Share data usage in Splunk Enterprise Security
How data is collected
Splunk Enterprise Security uses saved searches to collect anonymous usage data. These searches run in the background regardless of whether or not you opt-in to send usage data to Splunk, and do not have any significant impact on performance.
Splunk Enterprise Security also uses FullStory to collect experiential user journey information with the user personally identifiable information redacted.
Splunk collects usage data to improve the design, usability, and experience of the product. Customers may opt-out of sharing AI data including, but not limited to, chats, responses, context, and feedback. To opt out of sharing this AI data, see Opt out of data sharing for the AI Assistant in Splunk Enterprise Security.
What data is collected
Splunk Enterprise Security version 8.5 collects the following basic usage information. This page includes new telemetry components introduced in version 8.5. Splunk Enterprise Security still collects components introduced in earlier versions. Use the version selector to see data collection documentation from earlier versions.
For more information on telemetry information collected by Splunk SOAR, see Share data from Splunk SOAR (Cloud).
| Component | Description | Example |
|---|---|---|
ai-analysis-feedback-submitted |
Measure usefulness/quality of AI Analysis responses by incident and reason breakdown |
JSON
|
ai-analysis-nested-section-toggled |
Understand which sections users engage with most; which tools are surfaced/used |
JSON
|
ai-analysis-section-toggled |
Track overall engagement with AI Analysis section visibility |
JSON
|
ai-analysis-view-details-clicked |
Track deeper investigation intent and feature usage |
JSON
|
ai-suggested-disposition-match |
Measures AI suggestion adoption / trust signal (how often users accept AI's suggested disposition) |
JSON
|
detection-status-filter-changed |
Understand how users filter detections (which states are most used) and UX effectiveness of filtering |
JSON
|
ai-triage-status-filter-changed |
Understand how users filter detections by AI triage status and UX effectiveness of filtering |
JSON
|
detections-search-performed |
Understand search adoption and effectiveness (zero-result searches, common filters paired with searches) |
JSON
|
detections-load-error |
Track reliability issues and identify failing filter combinations / backend problems |
JSON
|
ai-triage-bulk-turned-on |
Adoption and usage patterns of bulk AI triage; size of bulk operations and which detections are targeted |
JSON
|
ai-triage-bulk-turned-off |
Adoption and usage patterns of bulk AI triage; size of bulk operations and which detections are targeted |
JSON
|
rbac-team-queue (permissions-updated) |
Capture role counts for each permission in a queue when save is hit; tracks usage of granular permission settings |
JSON
|
rbac-team-queue (retention-period-configured) |
Captures the difference between queue-specific and global investigation retention period in days; only fires when global policy is enabled and queue retention is updated |
JSON
|
live-test-mode (status-change-attempt) |
Measure Live Test adoption rates, aggregate by detection types, track errors during status transition |
JSON
|
live-test-mode (inventory-snapshot) |
Measure how many detections and versions are being tested in Live Test mode at once |
JSON
|
sint-local-source (create) |
Measure how many local sources are created |
JSON
|
sint-local-source (update) |
Measure how many local sources are updated |
JSON
|
sint-local-source (delete) |
Measure how many local sources are deleted |
JSON
|
sint-local-source (activate) |
Measure how many local sources are activated |
JSON
|
sint-local-source (deactivate) |
Measure how many local sources are deactivated |
JSON
|
sint-cloud-source (subscribe) |
Measure how many cloud sources are subscribed |
JSON
|
sint-cloud-source (unsubscribe) |
Measure how many cloud sources are unsubscribed |
JSON
|
sint-threatlist (create) |
Measure how many threatlists are created |
JSON
|
sint-threatlist (update) |
Measure how many threatlists are updated |
JSON
|
sint-threatlist (delete) |
Measure how many threatlists are deleted |
JSON
|
sint-threatlist (activate) |
Measure how many threatlists are activated |
JSON
|
sint-safelist (create) |
Measure how many safelists are created |
JSON
|
sint-safelist (delete) |
Measure how many safelists are deleted |
JSON
|
sint-safelist-entry (update) |
Measure how many safelist entries are updated |
JSON
|
sint-safelist-entry (delete) |
Measure how many safelist entries are deleted |
JSON
|
detection-in-editor-testing (diet-test-launch) |
Tracks how many detection tests are being run |
JSON
|
detection-in-editor-testing (diet-test-cancel) |
Tracks how many times results loading is canceled |
JSON
|
detection-in-editor-testing (diet-versioning-test-launch) |
Tracks how many version comparison tests are being run |
JSON
|
detection-in-editor-testing (diet-test-versioning-cancel) |
Tracks how many times results loading for version comparison is canceled |
JSON
|
detection-in-editor-testing (diet-results / success) |
Tracks how many times results fetch was successful for user |
JSON
|
detection-in-editor-testing (diet-warning / partial) |
Tracks how many times results shown were partial |
JSON
|
detection-in-editor-testing (diet-error) |
Tracks how many times results fetch was not successful and the reason for it |
JSON
|
aqSidePanelLayoutChanged |
Determines whether users are leveraging the new streamlined two-column redesign experience in the AQ side panel |
JSON
|
collapsibleSectionToggled |
Determines what information sections in the AQ sidepanel and investigation overview users persist for daily usage |
JSON
|
fieldGroupSelectionChanged |
Determines what field groups the analyst deems important for investigation/triage |
JSON
|
viewCompleteAnalysis |
Determines how often the analyst uses the new Threat analysis tab in the investigation page to view full job details |
JSON
|
saa-invocation |
Track SAA API reliability and adoption — success/failure rates per endpoint, identify unreliable endpoints, measure overall SAA feature usage volume |
JSON
|