Welcome to Splunk SOAR (On-premises)
The Splunk SOAR (On-premises) platform combines security infrastructure orchestration, playbook automation, and case management capabilities to integrate your team, processes, and tools to help you orchestrate security workflows, automate repetitive security tasks, and quickly respond to threats.
If you are new to Splunk SOAR (On-premises), read About Splunk SOAR (On-premises) in the Use Splunk SOAR (On-premises) manual to learn how you can use Splunk SOAR (On-premises) for security automation.
If your Splunk SOAR (On-premises) deployment uses the Splunk SOAR Automation Broker see What's new in Splunk SOAR Automation Broker in the Set up and manage Splunk Automation Broker documentation.
Documentation for earlier versions of Splunk SOAR (On-premises)
Where to find older versions of docs that aren't on the new help portal yet.
We are in the process of moving all versions of Splunk SOAR (On-premises) to this new documentation portal. In the interim, you can reach previous documentation versions in the docs.splunk.com portal. Follow this link to documentation for Splunk SOAR (On-premises) version 6.0.1. From there, use the version selector tool to view documentation for other versions. If you select a version that is already in the new documentation portal, you will be automatically redirected to the new portal.
September 2, 2026 Release 8.7.0
enhancements found in Splunk SOAR (On-premises) version 8.7.0
Splunk SOAR (On-premises) version 8.7.0 was released for General Availability on September 2, 2026.
Important update
Python 3.9: End of support
Starting with this release, Splunk SOAR no longer supports Python 3.9. All SOAR automations, including playbooks, custom functions and apps, that are not compatible with 3.13 will no longer be executed.
For details on the self-service migration feature within the SOAR UI, automation scripts, and linting tools, see the list of references in How SOAR (On-premises) uses Python.
What's new in Splunk SOAR (On-premises)
| Splunk Idea | Feature | Description |
|---|---|---|
| Automation Broker High Availability (Controlled Availability)* | Create groups of Automation Brokers for high availability and scalability. Within each group, if one broker goes offline, traffic automatically switches to active brokers. Add brokers to a group to scale for higher loads and distribute work across them. For details, see About Splunk SOAR Automation Broker. |
* In the Controlled Availability release stage, Splunk products may have limitations on customer access, features, maturity, and regional availability. For additional information on Controlled Availability please contact your Splunk representative.