splunk Security Assistant Splunk Agentic SOC |
Cloud Connect
The following AWS regions are available for the following components using Cloud Connect, unless otherwise noted:
-
Detection Studio
-
Threat Intelligence Management (Cloud)
-
Splunk Security Assistant
| AWS region | Geographic area | Exception |
|---|---|---|
| ap-northeast-1 | Tokyo | |
| ap-northeast-2 | Seoul / Korea | |
| ap-south-1 | Mumbai / India | |
| ap-southeast-1 | Singapore | |
| ap-southeast-2 | Sydney | |
| ap-southeast-3 | Jakarta / Indonesia | |
| ca-central-1 | Montréal | |
| ca-west-1 | Calgary | Splunk Security Assistant |
| eu-central-1 | Frankfurt | |
| eu-south-1 | Milan | Splunk Security Assistant |
| eu-west-1 | Ireland / Dublin | |
| eu-west-2 | London | |
| eu-west-3 | Paris | |
| sa-east-1 | Sao Paulo | Splunk Security Assistant |
| us-east-1 | N. Virginia | |
| us-west-2 | Oregon |
GCP and Azure availability
Splunk Enterprise Security and Splunk SOAR are available in the following GCP and Azure regions. Other components are not available in these regions.
| GCP region | Geographic area | Exception |
|---|---|---|
| Australia | Sydney | |
| Belgium | ||
| Canada | Montreal | |
| Germany | Frankfurt | |
| Saudi Arabia | Dammam | |
| Singapore | ||
| UK | London | |
| US Central | Iowa | |
| US West | Oregon | SOAR Not available |
| Azure region | Geographic area | Exception |
|---|---|---|
| Japan | Tokyo | |
| UK | London | |
| US East | Virginia | |
| US West | Phoenix |
Splunk SOAR compatibility
Splunk SOAR pairs with Splunk Enterprise Security to let users run actions, run playbooks, and review automation history in Splunk Enterprise Security.
Refer to the matrix that matches your Splunk Enterprise Security deployment:
Splunk Enterprise Security Premier Edition
The following versions of Splunk SOAR are compatible with the current version of Splunk Enterprise Security Premier Edition:
|
Splunk Enterprise Security deployment type |
Compatible version of Splunk SOAR (Cloud) |
Compatible version of Splunk SOAR (On-premises) |
|---|---|---|
|
Cloud versions 8.2 and higher |
6.4.1 and higher (AWS-AWS) |
--- |
|
On-premises versions 8.3 and higher |
--- |
7.1.0 and higher (including clustering; warm standby; backup and restore*) |
* Pairing Splunk Enterprise Security with multi-tenant Splunk SOAR (On-premises) deployments is not supported.
Splunk Enterprise Security paired with Splunk SOAR
The following versions of Splunk SOAR are compatible with this version of Splunk Enterprise Security:
|
Splunk Enterprise Security deployment type |
Compatible version of Splunk SOAR (Cloud) |
Compatible version of Splunk SOAR (On-premises) |
|---|---|---|
|
Cloud version 8.5 and higher |
8.5.0 and higher (Azure-Azure, AWS-AWS, GCP-GCP) 7.2.0 and higher (AWS-AWS, GCP-GCP) 6.3.0 - 7.1.0 (AWS-AWS only) |
8.5.0 and higher (standalone or clustering*) 7.0.0 - 8.4.0 (standalone only)
Note:
Hybrid pairing requires SSL certificates signed by a Public Certificate Authority (CA). Hybrid pairing is not supported for Splunk Cloud FedRAMP, IL2, and IL5 environments. |
|
On-premises version 8.5 and higher |
--- |
7.0.0 and higher (including clustering; warm standby; backup and restore*) 6.4.1 and higher (standalone only)
Note: Pairing supports SSL certificates signed by Public or Private Certificate Authorities (CAs).
|
* Pairing Splunk Enterprise Security with multi-tenant Splunk SOAR (On-premises) deployments is not supported.
Regional data notice for Splunk Attack Analyzer and Automated Threat Analysis
data usage notice
Certain Splunk Attack Analyzer and Automated Threat Analysis features, such as the AI Malware Reversing Agent, Phishing Analysis Agent, and Translation services, might process data in regions different from your primary environment's provisioning location. You do not need to configure or interact with this data processing as it is managed exclusively in the backend of the product. For details on sub-processors and their geographic locations, see the Cisco Offer Disclosures. To opt out of these AI-driven analytic features, you can submit a Splunk support case. Our support team can assist you to turn off these features on your deployment.
Threat Intelligence Management (Cloud) compatibility
Threat Intelligence Management (Cloud) is accessible in Splunk Enterprise Security to provide intelligence support for users.
To access Threat Intelligence Management (Cloud) within Splunk Enterprise Security, you must:
-
Have a compatible licensed version of Splunk Enterprise Security
-
Reside in an available region
If you meet the criteria in this article, Threat Intelligence Management (Cloud) is automatically included with Splunk Enterprise Security cloud deployments and can be set up by an admin. See Overview of threat intelligence in Splunk Enterprise Security
Compatibility
Threat Intelligence Management (Cloud) supports search head cluster (SHC) deployments of Splunk Enterprise Security. See the following table for version compatibility with Threat Intelligence Management (Cloud):
| Splunk Enterprise Security deployment type | Compatible version of Splunk Enterprise Security |
|---|---|
| Cloud | 6.6 or higher |
| On-premises | Not available |
Available regions
For available region information, refer to Enterprise Security Premier Edition regional availability.
Splunk AI Assistant for Security compatibility
The Splunk AI Assistant for Security is accessible in Splunk Enterprise Security for investigation summary, SPL generation, and more. The AI Assistant is not automatically available by default. An admin must contact their account management team to get started.
To get the AI Assistant for Splunk Enterprise Security, you must:
-
Have a compatible licensed version of Splunk Enterprise Security
-
Reside in an available region
Compatibility
| Splunk Enterprise Security deployment type | Compatible version of Splunk Enterprise Security |
|---|---|
| Cloud | 8.2 or higher |
| On-premises | Not available |
Available regions
For available region information, refer to Enterprise Security Premier Edition regional availability.
UEBA compatibility
User and entity behavior analytics (UEBA) is accessible in Splunk Enterprise Security Premier Edition. With UEBA, threat analysts and SOC analysts can evaluate risky users and assets, ensure compliance with regulatory requirements, and escalate findings with anomalous behavior.
For more details on UEBA, see User and entity behavior analytics (UEBA) overview in Splunk Enterprise Security.
To configure UEBA, reach out to your account management team and see Installing UEBA in Splunk Enterprise Security.
Compatibility
| Splunk Enterprise Security deployment type | Splunk Enterprise Security version | Splunk Enterprise Security edition | Splunk SOAR version | UEBA Content App |
|---|---|---|---|---|
| Cloud | 8.2 or higher | Premier | 6.3.x or higher | n/a |
| On-premises | 8.3 or higher | Premier | 6.3.x or higher | 1.0 or higher |
Available regions
For available region information, refer to Enterprise Security Premier Edition regional availability