Release notes for Splunk Enterprise Security

Find the following information on the Splunk Enterprise Security version 8.6.x release:

Whats new in 8.7.0

What's new in release 8.7.0

Splunk Enterprise Security version 8.7.0 was released on September 2, 2026 and includes the following new enhancements:

Note: Features included in Enterprise Security Essentials Edition are also included in Enterprise Security Premier Edition.
Splunk idea New feature Description Edition
AI SOC Analyst Move from investigation to response at machine speed. The AI SOC Analyst uses investigation and response plan context to automatically execute permitted actions, recommend next steps when analyst approval is required, and complete response tasks.
Note: To enable this feature, contact your Splunk representative.
Premier
Connector Builder Agent

Create connectors faster with an AI agent that can generate, test, and refine connectors, increasing automation coverage across more tools. For details, see Create and edit connectors with the Connector Builder Agent.

To enable this feature, contact your Splunk representative.

Premier
Automation Builder agent Automation Builder Agent: Improved understanding of the playbook session and ES finding context so it can apply and verify changes more accurately. For more information, see Use the Automation Builder Agent to build and understand playbooks. Essentials and Premier
Enterprise Security on MCP Get the ES investigation context your AI needs — alerts, entities, findings, and supporting data — all through MCP. For more information, see Use the Splunk MCP Server app to access tools in Splunk Enterprise Security. Essentials
AI Agent Enhancements for Essentials Detection Builder Agent: Improved reliability and accuracy when creating and refining detections, with better SPL guidance and validation. Essentials
Updated ES Navigation experience Organize navigation to fit your workflow. Preview the layout and choose from a range of custom icons before applying changes. The updated design to the analyst queue, team-based queues, and saved views, provides a more streamlined way to work. For more information, see Differences in navigation menu options in Splunk Enterprise Security 8.7 and higher. Essentials
View Change History Gain deeper visibility into analyst activity with complete change history in SPL search. Select the new magnifying glass icon in the Activity Log section to investigate changes with fuller context. For more information, see Create an audit trail in a unified logging format using Activity logs in Splunk Enterprise Security. Essentials

Upgrade notice for 8.x

Upgrading Splunk Enterprise Security to version 8.x is a one-way operation. The upgrade process doesn't automatically back up the app, its content, or its data. Perform a full backup of the search head, including the KV Store, before initiating the Splunk Enterprise Security upgrade process.

When you upgrade to Splunk Enterprise Security version 8.x, you can no longer access any investigations created prior to the upgrade. To save archives of your investigation data, back up and restore your existing Splunk Enterprise Security instance.

If you need to revert back to the version that previously existed on your search head, you must restore the previous version of Splunk Enterprise Security from a backup.

See Upgrade Splunk Enterprise Security.

Note: Upgrades to Splunk Enterprise Security version 8.x from versions 6.x and earlier are not supported. If you are using on-premises version 6.x or earlier, you must first upgrade to version 7.3.2 before upgrading to version 8.x.

Other important notes for upgrading include the following:

  • You cannot upload Splunk Enterprise Security 8.x on an on-premises deployment of Splunk Enterprise 10.x using the UI. You must install Splunk Enterprise Security 8.x using the command line. See Install Splunk Enterprise Security from the command line.
  • Splunk Enterprise Security in a search head cluster environment uses an installer that creates tokens and turns on token authorization if it is not available. Post-installation, the installer deletes the tokens. If an error occurs, contact Splunk Support to delete any residual tokens.
  • The Splunk Enterprise Security Health app is installed but is turned off for all Splunk Cloud customers. This app is turned on by the Splunk Cloud Platform only during upgrades to ensure that the stacks get upgraded faster. Do not turn on the Splunk Enterprise Security Health app.

Share threat data in Splunk Enterprise Security

Sharing telemetry usage data is different from sharing threat data. Sharing of threat data in Splunk Enterprise Security is only introduced for Splunk Enterprise Security Hosted Service Offering (cloud) customers with a standard terms contract renewed or created after January 10, 2025. For more information, see Share threat data in Splunk Enterprise Security

Compatibility and support

  • Splunk Enterprise Security version 8.x is compatible only with specific versions of the Splunk platform. See Splunk products version compatibility matrix for details.
  • Current versions of Splunk Enterprise Security only support TAXII version 2.0 and TAXII version 2.0.

Model Runtime in Splunk Security Assistant

What it means when you let Splunk determine the best model to use

Splunk Security Assistant provides the option to use the large language models (LLMs) hosted in Splunk Cloud Platform or models hosted in Azure OpenAI. When you use the Model Runtime feature, letting Splunk determine the best model to use, Splunk Security Assistant determines when to use a Splunk platform hosted LLM, and when to use a third-party LLM, based on your prompt. Third-party LLMs can provide better response quality through the assistant, depending on factors such as use case and cost. ES 8.6 or higher uses Model Runtime by default. Administrators can turn off this functionality at any time from the Settings page.

  1. In Splunk Enterprise Security, select Configure and then All configurations.
  2. Select Security AI Assistant settings.
  3. In the Model choice section, select Limit to Splunk-hosted models only.

Using the Model Runtime feature

When you choose to let Splunk determine the best model to use, Splunk AI Assistant can leverage an external large language models (LLM) hosted in Azure OpenAI. This LLM generates the response provided by the app when deemed necessary, and can improve the response quality.

Splunk Security Assistant leverages the additional options from the LLM based on the intent and complexity of the request. The external LLM endpoint is secure but is outside the Splunk platform data boundary. The search prompt is sent to the third-party LLM and is governed by the third-party LLM provider's data handling policy.

The Model Runtime feature includes enterprise-grade compliance and regional data boundaries. Opting in causes no disruption to Splunk Security Assistant services or responsiveness.

When you opt-in, search responses are tagged with the source as being either internal, using the Splunk platform, or external, using the third-party LLM. Administrators can view these audit log tags as needed.

Model Runtime feature availability and region standard

See the following table for each supported region for Model Runtime, when the feature became available in that region, and the region standard. Region standard shows if your requests to the app might be processed outside the selected region.

Region standards are defined as follows:

  • Data zone standard: App requests can route to any region within the same zone. Provides zone-level routing only.

  • Global standard App requests can route anywhere in the world. Does not provide zone-level or country-level routing guarantees.

Region Feature availability Region standard
AWS - Canada Central Available as of ES version 8.6 Global
AWS - AP Mumbai Available as of ES version 8.6 Global
AWS - AP Seoul Available as of ES version 8.6 Global
AWS - AP Singapore Available as of ES version 8.6 Global
AWS - AP Sydney Available as of ES version 8.6 Global
AWS - AP Tokyo Available as of ES version 8.6 Global
AWS - EU London Available as of ES version 8.6 Global
AWS - EU Frankfurt Available as of ES version 8.6 Data zone
AWS - EU Dublin Available as of ES version 8.6 Data zone
AWS - EU Milan Available as of ES version 8.6 Data zone
AWS - EU Paris Available as of ES version 8.6 Data zone
AWS - US West Oregon Available as of ES version 8.6 Data zone
AWS - US East Virginia Available as of ES version 8.6 Data zone
AWS - SA São Paulo Available as of ES version 8.6 Global
Azure - East US (Virginia) Available as of v1.4.0 N/A
Azure - UK South (London) Available as of v1.4.0 N/A
Azure - West US (California) Available as of v1.4.0 N/A
Azure - Japan East (Tokyo) Available as of v1.4.0 N/A

Supported regions

You can only use the Model Runtime feature if you are running the assistant in a supported region. Model Runtime is supported for Splunk AI Assistant users in the following regions:

  • AWS - Canada Central

  • AWS - AP Mumbai

  • AWS - AP Seoul

  • AWS - AP Singapore

  • AWS - AP Sydney

  • AWS - AP Tokyo

  • AWS - EU London

  • AWS - EU Frankfurt

  • AWS - EU Dublin

  • AWS - EU Milan

  • AWS - EU Paris

  • AWS - US West Oregon

  • AWS - US East Virginia

  • AWS - SA São Paulo

  • Azure - East US (Virginia)

  • Azure - UK South (London)

  • Azure - West US (California)

  • Azure - Japan East (Tokyo)

Deprecated or removed features

The following sources have been deprecated for Threat Intelligence Management in Splunk Enterprise Security 8.6.x and higher:
  • URLHaus

  • Abuse SSL IP Blacklist

Note: If you are using Splunk Enterprise Security for the first time, you must not subscribe to these deprecated sources. If you are an existing user, you must unsubscribe from these deprecated sources to avoid any disruptions.
The URLHaus source is deprecated due to changes in licensing terms. A new source named URLhaus Malware URL Feed is added, which requires an API key for access. For licensing and API key information, see URLHaus.

The following features have been deprecated from Splunk Enterprise Security 8.x:

  • Configuring the investigation type macro is no longer available.
  • Incident Review row expansion is no longer available.
  • Enhanced workflows are no longer available.
  • Sequence templates are no longer available.
  • The Investigation bar, Investigation Workbench, and Investigation dashboard from the Splunk Enterprise Security user interface (UI) are replaced by the Mission Control UI.
  • Service level agreements (SLAs) and role-based incident type filtering are not available.
  • The Content management page was updated to remove the following types of content: Workbench Profile, Workbench Panel, and Workbench Tab.
  • Workbench and workbench related views such as ess_investigation_list, ess_investigation_overview, and ess_investigation have been removed.
  • Capabilities such as edit_timeline and manage_all_investigations have been removed.
  • The Comments feature is replaced by an enhanced capability to add notes.
  • In Splunk Enterprise Security version 7.3, admins can turn on a setting to require analysts to leave a comment with a minimum character length after updating a notable event. In Splunk Enterprise Security version 8.x, you can no longer require a note when an analyst updates a finding in the analyst queue.

Add-ons

Technology-specific add-ons are supported differently than the add-ons that make up the Splunk Enterprise Security framework. For more information on the support provided for add-ons, see Support for Splunk Enterprise Security and provided add-ons in the Release Notes manual.

Note: Some new features might not work for on-prem Splunk Enterprise Security deployments 8.x and higher, unless you upgrade the Splunk_TA_ForIndexers add-on for every release.
Note: Do not uninstall the Mission Control app since the app is part of Splunk Enterprise Security.

To ensure that the Splunk Enterprise Security app works correctly, turn on the following add-ons. If any of the following add-ons aren't turned on, Splunk Support gets automatically notified and ensures that all the required add-ons are turned on automatically.

  • DA-ESS-AccessProtection
  • DA-ESS-EndpointProtection
  • DA-ESS-IdentityManagement
  • DA-ESS-NetworkProtection
  • DA-ESS-ThreatIntelligence
  • SA-AccessProtection
  • SA-AuditAndDataProtection
  • SA-EndpointProtection
  • SA-IdentityManagement
  • SA-NetworkProtection
  • SA-ThreatIntelligence
  • Splunk_SA_CIM
  • Splunk_SA_Scientific_Python_linux_x86_64
  • SplunkEnterpriseSecuritySuite
  • Splunk_ML_Toolkit

Deprecated or removed add-ons

Splunk Enterprise Security no longer includes many of the technology add-ons in the Splunk Enterprise Security package. Instead, you can download the technology add-ons that you need directly from Splunkbase. This change improves the performance of Splunk ES by reducing the number of unnecessary enabled add-ons, and allows you to install the most appropriate and updated versions of add-ons when you install Splunk ES.

The following technology add-ons are removed from the installer, but still supported:

The following technology add-ons are removed from the installer, supported for the next year, but are deprecated and will reach end of support one year from the release date of this Enterprise Security version:

  • TA-airdefense
  • TA-alcatel
  • TA-cef
  • TA-fortinet
  • TA-ftp
  • TA-nmap
  • TA-tippingpoint
  • TA-trendmicro

Updated add-ons

The Common Information Model Add-on is updated to version 8.7.0 and was released on September 2, 2026. The version number for the Common Information Model is synchronized with the version number of Splunk Enterprise Security from this release.

Libraries

The following libraries are included in this release:

  • Splunk_ML_Toolkit-5.3.0-1631633293630.tgz
  • Splunk_SA_Scientific_Python_linux_x86_64-3.0.2-0
  • Splunk_SA_Scientific_Python_windows_x86_64-3.0.0