Latest Product Updates and Feature Enhancements on Splunk LLC
From a Slow Trace to the Slow Method: Introducing Call Graph Profiling in Splunk APM
Splunk has introduced Call Graph Profiling in its APM, enhancing its observability capabilities. This feature connects distributed traces to method-level execution, allowing teams to pinpoint ineffic...ient code paths and investigate performance issues more effectively. It complements AlwaysOn Profiling by providing detailed call graphs for specific traces, aiding in faster troubleshooting and performance optimization.
From AI Assistance to Agentic Action: Advancing the SOC in Splunk Enterprise Security 8.6
Splunk has launched Enterprise Security 8.6, enhancing security operations with AI-driven capabilities. The update includes features like Detection Builder, natural-language automation, and guided re...sponse, allowing security teams to automate tasks while maintaining control. The Agentic SOC model aims to improve threat detection and response times, helping analysts focus on high-priority security decisions.
Citrix launches Experience Insights Flex observability service powered by Splunk Cloud Platform
Citrix has launched the Experience Insights Flex observability service, powered by the Splunk Cloud Platform. This integration enhances Citrix's workspace observability capabilities, providing manage...d, prebuilt insights. The service aims to meet enterprise demand for simplified modern-work delivery and reduce operational overhead.
From Vision to Value: New Splunk Platform Innovations Supporting Cisco Data Fabric Are Generally Available
Splunk has announced the general availability of new platform innovations that support Cisco Data Fabric. These enhancements, including Machine Data Lake and Federated Search, enable organizations to... manage and integrate machine data across environments without centralizing it. The platform's capabilities improve data management, AI integration, and operational resilience, providing a unified data journey for enhanced decision-making and response.
Introducing Splunk Agent Skills: Portable Splunk Expertise for Your AI Agents
Splunk has launched its first open-source agent skills repository on GitHub, featuring three skills designed for AI agents. These skills help automate Splunk-specific tasks such as search drafting an...d dashboard conversion, enhancing AI agent capabilities. The skills are open-source, allowing integration with various AI coding agents like Claude Code and Codex.
CVE-2026-20251: RCE in Splunk Secure Gateway (CVSS 8.8) – what to do now
A critical vulnerability, CVE-2026-20251, has been identified in Splunk Secure Gateway, allowing remote code execution due to unsafe deserialization. Rated CVSS 8.8, it affects specific versions of S...plunk Enterprise and Splunk Cloud. Users are advised to upgrade to secure versions or disable the app temporarily to mitigate risks.
Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise Security
Splunk has introduced Automated Threat Analysis in Splunk Enterprise Security, enhancing phishing investigations by centralizing context and analysis within the platform. This integration allows secu...rity analysts to efficiently manage phishing threats, reducing manual tasks and improving response times. The feature includes advanced capabilities like QR code analysis and risk scoring to prioritize threats.
Introducing Splunk Agent Launchpad: Turn Operational Signals Into Agent-Powered Action
Splunk has launched the Splunk Agent Launchpad, a no-code tool for building AI agents within the Splunk environment. This tool allows security and IT teams to automate tasks directly from Splunk aler...ts and searches, enhancing operational efficiency. Available on the Splunk Cloud Platform, it integrates with existing data and user permissions, facilitating faster issue investigation and response.
Splunk ES Premier Achieves FedRAMP Moderate Certification
Splunk's Enterprise Security Premier edition has achieved FedRAMP Moderate certification, ensuring compliance with stringent federal security controls. This certification allows federal agencies to u...tilize ES Premier's advanced capabilities, including security orchestration and automated threat analytics, to enhance data integrity and security. Splunk also expands access to its Edge Processor and Ingest Processor for FedRAMP Moderate customers on AWS GovCloud.
Splunk disclosed a critical remote code execution vulnerability (CVE-2026-20253) in Splunk Enterprise, affecting versions prior to 10.2.4 and 10.0.7. The vulnerability allows unauthenticated attacker...s to exploit the PostgreSQL sidecar service via Splunk Web, potentially leading to arbitrary code execution. Users are advised to upgrade to patched versions and implement security measures to mitigate risks.
Active Exploitation of Critical CVE-2026-20253 in Splunk Enterprise ...
A critical vulnerability, CVE-2026-20253, in Splunk Enterprise versions 10.0.0-10.0.6 and 10.2.0-10.2.3, allows unauthenticated remote code execution via the PostgreSQL Sidecar Service. The flaw is a...ctively exploited, necessitating urgent upgrades to versions 10.2.4 or 10.0.7. Organizations should disable the PostgreSQL Sidecar Service if immediate upgrades are not possible, although this may impact certain workflows.
Splunk has disclosed a critical vulnerability, CVE-2026-20253, affecting its Enterprise and Cloud platforms. This flaw allows unauthenticated remote code execution due to missing authentication contr...ols in the PostgreSQL sidecar service. Rated with a CVSS score of 9.8, it poses a severe threat to unpatched systems. Splunk advises immediate patching to secure environments against potential exploits.
Splunk Enterprise Vulnerability Exploited in Attacks Days After ...
Splunk has patched a critical vulnerability in Splunk Enterprise, identified as CVE-2026-20253, which allows unauthenticated attackers to exploit a PostgreSQL sidecar service endpoint. The vulnerabil...ity affects versions 10.2 before 10.2.4 and 10.0 before 10.0.7. Organizations are urged to update to the fixed versions to mitigate risks.
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026 ...
Splunk Enterprise is facing an active attack due to a critical vulnerability (CVE-2026-20253) that allows unauthenticated remote code execution. The flaw, found in versions below 10.2.4 and 10.0.7, c...an lead to full system compromise. Splunk has released patches and recommends upgrading to fixed versions to mitigate risks.
U.S. CISA adds Splunk Enterprise flaw to its Known Exploited ...
A critical vulnerability in Splunk Enterprise, CVE-2026-20253, has been added to the U.S. CISA's Known Exploited Vulnerabilities catalog. This flaw allows unauthenticated remote attackers to manipula...te files on affected systems. Splunk urges immediate upgrades to patched versions to mitigate risks.
Splunk has identified multiple security vulnerabilities in its AI Toolkit and Enterprise products, including critical issues that allow unauthorized command execution and data exfiltration. These vul...nerabilities are due to unsafe shell execution patterns, insecure default settings, and improper access controls. Users are advised to upgrade to the latest versions to mitigate these risks.
Splunk disclosed a critical security vulnerability (CVE-2026-20253) in Splunk Enterprise, allowing unauthenticated remote code execution. The flaw, with a CVSS score of 9.8, affects specific versions... and requires urgent patching. The vulnerability involves an unauthenticated arbitrary file creation flaw in the PostgreSQL sidecar service. Organizations are advised to apply patches immediately to mitigate potential exploitation.
CISA KEV: Patch Splunk CVE-2026-20253 Missing Authentication Now
CISA added a critical vulnerability in Splunk Enterprise, CVE-2026-20253, to its Known Exploited Vulnerabilities Catalog. This flaw allows unauthenticated access to create or truncate files, posing a... significant risk to security infrastructure. Splunk has released patches for affected versions, emphasizing the need for immediate updates to maintain security integrity.
A critical vulnerability in Splunk, CVE-2026-20253, is being actively exploited. The flaw allows unauthorized file operations via a PostgreSQL sidecar service. Splunk urges customers to upgrade to fi...xed versions. CISA added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch within three days.
Splunk has addressed multiple vulnerabilities in its products, including Python for Scientific Computing, Splunk AI Toolkit, and Splunk SOAR, by upgrading third-party packages and releasing new versi...ons. These updates enhance security by remedying various CVEs, ensuring compliance with the National Vulnerability Database ratings.
Splunk OpenTelemetry Collector Distribution Roadmap Update: Breaking Changes
Splunk released OpenTelemetry Collector v0.154.0, removing legacy components to reduce software size and security risks. This update marks a shift from older technologies to native OpenTelemetry capa...bilities, enhancing observability. Splunk continues to invest in OpenTelemetry, focusing on modernizing its data collection tools and improving DNS monitoring.
Splunk has released emergency security updates for a critical vulnerability in Splunk Enterprise, tracked as CVE-2026-20253, with a CVSS score of 9.8. The flaw allows unauthenticated users to execute... arbitrary code, posing significant risks to enterprises using the platform for security monitoring. The vulnerability affects specific versions of Splunk Enterprise, but not Splunk Cloud.
A critical vulnerability (CVE-2026-20253) in Splunk Enterprise versions 10.0.x and 10.2.x allows unauthenticated file operations, potentially leading to remote code execution. Splunk advises immediat...e patching to versions 10.0.7 and 10.2.4 to mitigate risks. The flaw involves a PostgreSQL sidecar service endpoint lacking authentication controls.
Splunk has released emergency security updates for Splunk Enterprise to address a critical vulnerability, CVE-2026-20253, which allows unauthenticated remote code execution. The flaw affects versions... 10.0.0-10.0.6 and 10.2.0-10.2.3, with a CVSS score of 9.8. Organizations are urged to update to versions 10.0.7 and 10.2.4 immediately to mitigate risks.
From Static A&I to Continuous Entity Discovery Using Exposure Analytics in Splunk ES
Splunk has introduced Exposure Analytics in its Enterprise Security platform, enhancing asset and identity management through continuous entity discovery. This feature integrates real-time and schedu...led data sources, improving security operations by providing a comprehensive view of assets and users. It reduces manual updates and enriches security investigations with accurate context.
Multiple vulnerabilities have been identified in Splunk products, including Splunk Enterprise and Splunk Cloud Platform, which could lead to security restriction bypass, information disclosure, and c...ross-site scripting. A specific vulnerability, CVE-2026-20253, is being actively exploited. Splunk has issued advisories and fixes to address these issues.
Splunk disclosed critical vulnerabilities in its Enterprise, Cloud Platform, and Secure Gateway app, including CVE-2026-20253, which allows unauthenticated file operations. Immediate patching is advi...sed to prevent potential infrastructure compromise. Orca Security offers tools to identify and prioritize remediation for affected Splunk installations.
Splunk, Palo Alto Networks Patch Severe Vulnerabilities
Splunk and Palo Alto Networks released patches for critical vulnerabilities in their products. Splunk addressed a severe flaw in Splunk Enterprise, CVE-2026-20253, allowing unauthenticated file opera...tions. Additional fixes were made for high-severity issues in Splunk Enterprise and SOAR, enhancing security against remote code execution and data exfiltration.
Ready to Play? Step Into the New Splunk Observability Cloud Playground
Splunk has launched the Observability Cloud Playground, a pre-configured demo environment that allows users to explore observability features without setup or coding. It includes pre-built dashboards..., service maps, and guided workflows, enabling users to quickly understand monitoring and troubleshooting capabilities. The Playground is designed to reduce the time to value for new users, offering a secure, read-only environment for experimentation.
Splunk has released IT Service Intelligence (ITSI) 5.0, enhancing IT operations with new features like AI-powered service and KPI discovery, improved alert integrations, and a modernized user experie...nce. The update focuses on reducing alert noise and speeding troubleshooting with AI-driven event correlation and enriched data integration, aiming to connect service health with business impact.
Monitor LLM and Agent Performance With AI Agent Monitoring in Splunk Observability Cloud
Splunk has introduced AI Agent Monitoring within its Observability Cloud, enhancing its Application Performance Monitoring (APM) capabilities. This feature provides visibility into AI agent and model... performance, allowing teams to troubleshoot issues with trace-level insights. It integrates with Cisco AI Defense for risk mitigation and aligns with AGNTCY standards to ensure vendor-neutral telemetry capture for AI applications.
Deep Insights, No Barriers: Splunk Observability Cloud Free Edition
Splunk launched a free edition of its Observability Cloud, offering 15 hosts with full platform features, aimed at developers and startups. This edition provides enterprise-grade observability tools ...without procurement barriers, enhancing application performance monitoring and security threat detection.
Multiple vulnerabilities have been identified in Splunk products, including Splunk Enterprise, Splunk Cloud Platform, and Splunk AI Toolkit. These vulnerabilities could allow remote attackers to expl...oit systems, leading to information disclosure, security restriction bypass, and denial of service. Users are advised to apply the fixes provided by Splunk to mitigate these risks.
Splunk, a Cisco company, released a research report titled "The Hidden Costs of Downtime," highlighting that unplanned downtime costs Global 2000 companies $600 billion annually. The study, conducted... with Oxford Economics, emphasizes the severe financial impact of downtime, including $15,000 per minute in costs and a 3.4% average stock price drop. The report underscores the importance of resilience, end-to-end visibility, and AI in mitigating these issues.
Splunk, now a Cisco company, released a study titled "The Hidden Costs of Downtime," revealing that downtime costs for Global 2000 companies have surged to $600 billion annually. The study highlights... the severe financial impact of downtime, including a $15,000 per minute cost and a 3.4% average stock price drop. It emphasizes the importance of aligning technology with business outcomes to enhance resilience.
Announcing Splunk Cloud Platform 10.4 and Splunk Enterprise 10.4: Federated Search Is Here
Splunk has launched Splunk Cloud Platform 10.4 and Splunk Enterprise 10.4, introducing Federated Search, which allows data analysis across hybrid and multi-cloud environments without data movement. T...he update includes enhancements like Splunk AI Assistant 2.0, improved dashboards, and modern navigation, enhancing security, performance, and scalability for enterprise and cloud customers.
Splunk has released updates to address vulnerabilities in its Enterprise, Cloud Platform, and MCP Server. A critical flaw, CVE-2026-20204, in Splunk Enterprise and Cloud Platform could allow remote c...ode execution. Users should update to the latest versions to secure their systems. Additional fixes were applied to third-party packages and the MCP Server app.
Splunk disclosed a high-severity security flaw (CVE-2026-20204) in its Enterprise and Cloud Platform, risking remote code execution. Affected versions are below 10.2.1 for Enterprise and 10.3.2512.5 ...for Cloud. Splunk advises upgrading or disabling Splunk Web as a workaround. The flaw highlights risks in security platforms, emphasizing the need for prompt patching.
Expel launches managed SIEM service for Sentinel & Splunk
Expel has introduced a managed SIEM service for Microsoft Sentinel and Splunk Enterprise Security users. This service, available to Expel MDR customers, integrates Expel's detection engineers into ex...isting SIEM environments to enhance detection strategies and manage operational tasks. It aims to alleviate the burden on security teams by offering transparency and control over detection rules without requiring platform migration.
Splunk Enterprise Security Premier is Now Generally Available: Delivering the Industrys Best Analyst Experience
Splunk has announced the general availability of Splunk Enterprise Security (ES) Premier for cloud customers, with customer-managed environments following soon. This AI-powered security platform inte...grates SIEM, SOAR, and UEBA to enhance threat detection and response. It aims to transform security operations by unifying workflows and automating routine tasks, enabling analysts to focus on strategic defense.
A CIO's Guide to the Splunk AI Toolkit: Shifting IT from Reactive to Predictive
Splunk introduces its AI Toolkit, designed to transform IT operations from reactive to predictive. The toolkit empowers users with AI and machine learning capabilities to predict incidents, uncover h...idden issues, and automate responses. It supports both no-code and pro-code environments, enhancing productivity and security within the Splunk ecosystem. The AI Toolkit aims to deliver digital resilience by integrating AI directly with data, reducing latency and costs.
Splunk Report: Agentic AI Takes Center Stage in CISOs' Path to Digital ...
Splunk, a Cisco company, released its annual CISO Report highlighting the pivotal role of AI in enhancing cybersecurity. The report, surveying 650 global CISOs, emphasizes the growing importance of A...I governance and risk management. It reveals that 95% of CISOs view advanced threat actor capabilities as a major risk, while 92% note AI's role in improving threat detection and response.
Cisco's Splunk Cloud Platform: Accelerating Digital Resilience for the Agentic AI Era in ...
Splunk has launched its Cloud Platform on Google Cloud in Saudi Arabia, enhancing digital resilience and cybersecurity for local enterprises. This move aligns with Saudi Arabia's Vision 2030, offerin...g organizations a secure, scalable, and localized cloud environment. The platform integrates observability and security, enabling faster issue detection and operational excellence.
Cisco's Splunk Cloud awarded DESC Cybersecurity Certification in Dubai - Al Bawaba
Splunk Cloud Platform has received the DESC Cybersecurity Certification from the Dubai Electronic Security Center, meeting stringent cybersecurity and compliance standards. This certification enhance...s Splunk's credibility as a secure cloud service provider, supporting Dubai's digital transformation and enabling government and critical sectors to adopt its platform with confidence.
Cisco launches Splunk Observability Cloud on AWS in Singapore - FutureCIO
Cisco has launched the Splunk Observability Cloud on AWS in Singapore, enhancing IT operations with real-time visibility and data control. This deployment aids industries in meeting regulatory and da...ta retention needs while maintaining system performance and resilience. The solution offers unsampled insights across infrastructure and applications, supporting innovation and strategic business initiatives.
Splunk Conference Unveils AI-Driven Vision for SOC Security Operations, Enhancing Cybersecurity with AI
Splunk unveiled its AI-driven Security Operations Center (SOC) at its annual .Conf conference, introducing agent-driven tools to enhance cybersecurity operations. The new Enterprise Security Basic an...d Advanced Editions integrate features like Splunk SOAR and UEBA, aiming to simplify workflows and improve threat detection and response. This launch, following Splunk's merger with Cisco, marks a significant advancement in security technology, promising improved efficiency and proactive defense capabilities.
Gigamon unveils AI - powered Insights to boost cloud security & IT
Gigamon has launched Gigamon Insights, an AI-powered application integrated with platforms like AWS, Elastic, and Splunk. This tool enhances security and IT operations by providing network-derived te...lemetry insights, aiding in threat detection and compliance. The integration with Splunk allows users to leverage AI for improved security workflows, accelerating detection and response times.
Strategic Partnerships and Integrations of Splunk LLC
AWS
Your 90 Days Guide to Operationalizing Security in the Anthropic Mythos Era: Splunk and AWS’s Path to Resilience
Splunk and AWS have collaborated to develop an integrated solution that enhances security operations by combining AI automation with human expertise. This joint effort, known as the Agentic SOC model..., leverages AWS's cloud infrastructure and Splunk's platform to improve threat detection, investigation, and response times. The solution addresses challenges posed by AI-driven threats, offering a scalable and resilient security framework.
From Alert Fatigue to Operational Clarity: Turning Cisco Data Fabric Vision, powered by Splunk, into Agentic Operations Reality
Splunk and Cisco have collaborated to develop the Cisco Data Fabric, powered by the Splunk Platform, to enhance operational clarity and efficiency through agentic operations. This joint effort aims t...o transform enterprise operations by integrating AI to manage data across security, IT, observability, and network environments, enabling faster and more informed decision-making.
Cisco Partners with Qmulos and Splunk to Enhance Software and Security Capabilities
Cisco has integrated Qmulos compliance and analytics solutions into its SolutionsPlus Partner Program, enhancing their availability through Cisco channels with improved integration within the Splunk ...platform. This move strengthens Cisco's software and security offerings by automating compliance processes, benefiting both customers and partners. The integration is set to standardize Splunk-based compliance workflows among Cisco's clients.
Cisco Systems Accelerates AI Infrastructure Growth with Splunk Integration
Cisco Systems is integrating Splunk's software to enhance its AI infrastructure, providing a unified view of networking and security. This integration supports Cisco's shift towards AI-focused soluti...ons, aiming to capitalize on the growing demand for high-bandwidth AI applications.
Resecurity Integrates with Splunk to Enhance Threat Intelligence
Resecurity has launched a native integration with Splunk, available on the Splunkbase platform, to enhance cyber threat intelligence capabilities. This integration allows organizations to incorporate... advanced threat intelligence into their Splunk SIEM and SOC environments, improving threat detection and response processes. The integration supports standard protocols like TAXII and offers flexible configuration options for diverse organizational needs.
Resecurity Introduces Native Integration with Splunk
Resecurity has launched a native integration with Splunk, available via a dedicated app on Splunkbase. This integration allows organizations to incorporate Resecurity's cyber threat intelligence into... Splunk's SIEM, enhancing security event analysis through the ingestion of threat intelligence feeds. The app supports industry-standard protocols like TAXII, facilitating enriched data analysis and improved security operations.
Resecurity Introduces Native Integration with Splunk
Resecurity has launched a native integration with Splunk, available via a dedicated app on Splunkbase. This integration allows organizations to connect Resecurity's cyber threat intelligence with Spl...unk's ecosystem, enhancing security event analysis through the ingestion of threat intelligence feeds using the TAXII protocol. The app supports Splunk Enterprise environments, facilitating improved data analysis and threat visibility.
Splunk and AWS have integrated their security tools, enabling faster access to critical security insights. This collaboration allows AWS Security Hub findings to flow into Splunk in real-time, reduci...ng alert noise and enhancing threat detection. The integration aims to provide a unified security approach, empowering organizations to better protect their assets and drive innovation.
Splunk & Cisco Secure Firewall: Better Together at Cisco LiveAmsterdam 2026
At Cisco Live Amsterdam 2026, Cisco introduced new integrations with Splunk, including a Splunk integration wizard and Advanced Logging for Cisco Secure Firewall. These enhancements simplify syslog c...onfiguration and provide detailed logging capabilities, allowing for better monitoring and analysis of network traffic. The collaboration highlights the synergy between Cisco's firewall technology and Splunk's SIEM solutions.
TekStream, a certified Splunk partner, will present at Splunk Go Austin on March 11, discussing strategies to enhance SOC efficiency using Splunk's ecosystem. The session will focus on reducing execu...tive escalations by aligning alerts with business impact, emphasizing containment over detection, and translating Splunk data into resilience metrics. TekStream's expertise in Splunk solutions has earned them multiple partner awards and recognition.
Cisco looses Splunk to probe and tame its growing agentic menagerie - The Register
Cisco integrates Splunk's AI Agent Monitoring tool into its Observability Cloud, enhancing its AI Defense suite. This tool visualizes agent workflows and tracks performance, cost, and behavior of LLM... and agentic applications. Cisco plans further integration with its AI Canvas and Cloud Control, set to launch later in 2026.
Splunk's Strategic Integration Takes Center Stage - ad-hoc-news
Cisco is integrating Splunk into its new "Cisco 360 Partner Program," enhancing Splunk's channel strategy amidst growing demand for IT monitoring solutions.
Splunk and the Australian Signals Directorate have partnered to launch a CTIS cyber plug-in, integrating Splunk's Enterprise Security platform with ASD's Cyber Threat Intelligence Sharing system. Thi...s integration, mandatory for federal agencies by July 2025, enhances real-time cyber threat intelligence exchange, improving detection and response times. The plug-in is also available to private sector critical infrastructure operators.
Mergers, Acquisitions, and Business Moves by Splunk LLC
Splunk partners brace for Cisco transition - SC Media
Splunk's integration into Cisco's operations following its $28 billion acquisition is reshaping its channel strategy. Splunk's channel unit will merge with Cisco's global partner sales, and the Splun...k Partnerverse program will transition into Cisco's 360 Partner Program in 2026. Splunk will remain a distinct business unit within Cisco, focusing on deeper product integrations like Cisco Data Fabric and Splunk Cloud's integration with Cisco's AI Canvas.
Funding News and Financial Performance of Splunk LLC
Splunk Inc. Announces Fiscal Second Quarter 2014 Financial Results
Splunk Inc. reported its fiscal second quarter 2014 financial results, highlighting a 50% year-over-year revenue growth to $66.9 million. The company also announced the beta version of Hunk: Splunk A...nalytics for Hadoop and the general availability of the latest Splunk App for VMware. Splunk crossed the 6,000 customer mark, adding over 400 new customers, including major organizations like Bank of the West and Sony Corporation.
Splunk Cloud Platform has been awarded the DESC Cybersecurity Certification by the Dubai Electronic Security Center, marking a significant milestone for Splunk in the UAE. This certification ensures ...that Splunk meets the highest cybersecurity and compliance standards, facilitating adoption by government and critical sectors in Dubai. It enhances trust in Splunk's services, supporting secure digital transformation across public and private sectors.