Share data usage in Splunk Enterprise Security
How data is collected
Splunk Enterprise Security uses saved searches to collect anonymous usage data. These searches run in the background regardless of whether or not you opt-in to send usage data to Splunk, and do not have any significant impact on performance.
Splunk Enterprise Security also uses FullStory to collect experiential user journey information with the user personally identifiable information redacted.
Splunk collects usage data to improve the design, usability, and experience of the product. Customers may opt-out of sharing AI data including, but not limited to, chats, responses, context, and feedback. To opt out of sharing this AI data, see Opt out of data sharing for the AI Assistant in Splunk Enterprise Security.
What data is collected
Splunk Enterprise Security version 8.5 collects the following basic usage information. This page includes new telemetry components introduced in version 8.5. Splunk Enterprise Security still collects components introduced in earlier versions. Use the version selector to see data collection documentation from earlier versions.
For more information on telemetry information collected by Splunk SOAR, see Share data from Splunk SOAR (Cloud).
| Component | Description | Example |
|---|---|---|
teamQueue |
Indicates that a team queue status is updated by de-activating and re-activating the queue and reports the total number of active and inactive queues. |
JSON
|
team-queue-check-empty |
Verifies whether the queue is empty or not prior to deleting a queue. |
JSON
|
team-queue-delete |
Indicates that a team queue is deleted and reports the total number of queues that are active and inactive. |
JSON
|
get-detection-state-executed |
Measures tool execution and tracking errors. |
JSON
|
scroll-to-section-executed |
Measures tool adoption and tracks errors. |
JSON
|
update-detection-fields-executed |
Measures tool adoption and tracks errors. |
JSON
|
session-summary |
Measures feature adoption. |
JSON
|
rbac-team-queue-permission-type-updated |
Indicates that a team queue role type is switched between fullAccess and customAccess and reports the total number of queues with fullAccess and customAccess selected. |
JSON
|
MissionControl.splunkOwnedResponseTemplateCloned ; SplunkOwnedResponseTemplateRetrieval ; SplunkOwnedResponseTemplateDownload |
Collects which Splunk owned response templates are downloaded, cloned, or retrieved. |
JSON
JSON
JSON
|
ResponseTemplateSoftLimitExceeded |
Tracks when the user exceeds the soft imposed limits for response templates. |
JSON
|
app.session.MissionControl.responseTemplateCreated |
Collects data from the response plan importer AI capability and measures which response plans are generated by AI, cloned, or human generated |
CODE
|
responseTemplateUpdated |
Measures which response plans are generated by AI, cloned, or human generated |
CODE
|
ResponsePlanAiImportSubmitted |
Tracks when a user started a new AI response plan generation. |
JSON
|
ResponsePlanAiImportFinished |
Tracks when the system finished generating anAI response plan. |
JSON
|
ResponsePlanAiGeneratedApplied |
Tracks when an AI generated response plan was applied to an investigation. |
JSON
|
aiAnalysisFeedbackSubmitted |
Measures the usefulness or the quality of AI Analysis responses by incident and logic breakdown. |
JSON
|
aiAnalysisCopied |
Measures how often the users copy AI analysis. |
JSON
|
aiAnalysisCopyFailed |
Tracks the copy failure rate. |
JSON
|
aiAnalysisDownloaded |
Measures how often the users download AI analysis as PDF. |
JSON
|
aiAnalysisDownloadFailed |
Tracks the download failure. |
JSON
|
aiAnalysisSavedAsNote |
Measures how often the users save AI analysis to notes. |
JSON
|
aiAnalysisSaveAsNoteFailed |
Tracks the note save failure rate. |
JSON
|
connectorsSearchPerformed |
Measures the connector search usage and result quality. |
JSON
|
connectorsLoadError |
Tracks the connector load failure rate and conditions. |
JSON
|
aiTriageConnectorActionToggled |
Tracks the action-level AI triage adoption. |
JSON
|
aiTriageConnectorActionToggleFailed empty |
Tracks the action toggle failure rate. |
JSON
|
activityLogCsvDownloaded |
Tracks the user clicks on the download button forthe Activity Log in Response History. |
JSON
|
activityLogRefreshed |
Tracks the user clicks on refresh to re-fetch the activity log. |
JSON
|
activityLogSorted |
Tracks the user clicks on sort or filters within the activity log table. |
JSON
|
activityLogPageChanged |
Tracks the user changes to the activity log page. |
JSON
|
DrilldownDashboardList and DrilldownSearchList |
Tracks the clicks when a user adds or removes a drill-down dashboard or drill-down search. Currently these components are being used in the ES Ingest Settings UI. These events measure usage of drilldown features for users of the ES Phishing flow. |
JSON
|
app.exposure-analytics.details |
Track the number of custom enrichment entries that are added for each type. Also, track custom enrichment usage statistics. |
JSON
|
|
|
A mapping between customer and data with restricted access for those with permissions to view the mapping table. |
JSON
|
|
|
Track the percentage of our customers, who are paid users. Also, track the license status of current customers. |
JSON
|
automation.summary.playbook_names |
Getting a deeper understanding of the playbooks that are created by customers. |
JSON
|
|
|
A mapping between customer and data with restricted access for those with permissions to view the mapping table. |
JSON
|
|
app.session.soar.license app.session.phantom.license |
Track the percentage of customers that are paid users. Also, track the license status of current customers. |
JSON
|
app.session.soar.license |
Track the percentage of our customers that are paid users and the license status of current customers. |
JSON
|
app.session.phantom.license |
Track the percentage of our customers that are paid users. Also, track the license status of the current customers. |
JSON
|
app.session.soar.pageview |
Track the most popular pages in Splunk SOAR. |
JSON
|
app.session.phantom.pageview |
Track the most popular pages in Phantom. |
JSON
|
app.session.soar.error |
Uncaught errors of front-end Phantom scripts. |
JSON
|
app.session.soar.error |
Uncaught errors of front-end Phantom scripts. |
JSON
|
app.session.soar.apiTime |
Track the efficiency of our API requests. Also, track if there are any noticeable errors coming back to the client side. |
JSON
|
app.session.phantom.apiTime |
Track the efficiency of our API requests? Also, track if there are any noticeable errors coming back to the client side. |
JSON
|
app.session.phantom.vpe |
Track the vpe that a customer is using such as Classic or Modern. Also, track the number of blocks an average playbook has and the average count of each block type. Also, track how the playbooks grow over time. |
JSON
|
app.session.soar.vpe |
Track the vpe that a customer using such as Classic or Modern. Also track the number of blocks an average playbook has and the average count of each block type. Also, track how the playbooks grow over time. |
JSON
|
app.session.phantom.vpeTime |
Track the average page load time for the vpe. |
JSON
|
app.session.soar.vpeTime |
Track the average page load time for the vpe. |
JSON
|
|
|
Reack which features are being turned on by the customers. |
JSON
|
app.session.soar.systemSettings |
Feature turned on or turned off settings and product version. |
JSON
|
app.session.phantom.systemSettings |
Feature turned on or turned off settings and product version. |
JSON
|
automation.summary.ingestion_status |
Track how many apps are currently installed for a given deploymentID. Also, track how many times a given app is launched and what is the distribution of apps installed for all deployment Ingestion status and events ingested per SOAR stackIDs. |
JSON
|
automation.summary.publish_telemetry_time_taken |
Time taken for publish_telemetry job to run to examine the performance of the queries. |
JSON
|
automation.summary.app_summary |
Get a deeper understanding of the apps customers are using from a summary of apps that are installed on the system. |
JSON
|
automation.summary.playbook_runs.by_trigger |
Track the number of SOAR playbooks run by Mission Control customers and track the count of playbook runs by trigger, i.e. adhoc or automated, aggregated over a given day. Emitted once per day at 12:00 AM UTC. |
JSON
|
automation.summary.case_summary |
A summary of opened or closed cases. |
JSON
|
automation.summary.workbook_summary |
A summary of opened or closed workbooks. |
JSON
|
orchestration.summary.action_runs.by_trigger |
Identify what fraction of action runs are executing on broker groups versus local versus legacy brokers, and track RPC broker adoption in terms of actual workload, not just registration. |
JSON
|
automation_broker.summary.broker_adoption |
Track RPC broker adoption over time, alert when inactive_rpc_broker_count spikes, and understand version spread across the fleet. |
JSON
|
automation_broker.summary.group_adoption |
Identify degraded or empty groups that need attention, understand HA posture (i.e. how many groups are truly active versus just registered, and track group adoption depth. |
JSON
|
automation_broker.summary.asset_assignment |
Measure ABHA adoption depth, understand the share of assets that are protected by HA groups versus a single broker versus local execution. Track app-level RPC/group usage. |
JSON
|
automation_broker.summary.registration |
Detect registration churn (many re-registrations may indicate instability); validate credential rotation is happening on schedule; compare against fleet size for coverage. |
JSON
|
automation_broker.summary.group_management |
Track group lifecycle activity, identify customers actively managing HA topology, flag unexpected removal spikes as potential mis-configurations. |
JSON
|
automation_broker.summary.group_dispatch |
Measure actual broker group workload, track failure rates for group-dispatched actions, and identify under-utilized or overloaded groups. |
JSON
|
automation_broker.summary.group_dispatch |
Understand the mix of websocket vs RPC connectivity among legacy brokers. Also, track the upgrade progress across the fleet and inform deprecation planning for older broker versions. |
JSON
|
app.session.DA-ESS-TIM.dashboardLoaded |
Track how frequently users access the TIM dashboard. Also, track the adoption rate of the TIM app and when a user loads the TIM dashboard page. |
JSON
|
app.session.DA-ESS-TIM.filterApplied |
Track the frequency with which users use filtering capabilities and the number of filters users typically apply at the same time. |
JSON
|
app.session.DA-ESS-TIM.openInSearch |
Track how frequently users drill down into the raw search from the TIM dashboard. Also, track whether users find the dashboard panels informative enough or if they need to investigate further. |
JSON
|
app.DA-ESS-TIM.TIMSearch |
Track the time taken by dashboard queries to run. For long-running queries, track the number of results and identify any performance bottlenecks in specific panels. |
JSON
|
app.DA-ESS-TIM.TIMPerformanceMetadata |
Track how long the TIM dashboard takes to load and render. Also, track the dashboard complexity and performance regressions between versions. |
JSON
|
chatFeedbackSubmitted |
Measure SecA assistant response quality and usefulness by tenant, user feedback direction, reason, screen/surface, and product context. Use negative feedback patterns and comments to identify response-quality issues and prioritize improvements. |
PYTHON
|
chatMessageCaptured |
Measure SecA usage volume, conversation length, message role mix, and assistant response flow. |
JSON
|
contextSubmitted |
Understand which context types are used, detect oversized context, prioritize context handling improvements. |
JSON
|
skillOrchestrationCompleted |
Measure skill selection quality, understand feature usage, and debug wrong tool/skill routing. |
JSON
|
splFewshotSearchPerformed |
Measure retrieval relevance, detect RAG gaps, and improve SPL example corpus. |
JSON
|
modelGenerationCompleted |
Evaluate model quality, debug poor generations, and compare behavior by model. |
JSON
|
ragPromptFetchNoMatches |
Identify RAG corpus coverage gaps and queries with no useful retrieval hits. |
JSON
|
|
Measure usefulness/quality of AI Analysis responses by incident and reason breakdown |
JSON
|
ai-analysis-nested-section-toggled |
Understand which sections users engage with most; which tools are surfaced/used |
JSON
|
ai-analysis-section-toggled |
Track overall engagement with AI Analysis section visibility |
JSON
|
ai-analysis-view-details-clicked |
Track deeper investigation intent and feature usage |
JSON
|
ai-suggested-disposition-match |
Measures AI suggestion adoption / trust signal (how often users accept AI's suggested disposition) |
JSON
|
detection-status-filter-changed |
Understand how users filter detections (which states are most used) and UX effectiveness of filtering |
JSON
|
ai-triage-status-filter-changed |
Understand how users filter detections by AI triage status and UX effectiveness of filtering |
JSON
|
detections-search-performed |
Understand search adoption and effectiveness (zero-result searches, common filters paired with searches) |
JSON
|
detections-load-error |
Track reliability issues and identify failing filter combinations / backend problems |
JSON
|
ai-triage-bulk-turned-on |
Adoption and usage patterns of bulk AI triage; size of bulk operations and which detections are targeted |
JSON
|
ai-triage-bulk-turned-off |
Adoption and usage patterns of bulk AI triage; size of bulk operations and which detections are targeted |
JSON
|
rbac-team-queue (permissions-updated) |
Capture role counts for each permission in a queue when save is hit; tracks usage of granular permission settings |
JSON
|
rbac-team-queue (retention-period-configured) |
Captures the difference between queue-specific and global investigation retention period in days; only fires when global policy is enabled and queue retention is updated |
JSON
|
live-test-mode (status-change-attempt) |
Measure Live Test adoption rates, aggregate by detection types, track errors during status transition |
JSON
|
live-test-mode (inventory-snapshot) |
Measure how many detections and versions are being tested in Live Test mode at once |
JSON
|
sint-local-source (create) |
Measure how many local sources are created |
JSON
|
sint-local-source (update) |
Measure how many local sources are updated |
JSON
|
sint-local-source (delete) |
Measure how many local sources are deleted |
JSON
|
sint-local-source (activate) |
Measure how many local sources are activated |
JSON
|
sint-local-source (deactivate) |
Measure how many local sources are deactivated |
JSON
|
sint-cloud-source (subscribe) |
Measure how many cloud sources are subscribed |
JSON
|
sint-cloud-source (unsubscribe) |
Measure how many cloud sources are unsubscribed |
JSON
|
sint-threatlist (create) |
Measure how many threatlists are created |
JSON
|
sint-threatlist (update) |
Measure how many threatlists are updated |
JSON
|
sint-threatlist (delete) |
Measure how many threatlists are deleted |
JSON
|
sint-threatlist (activate) |
Measure how many threatlists are activated |
JSON
|
sint-safelist (create) |
Measure how many safelists are created |
JSON
|
sint-safelist (delete) |
Measure how many safelists are deleted |
JSON
|
sint-safelist-entry (update) |
Measure how many safelist entries are updated |
JSON
|
sint-safelist-entry (delete) |
Measure how many safelist entries are deleted |
JSON
|
detection-in-editor-testing (diet-test-launch) |
Tracks how many detection tests are being run |
JSON
|
detection-in-editor-testing (diet-test-cancel) |
Tracks how many times results loading is canceled |
JSON
|
detection-in-editor-testing (diet-versioning-test-launch) |
Tracks how many version comparison tests are being run |
JSON
|
detection-in-editor-testing (diet-test-versioning-cancel) |
Tracks how many times results loading for version comparison is canceled |
JSON
|
detection-in-editor-testing (diet-results / success) |
Tracks how many times results fetch was successful for user |
JSON
|
detection-in-editor-testing (diet-warning / partial) |
Tracks how many times results shown were partial |
JSON
|
detection-in-editor-testing (diet-error) |
Tracks how many times results fetch was not successful and the reason for it |
JSON
|
aqSidePanelLayoutChanged |
Determines whether users are leveraging the new streamlined two-column redesign experience in the AQ side panel |
JSON
|
collapsibleSectionToggled |
Determines what information sections in the AQ sidepanel and investigation overview users persist for daily usage |
JSON
|
fieldGroupSelectionChanged |
Determines what field groups the analyst deems important for investigation/triage |
JSON
|
viewCompleteAnalysis |
Determines how often the analyst uses the new Threat analysis tab in the investigation page to view full job details |
JSON
|
saa-invocation |
Track SAA API reliability and adoption — success/failure rates per endpoint, identify unreliable endpoints, measure overall SAA feature usage volume |
JSON
|