Welcome to Splunk SOAR (On-premises)

The Splunk SOAR (On-premises) platform combines security infrastructure orchestration, playbook automation, and case management capabilities to integrate your team, processes, and tools to help you orchestrate security workflows, automate repetitive security tasks, and quickly respond to threats.

If you are new to Splunk SOAR (On-premises), read About Splunk SOAR (On-premises) in the Use Splunk SOAR (On-premises) manual to learn how you can use Splunk SOAR (On-premises) for security automation.

If your Splunk SOAR (On-premises) deployment uses the Splunk SOAR Automation Broker see What's new in Splunk SOAR Automation Broker in the Set up and manage Splunk Automation Broker documentation.

Documentation for earlier versions of Splunk SOAR (On-premises)

Where to find older versions of docs that aren't on the new help portal yet.

We are in the process of moving all versions of Splunk SOAR (On-premises) to this new documentation portal. In the interim, you can reach previous documentation versions in the docs.splunk.com portal. Follow this link to documentation for Splunk SOAR (On-premises) version 6.0.1. From there, use the version selector tool to view documentation for other versions. If you select a version that is already in the new documentation portal, you will be automatically redirected to the new portal.

August 4, 2026 Release 8.6.0

What's new in the Splunk SOAR (On-premises) release 8.6.0

Important updates

Final version that supports Python 3.9

This is the final Splunk SOAR release that supports Python 3.9. Starting with the Splunk SOAR release scheduled for September 2026, Splunk SOAR will no longer support Python 3.9. Review your actively used automation and complete migration to Python 3.13.

For details on the self-service migration feature within the SOAR UI, automation scripts, and linting tools, see the list of references in How SOAR (Cloud) uses Python

FIPS 140-3 compliance

This release is compliant with FIPS 140-3. This FIPS version is used automatically for systems running Red Hat Enterprise Linux (RHEL) 9, Oracle Linux 9, or Amazon Linux 2023. For additional information on FIPS, see FIPS compliance in the Install and Upgrade Splunk SOAR (On-premises) manual.

The following apps are currently not compliant with FIPS 140-3:

Carbon Black Response, Cisco ESA, CylancePROTECT, Fidelis Network, ForeScout CounterACT, MS Graph for Active Directory, PostgreSQL, ProtectWise, QRadar, Symantec Security Analytics

Documentation updates
  • Release Notes format: Known and Fixed Issues in these release notes now indicate whether each issue relates to Splunk SOAR (Cloud), Splunk SOAR (On-premises), or both.

  • Downloadable PDFs: You can now download entire manuals in portable document format (PDFs). Go to any documentation topic on help.splunk.com, select the PDF button, and then select Download Manual. Available for most manuals.

What's new in Splunk SOAR (On-premises)

This release of Splunk SOAR (On-premises) includes the following enhancements.
Splunk Idea Feature Description

PPSID-I-649

PPSID-I-131

System Insights enhancements

Improvements to the System Insights data visualizations user interface, along with including new tabs that include asset and ingestion activity, certificate status, and system resources health.

For details, see System insights in the Splunk App for SOAR documentation. ​

Deferred upgrades for major app version changes

When a major update is available for an app with configured assets, that app's update is deferred. Users who can manage apps are notified and can review the new version before selecting it from the Apps page to complete the upgrade. For details, see Install app upgrades after a Splunk SOAR system upgrade in Install, update, or delete apps on Splunk SOAR (On-premises).

PPSID-I-144

FIPS 140-3 support Splunk SOAR now supports FIPS 140-3 for FedRAMP. For details, see FIPS compliance in Install and Upgrade Splunk SOAR (On-premises).