Release notes for Splunk Enterprise Security
Find the following information on the Splunk Enterprise Security version 8.6.0 release:
What's New in 8.6.0
New features in release 8.6.0
In the Controlled Availability release stage, Splunk products may have limitations on customer access, features, maturity, and regional availability. For additional information on Controlled Availability please contact your Splunk representative.
Documentation update: You can now download entire manuals in portable document format (PDFs). Go to any documentation topic on help.splunk.com, select the PDF button, and then select Download Manual. Available for most manuals.
Splunk Enterprise Security version 8.6.0 (Controlled Availability) was released on July 21, 2026 and includes the following new enhancements:
| Splunk idea | New feature | Description |
|---|---|---|
|
Modifications to the menu options for navigation in the user interface for Splunk Enterprise Security version 8.6 UI to ensure consistency with Cisco products. |
Updates to the menu options and collapsible side navigation panels for streamlined user workflows and consistency. For more information, see Differences in navigation menu options in Splunk Enterprise Security version 8.6 and higher.
Note: New menu options for navigation are available on both Cloud and On-premise for Splunk Enterprise Security Essentials and Premier Editions. However, you must use Splunk Enterprise Security version 8.6 paired with Splunk Platform 10.4.x or higher to view these navigation menu options.
|
|
| Detection Builder agent integrated in the detection editor to create, tune, validate, and troubleshoot detections | Ability to create, tune, validate, and troubleshoot detections using the Detection Builder agentic chat within the detection editors. For more information, see Author detections using the Detection Builder agent in Splunk Enterprise Security and Troubleshoot AI Assistant in Splunk Enterprise Security. | |
| Malware Reversing Agent and Phishing analysis agent to enrich alerts with insights, support investigations, and accelerate threat hunting | Ability to review and investigate potentially malicious scripts using the AI-powered Malware Reversing Agent and Phishing Analysis Agent in Splunk Enterprise Security. For more information, see
Analyze scripts using the AI-powered Malware Reversing Agent and Phishing Analysis Agent. |
|
| Enhancements to the Triage agent |
Ability to specify the SOAR connectors that the Triage agent can use for autonomous enrichment or to perform adaptive response actions in Splunk Enterprise Security. For more information, see Specify SOAR connectors to enrich findings using the Triage agent. Additionally, the Triage agent also offers the ability to automatically analyze and triage findings by assigning a disposition to them based on evidence. For more information, see Analyze the findings using the Triage agent. |
|
| Guided Response agent | Ability to run SOAR response actions or playbooks on findings using the AI-powered Guided Response agent so that you can accelerate your security response. For more information, see Run SOAR response actions using the Guided Response Agent in Splunk Enterprise Security. | |
| Cloud connected on-premises support for AI Assistant in Splunk Enterprise Security | Ability to access AI Assistant in Splunk Enterprise Security if you are using Splunk Cloud Connect to connect on-premises deployments of Splunk Enterprise Security with Cloud-native, Splunk managed, or Splunk Cloud Services (SCS). For more information, see Access Splunk Cloud Connect in Splunk Enterprise Security to access Cloud extensions. | |
| Improvements to Detection Studio | Key performance indicator (KPI) refreshes for selected detections, compatibility labels, fixes to the accuracy for confidence and KPIs, improved handling of large detection libraries and long-running jobs, and improved health telemetry for tracking integration status, job state, execution time, and reliability at scale. For more information, see Identify optimal detections for your security environment using Detection studio in Splunk Enterprise Security. | |
| Updates to capabilities for team queues | Modifications to role-based access (RBAC) capabilities for queues, deletion and deactivation of queues, access to dashboards based on RBAC queue controls. For more information, see Analyst and team-based queues in Splunk Enterprise Security. | |
| Activity logs to create an audit trail in a unified logging format |
Review a clear, consistent audit trail for key actions across findings, finding groups, and investigations. The activity log captures updates, deletions, note activity, ownership changes, and other investigation events in a paginated table, helping teams understand what changed, when it changed, and who made the change. CSV export is available for sharing, review, and offline analysis. Ability to provide a detailed description of all changes made to a finding, finding group, or investigation and create a tamper-proof audit trail in a unified logging format using Activity logs, which can be parsed by dashboards or custom searches. For more information, see Create an audit trail in a unified logging format using Activity logs in Splunk Enterprise Security. |
|
| Detection versioning is turned on by default for both Splunk Cloud Platform and Splunk Enterprise deployments in ES version 8.6 | Detection versioning is turned on by default and provides a history of changes to the detection, and a comparison of supporting versions as well as version-dependent workflows. This release resolves the issues that required detection versioning to be turned off for ES versions 8.4.1 and 8.5.1. Detection versioning is automatically turned on as part of the upgrade to ES version 8.6. After versioning is turned on, all changes made while detection versioning was turned off are captured in a single detection version. If the detection is turned on, that version becomes active. You can turn off the feature when required and configure advanced settings in the UI. For more information, see Use detection versioning in Splunk Enterprise Security. | |
| Exposure Analytics updates |
Expanded discovery reporting provides deeper, intelligence-driven insights into trends, operating systems, cloud environments, default accounts, NHI and more. See Entity discovery insights for details. Subnet discovery helps accelerate investigations by querying an IP or subnet to view all assets discovered within that same network boundary. See Review entity subnets for details. Entity change history provides a comprehensive timeline of how assets and users evolve over time, providing the timeline needed to reconstruct events and distinguish routine updates from potential threats. See Review attributions for an entity for details. Enrichment lookups can now be modified to enrich entity discovery with tailored business environmental intelligence. See Enrichment lookups in Exposure Analytics for details. |
|
| Threat intelligence dashboard | Displays the aggregated threat intelligence data that your system has ingested, providing insights for enrichment and detection matching. For details, see Gain insights with the threat intelligence dashboard. | |
| Entity risk score (ERS) improvements | Three multipliers re-added to this score: detection_frequency_per_entity_multiplier, detection_frequency_per_stack_multiplier, and detection_quality_per_stack_multiplier. For details, see Entity risk scoring in Splunk Enterprise Security. |
|
| New UEBA auditing dashboard | UEBA Detection Performance Summary view that provides aggregated insights for selected detections. For details, see Auditing UEBA with dashboards in Splunk Enterprise Security. | |
| New UEBA cloud detection |
New UEBA Content App for Cloud (DA-ESS-UEBASecurityContent) extends the functions of UEBA and accesses UEBA detections. For details, see User and entity behavior analytics (UEBA) overview in Splunk Enterprise Security and UEBA Content App for Cloud. |
|
| System insights updates |
Improvements to the System Insights data visualizations user interface, along with including new tabs that include asset and ingestion activity, certificate status, and system resources health. For details, see System insights in the Splunk App for SOAR Users' Guide. |
For additional enhancements in Splunk SOAR, see the following articles:
Upgrade notice for 8.x
Upgrading Splunk Enterprise Security to version 8.x is a one-way operation. The upgrade process doesn't automatically back up the app, its content, or its data. Perform a full backup of the search head, including the KV Store, before initiating the Splunk Enterprise Security upgrade process.
When you upgrade to Splunk Enterprise Security version 8.x, you can no longer access any investigations created prior to the upgrade. To save archives of your investigation data, back up and restore your existing Splunk Enterprise Security instance.
If you need to revert back to the version that previously existed on your search head, you must restore the previous version of Splunk Enterprise Security from a backup.
See Upgrade Splunk Enterprise Security.
Other important notes for upgrading include the following:
- You cannot upload Splunk Enterprise Security 8.x on an on-premises deployment of Splunk Enterprise 10.x using the UI. You must install Splunk Enterprise Security 8.x using the command line. See Install Splunk Enterprise Security from the command line.
- Splunk Enterprise Security in a search head cluster environment uses an installer that creates tokens and turns on token authorization if it is not available. Post-installation, the installer deletes the tokens. If an error occurs, contact Splunk Support to delete any residual tokens.
- The Splunk Enterprise Security Health app is installed but is turned off for all Splunk Cloud customers. This app is turned on by the Splunk Cloud Platform only during upgrades to ensure that the stacks get upgraded faster. Do not turn on the Splunk Enterprise Security Health app.
Share threat data in Splunk Enterprise Security
Compatibility and support
- Splunk Enterprise Security version 8.x is compatible only with specific versions of the Splunk platform. See Splunk products version compatibility matrix for details.
- Current versions of Splunk Enterprise Security only support TAXII version 1.0 and TAXII version 1.1.
AI processing boundary
Information available soon
Deprecated or removed features
-
URLHaus -
Abuse SSL IP Blacklist
URLHaus source is deprecated due to changes in licensing terms. A new source named URLhaus Malware URL Feed is added, which requires an API key for access. For licensing and API key information, see URLHaus.
The following features have been deprecated from Splunk Enterprise Security 8.x:
- Configuring the investigation type macro is no longer available.
- Incident Review row expansion is no longer available.
- Enhanced workflows are no longer available.
- Sequence templates are no longer available.
- The Investigation bar, Investigation Workbench, and Investigation dashboard from the Splunk Enterprise Security user interface (UI) are replaced by the Mission Control UI.
- Service level agreements (SLAs) and role-based incident type filtering are not available.
- The Content management page was updated to remove the following types of content: Workbench Profile, Workbench Panel, and Workbench Tab.
- Workbench and workbench related views such as
ess_investigation_list,ess_investigation_overview, andess_investigationhave been removed. - Capabilities such as
edit_timelineandmanage_all_investigationshave been removed. - The Comments feature is replaced by an enhanced capability to add notes.
- In Splunk Enterprise Security version 7.3, admins can turn on a setting to require analysts to leave a comment with a minimum character length after updating a notable event. In Splunk Enterprise Security version 8.x, you can no longer require a note when an analyst updates a finding in the analyst queue.
Add-ons
Technology-specific add-ons are supported differently than the add-ons that make up the Splunk Enterprise Security framework. For more information on the support provided for add-ons, see Support for Splunk Enterprise Security and provided add-ons in the Release Notes manual.
Splunk_TA_ForIndexers add-on for every release.
To ensure that the Splunk Enterprise Security app works correctly, turn on the following add-ons. If any of the following add-ons aren't turned on, Splunk Support gets automatically notified and ensures that all the required add-ons are turned on automatically.
- DA-ESS-AccessProtection
- DA-ESS-EndpointProtection
- DA-ESS-IdentityManagement
- DA-ESS-NetworkProtection
- DA-ESS-ThreatIntelligence
- SA-AccessProtection
- SA-AuditAndDataProtection
- SA-EndpointProtection
- SA-IdentityManagement
- SA-NetworkProtection
- SA-ThreatIntelligence
- Splunk_SA_CIM
- Splunk_SA_Scientific_Python_linux_x86_64
- SplunkEnterpriseSecuritySuite
- Splunk_ML_Toolkit
Deprecated or removed add-ons
Splunk Enterprise Security no longer includes many of the technology add-ons in the Splunk Enterprise Security package. Instead, you can download the technology add-ons that you need directly from Splunkbase. This change improves the performance of Splunk ES by reducing the number of unnecessary enabled add-ons, and allows you to install the most appropriate and updated versions of add-ons when you install Splunk ES.
The following technology add-ons are removed from the installer, but still supported:
- Splunk Add-on for Blue Coat ProxySG
- Splunk Add-on for McAfee
- Splunk Add-on for Juniper
- Splunk Add-on for Microsoft Windows
- Splunk Add-on for Oracle Database
- Splunk Add-on for OSSEC
- Splunk Add-on for RSA SecurID
- Splunk Add-on for Sophos
- Splunk Add-on for FireSIGHT
- Splunk Add-on for Symantec Endpoint Protection
- Splunk Add-on for Unix and Linux
- Splunk Add-on for Websense Content Gateway
The following technology add-ons are removed from the installer, supported for the next year, but are deprecated and will reach end of support one year from the release date of this Enterprise Security version:
- TA-airdefense
- TA-alcatel
- TA-cef
- TA-fortinet
- TA-ftp
- TA-nmap
- TA-tippingpoint
- TA-trendmicro
Updated add-ons
The Common Information Model Add-on is updated to version 8.6.0 and was released on July 21, 2026. The version number for the Common Information Model is synchronized with the version number of Splunk Enterprise Security from this release.
Libraries
The following libraries are included in this release:
- Splunk_ML_Toolkit-5.3.0-1631633293630.tgz
- Splunk_SA_Scientific_Python_linux_x86_64-3.0.2-0
- Splunk_SA_Scientific_Python_windows_x86_64-3.0.0