Release notes for Splunk Enterprise Security

Find the following information on the Splunk Enterprise Security version 8.6.x release:

What's New in 8.6.1

New features in release 8.6.1

Splunk Enterprise Security version 8.6.1 was released for General Availability on August 4, 2026 and was released for Controlled Availability on July 21, 2026 as version 8.6.0. It includes the following enhancements:

Documentation update: You can now download entire manuals in portable document format (PDFs). Go to any documentation topic on help.splunk.com, select the PDF button, and then select Download Manual. Available for most manuals.

Splunk idea New feature Description
Agentic SOC: Splunk Enterprise Security offers the following AI-powered agents to assist with tasks such as creating detections, triage findings, authoring playbooks, and so on. For more information, see Agentic AI offerings in Splunk Enterprise Security.
Detection Builder agent is an AI-assisted workflow integrated in the detection editor to create, tune, validate, and troubleshoot detections. Ability to create, explain, and annotate detections. For more information, see Author detections using the Detection Builder agent in Splunk Enterprise Security and Troubleshoot AI Assistant in Splunk Enterprise Security.
Triage agent is an AI-assisted alert triage to help analysts focus on higher-priority findings.

Ability to prioritize alerts, explain findings, and help analysts focus on true positives. For more information, see Set up Trige agent in Splunk Enterprise Security.

Malware Reversing Agent and Phishing analysis agent to enrich alerts with insights, support investigations, and accelerate threat hunting Ability to review and investigate potentially malicious scripts using the AI-powered Malware Reversing Agent and Phishing Analysis Agent in Splunk Enterprise Security. For more information, see
Analyze scripts using the AI-powered Malware Reversing Agent and Phishing Analysis Agent.
Guided Response agent Ability to run SOAR response actions or playbooks on findings using the AI-powered Guided Response agent so that you can accelerate your security response. For more information, see Run SOAR response actions using the Guided Response Agent in Splunk Enterprise Security.
Automation Builder agent o build SOAR playbooks faster using natural language. Ability to turn a natural language automation idea into a tested SOAR playbook. For more information, see Use the Automation Builder Agent to build and understand playbooks.
Cloud connected on-premises support for AI Assistant in Splunk Enterprise Security Ability to access AI Assistant in Splunk Enterprise Security if you are using Splunk Cloud Connect to connect on-premises deployments of Splunk Enterprise Security with Cloud-native, Splunk managed, or Splunk Cloud Services (SCS). For more information, see Access Splunk Cloud Connect in Splunk Enterprise Security to access Cloud extensions.
Standard Operation Procedure (SOP) agent Ability to operationalize SOC procedures inside response plans and keep the response aligned to team process. For more information, see Create response plans with the SOP agent.
Improvements to Detection Studio Key performance indicator (KPI) refreshes for selected detections, compatibility labels, fixes to the accuracy for confidence and KPIs, improved handling of large detection libraries and long-running jobs, and improved health telemetry for tracking integration status, job state, execution time, and reliability at scale. For more information, see Identify optimal detections for your security environment using Detection studio in Splunk Enterprise Security.
Updates to capabilities for team queues Modifications to role-based access (RBAC) capabilities for queues, deletion and deactivation of queues, access to dashboards based on RBAC queue controls. For more information, see Analyst and team-based queues in Splunk Enterprise Security.
Activity logs to create an audit trail in a unified logging format

Review a clear, consistent audit trail for key actions across findings, finding groups, and investigations. The activity log captures updates, deletions, note activity, ownership changes, and other investigation events in a paginated table, helping teams understand what changed, when it changed, and who made the change. CSV export is available for sharing, review, and offline analysis.

Ability to provide a detailed description of all changes made to a finding, finding group, or investigation and create a tamper-proof audit trail in a unified logging format using Activity logs, which can be parsed by dashboards or custom searches. For more information, see Create an audit trail in a unified logging format using Activity logs in Splunk Enterprise Security.
Detection versioning is turned on by default for both Splunk Cloud Platform and Splunk Enterprise deployments in ES version 8.6 Detection versioning is turned on by default and provides a history of changes to the detection, and a comparison of supporting versions as well as version-dependent workflows. This release resolves the issues that required detection versioning to be turned off for ES versions 8.4.1 and 8.5.1. Detection versioning is automatically turned on as part of the upgrade to ES version 8.6. After versioning is turned on, all changes made while detection versioning was turned off are captured in a single detection version. If the detection is turned on, that version becomes active. You can turn off the feature when required and configure advanced settings in the UI. For more information, see Use detection versioning in Splunk Enterprise Security.
Exposure Analytics updates

Expanded discovery reporting provides deeper, intelligence-driven insights into trends, operating systems, cloud environments, default accounts, NHI and more. See Entity discovery insights for details.

Subnet discovery helps accelerate investigations by querying an IP or subnet to view all assets discovered within that same network boundary. See Review entity subnets for details.

Entity change history provides a comprehensive timeline of how assets and users evolve over time, providing the timeline needed to reconstruct events and distinguish routine updates from potential threats. See Review attributions for an entity for details.

Enrichment lookups can now be modified to enrich entity discovery with tailored business environmental intelligence. See Enrichment lookups in Exposure Analytics for details.

Threat intelligence dashboard Displays the aggregated threat intelligence data that your system has ingested, providing insights for enrichment and detection matching. For details, see Gain insights with the threat intelligence dashboard.
Entity risk score (ERS) improvements Three multipliers re-added to this score: detection_frequency_per_entity_multiplier, detection_frequency_per_stack_multiplier, and detection_quality_per_stack_multiplier. For details, see Entity risk scoring in Splunk Enterprise Security.
New UEBA auditing dashboard UEBA Detection Performance Summary view that provides aggregated insights for selected detections. For details, see Auditing UEBA with dashboards in Splunk Enterprise Security.
New UEBA cloud detection

New UEBA Content App for Cloud (DA-ESS-UEBASecurityContent) extends the functions of UEBA and accesses UEBA detections. For details, see User and entity behavior analytics (UEBA) overview in Splunk Enterprise Security and UEBA Content App for Cloud.

Inline attachment previews Review evidence quickly without breaking your flow. Open and expand PDFs, images, and more right inside attachments to spot key details and keep investigations moving. Supports PNG, PDF, JPEG, GIF, BMP, and WebP. For details, see Upload files to an investigation.
System insights updates

Improvements to the System Insights data visualizations user interface, along with including new tabs that include asset and ingestion activity, certificate status, and system resources health.

For details, see System insights in the Splunk App for SOAR Users' Guide.

Modifications to the menu options for navigation in the user interface for Splunk Enterprise Security version 8.6 UI to ensure consistency with Cisco products.

Updates to the menu options and collapsible side navigation panels for streamlined user workflows and consistency. For more information, see Differences in navigation menu options in Splunk Enterprise Security version 8.6 and higher.
Note: New menu options for navigation are available on both Cloud and On-premise for Splunk Enterprise Security Essentials and Premier Editions. However, you must use Splunk Enterprise Security version 8.6 paired with Splunk Platform 10.4.x or higher to view these navigation menu options.

For additional enhancements in Splunk SOAR, see the following articles:

Welcome to Splunk SOAR (Cloud)

Welcome to Splunk SOAR (On-premises)

Upgrade notice for 8.x

Upgrading Splunk Enterprise Security to version 8.x is a one-way operation. The upgrade process doesn't automatically back up the app, its content, or its data. Perform a full backup of the search head, including the KV Store, before initiating the Splunk Enterprise Security upgrade process.

When you upgrade to Splunk Enterprise Security version 8.x, you can no longer access any investigations created prior to the upgrade. To save archives of your investigation data, back up and restore your existing Splunk Enterprise Security instance.

If you need to revert back to the version that previously existed on your search head, you must restore the previous version of Splunk Enterprise Security from a backup.

See Upgrade Splunk Enterprise Security.

Note: Upgrades to Splunk Enterprise Security version 8.x from versions 6.x and earlier are not supported. If you are using on-premises version 6.x or earlier, you must first upgrade to version 7.3.2 before upgrading to version 8.x.

Other important notes for upgrading include the following:

  • You cannot upload Splunk Enterprise Security 8.x on an on-premises deployment of Splunk Enterprise 10.x using the UI. You must install Splunk Enterprise Security 8.x using the command line. See Install Splunk Enterprise Security from the command line.
  • Splunk Enterprise Security in a search head cluster environment uses an installer that creates tokens and turns on token authorization if it is not available. Post-installation, the installer deletes the tokens. If an error occurs, contact Splunk Support to delete any residual tokens.
  • The Splunk Enterprise Security Health app is installed but is turned off for all Splunk Cloud customers. This app is turned on by the Splunk Cloud Platform only during upgrades to ensure that the stacks get upgraded faster. Do not turn on the Splunk Enterprise Security Health app.

Share threat data in Splunk Enterprise Security

Sharing telemetry usage data is different from sharing threat data. Sharing of threat data in Splunk Enterprise Security is only introduced for Splunk Enterprise Security Hosted Service Offering (cloud) customers with a standard terms contract renewed or created after January 10, 2025. For more information, see Share threat data in Splunk Enterprise Security

Compatibility and support

  • Splunk Enterprise Security version 8.x is compatible only with specific versions of the Splunk platform. See Splunk products version compatibility matrix for details.
  • Current versions of Splunk Enterprise Security only support TAXII version 1.0 and TAXII version 1.1.

Model Runtime in Splunk Security Assistant

What it means when you let Splunk determine the best model to use

Splunk Security Assistant provides the option to use the large language models (LLMs) hosted in Splunk Cloud Platform or models hosted in Azure OpenAI. When you use the Model Runtime feature, letting Splunk determine the best model to use, Splunk Security Assistant determines when to use a Splunk platform hosted LLM, and when to use a third-party LLM, based on your prompt. Third-party LLMs can provide better response quality through the assistant, depending on factors such as use case and cost. ES 8.6 or higher uses Model Runtime by default. Administrators can turn off this functionality at any time from the Settings page.

  1. In Splunk Enterprise Security, select Configure and then All configurations.
  2. Select Security AI Assistant settings.
  3. In the Model choice section, select Limit to Splunk-hosted models only.

Using the Model Runtime feature

When you choose to let Splunk determine the best model to use, Splunk AI Assistant can leverage an external large language models (LLM) hosted in Azure OpenAI. This LLM generates the response provided by the app when deemed necessary, and can improve the response quality.

Splunk Security Assistant leverages the additional options from the LLM based on the intent and complexity of the request. The external LLM endpoint is secure but is outside the Splunk platform data boundary. The search prompt is sent to the third-party LLM and is governed by the third-party LLM provider's data handling policy.

The Model Runtime feature includes enterprise-grade compliance and regional data boundaries. Opting in causes no disruption to Splunk Security Assistant services or responsiveness.

When you opt-in, search responses are tagged with the source as being either internal, using the Splunk platform, or external, using the third-party LLM. Administrators can view these audit log tags as needed.

Model Runtime feature availability and region standard

See the following table for each supported region for Model Runtime, when the feature became available in that region, and the region standard. Region standard shows if your requests to the app might be processed outside the selected region.

Region standards are defined as follows:

  • Data zone standard: App requests can route to any region within the same zone. Provides zone-level routing only.

  • Global standard App requests can route anywhere in the world. Does not provide zone-level or country-level routing guarantees.

Region Feature availability Region standard
AWS - Canada Central Available as of ES version 8.6 Global
AWS - AP Mumbai Available as of ES version 8.6 Global
AWS - AP Seoul Available as of ES version 8.6 Global
AWS - AP Singapore Available as of ES version 8.6 Global
AWS - AP Sydney Available as of ES version 8.6 Global
AWS - AP Tokyo Available as of ES version 8.6 Global
AWS - EU London Available as of ES version 8.6 Global
AWS - EU Frankfurt Available as of ES version 8.6 Data zone
AWS - EU Dublin Available as of ES version 8.6 Data zone
AWS - EU Milan Available as of ES version 8.6 Data zone
AWS - EU Paris Available as of ES version 8.6 Data zone
AWS - US West Oregon Available as of ES version 8.6 Data zone
AWS - US East Virginia Available as of ES version 8.6 Data zone
AWS - SA São Paulo Available as of ES version 8.6 Global
Azure - East US (Virginia) Available as of v1.4.0 N/A
Azure - UK South (London) Available as of v1.4.0 N/A
Azure - West US (California) Available as of v1.4.0 N/A
Azure - Japan East (Tokyo) Available as of v1.4.0 N/A

Supported regions

You can only use the Model Runtime feature if you are running the assistant in a supported region. Model Runtime is supported for Splunk AI Assistant users in the following regions:

  • AWS - Canada Central

  • AWS - AP Mumbai

  • AWS - AP Seoul

  • AWS - AP Singapore

  • AWS - AP Sydney

  • AWS - AP Tokyo

  • AWS - EU London

  • AWS - EU Frankfurt

  • AWS - EU Dublin

  • AWS - EU Milan

  • AWS - EU Paris

  • AWS - US West Oregon

  • AWS - US East Virginia

  • AWS - SA São Paulo

  • Azure - East US (Virginia)

  • Azure - UK South (London)

  • Azure - West US (California)

  • Azure - Japan East (Tokyo)

Deprecated or removed features

The following sources have been deprecated for Threat Intelligence Management in Splunk Enterprise Security 8.6.x and higher:
  • URLHaus

  • Abuse SSL IP Blacklist

Note: If you are using Splunk Enterprise Security for the first time, you must not subscribe to these deprecated sources. If you are an existing user, you must unsubscribe from these deprecated sources to avoid any disruptions.
The URLHaus source is deprecated due to changes in licensing terms. A new source named URLhaus Malware URL Feed is added, which requires an API key for access. For licensing and API key information, see URLHaus.

The following features have been deprecated from Splunk Enterprise Security 8.x:

  • Configuring the investigation type macro is no longer available.
  • Incident Review row expansion is no longer available.
  • Enhanced workflows are no longer available.
  • Sequence templates are no longer available.
  • The Investigation bar, Investigation Workbench, and Investigation dashboard from the Splunk Enterprise Security user interface (UI) are replaced by the Mission Control UI.
  • Service level agreements (SLAs) and role-based incident type filtering are not available.
  • The Content management page was updated to remove the following types of content: Workbench Profile, Workbench Panel, and Workbench Tab.
  • Workbench and workbench related views such as ess_investigation_list, ess_investigation_overview, and ess_investigation have been removed.
  • Capabilities such as edit_timeline and manage_all_investigations have been removed.
  • The Comments feature is replaced by an enhanced capability to add notes.
  • In Splunk Enterprise Security version 7.3, admins can turn on a setting to require analysts to leave a comment with a minimum character length after updating a notable event. In Splunk Enterprise Security version 8.x, you can no longer require a note when an analyst updates a finding in the analyst queue.

Add-ons

Technology-specific add-ons are supported differently than the add-ons that make up the Splunk Enterprise Security framework. For more information on the support provided for add-ons, see Support for Splunk Enterprise Security and provided add-ons in the Release Notes manual.

Note: Some new features might not work for on-prem Splunk Enterprise Security deployments 8.x and higher, unless you upgrade the Splunk_TA_ForIndexers add-on for every release.
Note: Do not uninstall the Mission Control app since the app is part of Splunk Enterprise Security.

To ensure that the Splunk Enterprise Security app works correctly, turn on the following add-ons. If any of the following add-ons aren't turned on, Splunk Support gets automatically notified and ensures that all the required add-ons are turned on automatically.

  • DA-ESS-AccessProtection
  • DA-ESS-EndpointProtection
  • DA-ESS-IdentityManagement
  • DA-ESS-NetworkProtection
  • DA-ESS-ThreatIntelligence
  • SA-AccessProtection
  • SA-AuditAndDataProtection
  • SA-EndpointProtection
  • SA-IdentityManagement
  • SA-NetworkProtection
  • SA-ThreatIntelligence
  • Splunk_SA_CIM
  • Splunk_SA_Scientific_Python_linux_x86_64
  • SplunkEnterpriseSecuritySuite
  • Splunk_ML_Toolkit

Deprecated or removed add-ons

Splunk Enterprise Security no longer includes many of the technology add-ons in the Splunk Enterprise Security package. Instead, you can download the technology add-ons that you need directly from Splunkbase. This change improves the performance of Splunk ES by reducing the number of unnecessary enabled add-ons, and allows you to install the most appropriate and updated versions of add-ons when you install Splunk ES.

The following technology add-ons are removed from the installer, but still supported:

The following technology add-ons are removed from the installer, supported for the next year, but are deprecated and will reach end of support one year from the release date of this Enterprise Security version:

  • TA-airdefense
  • TA-alcatel
  • TA-cef
  • TA-fortinet
  • TA-ftp
  • TA-nmap
  • TA-tippingpoint
  • TA-trendmicro

Updated add-ons

The Common Information Model Add-on is updated to version 8.6.0 and was released on July 21, 2026. The version number for the Common Information Model is synchronized with the version number of Splunk Enterprise Security from this release.

Libraries

The following libraries are included in this release:

  • Splunk_ML_Toolkit-5.3.0-1631633293630.tgz
  • Splunk_SA_Scientific_Python_linux_x86_64-3.0.2-0
  • Splunk_SA_Scientific_Python_windows_x86_64-3.0.0