<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RSAC 2026: The Shift from AI Hype to Platform Reality in the SOC in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/RSAC-2026-The-Shift-from-AI-Hype-to-Platform-Reality-in-the-SOC/m-p/759808#M4199</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/316451"&gt;@KCW&lt;/a&gt;&amp;nbsp;Appreciate the write up. For us, what is providing real value with AI in Splunk is w&lt;SPAN&gt;riting SPL using natural language which our team members were struggling especially with complex multi join SPL queries. This feature is adding a lot of value to customers.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 31 Mar 2026 03:12:35 GMT</pubDate>
    <dc:creator>kknairr</dc:creator>
    <dc:date>2026-03-31T03:12:35Z</dc:date>
    <item>
      <title>RSAC 2026: The Shift from AI Hype to Platform Reality in the SOC</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/RSAC-2026-The-Shift-from-AI-Hype-to-Platform-Reality-in-the-SOC/m-p/759805#M4198</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;I attended RSAC this year and one thing was clear: AI is no longer the differentiator. Everyone has it. Everyone is talking about it.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;The real question organizations are now asking is: &lt;SPAN&gt;how do we operationalize AI, especially agentic AI, in a way that actually works inside the SOC?&amp;nbsp;&lt;/SPAN&gt;And the answer that kept surfacing across conversations, sessions, and customer meetings was this:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;The future of the SOC is not more tools…it’s a platform strategy.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;From AI Experiments to SOC Execution&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Agentic AI introduces a new model for security operations, one where systems don’t just detect, but investigate, recommend, and even act. But that only works if AI has access to the &lt;SPAN&gt;right data, the right context, and the ability to take action across environments.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;That’s where many organizations are hitting friction today.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Data is still fragmented.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Workflows are still siloed.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Teams are still operating across disconnected tools.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;You can’t scale AI in that environment.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;To truly unlock agentic AI, organizations are realizing they need a &lt;SPAN&gt;unified data and operations layer&lt;/SPAN&gt;—a platform that brings everything together.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif" size="5"&gt;Why Platform Strategy Is Becoming the SOC Strategy&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;A platform approach does three critical things:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Unifies data across security, IT, and engineering teams&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Provides shared context for faster, more accurate decisions&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Enables coordinated action, not just isolated alerts&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;This is exactly the foundation needed to move from reactive SOCs to resilient, AI-powered operations.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;And it’s not a future vision, it’s already happening.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Splunk has long been focused on bringing SecOps, ITOps, and engineering together through a unified platform to drive digital resilience.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;A href="https://www.splunk.com/en_us/products/splunk-cloud-platform.html" target="_self"&gt;Splunk Platform: Built for the Agentic Era&lt;/A&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;What stood out at RSAC is how aligned this shift is with where Splunk is already delivering value today.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;The Splunk platform provides:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;End-to-end visibility across hybrid and multi-cloud environments&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;A shared data layer that powers both security and observability use cases&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;AI-driven analytics to accelerate detection, investigation, and response&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;In other words, the exact ingredients required to support agentic workflows at scale.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;But what’s becoming even more critical, especially as data volumes explode, is &lt;SPAN&gt;how&lt;/SPAN&gt; organizations access and manage that data.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Federated Search: Powering AI Without the Cost Tradeoffs&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;This is where &lt;A href="https://www.splunk.com/en_us/blog/learn/federated-search.html" target="_self"&gt;Federated Search&lt;/A&gt; becomes a game changer.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Instead of forcing organizations to ingest everything into a single system, federated search allows teams to:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Access and investigate data wherever it lives&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Correlate across environments without duplicating data&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Optimize cost while still enabling deep investigations&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;This flexibility is key in an AI-driven world.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Because agentic AI doesn’t just need &lt;SPAN&gt;more data&lt;/SPAN&gt;, it needs &lt;SPAN&gt;access to the right data, at the right time, without unnecessary cost or complexity.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Federated search enables that balance:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Ingest for speed where needed&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Federate for scale and cost efficiency where it makes sense&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Final Thought: The SOC Is Becoming a System, Not a Stack&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;RSAC made one thing clear: the conversation has shifted.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;We’re moving from:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Tools → Platforms&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Alerts → Actions&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;AI experiments → AI-driven operations&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Organizations that embrace a platform strategy will be the ones that successfully operationalize agentic AI.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;And with a unified platform and federated data access, they won’t just keep up they’ll lead.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 01:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/RSAC-2026-The-Shift-from-AI-Hype-to-Platform-Reality-in-the-SOC/m-p/759805#M4198</guid>
      <dc:creator>KCW</dc:creator>
      <dc:date>2026-03-31T01:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: RSAC 2026: The Shift from AI Hype to Platform Reality in the SOC</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/RSAC-2026-The-Shift-from-AI-Hype-to-Platform-Reality-in-the-SOC/m-p/759808#M4199</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/316451"&gt;@KCW&lt;/a&gt;&amp;nbsp;Appreciate the write up. For us, what is providing real value with AI in Splunk is w&lt;SPAN&gt;riting SPL using natural language which our team members were struggling especially with complex multi join SPL queries. This feature is adding a lot of value to customers.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 03:12:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/RSAC-2026-The-Shift-from-AI-Hype-to-Platform-Reality-in-the-SOC/m-p/759808#M4199</guid>
      <dc:creator>kknairr</dc:creator>
      <dc:date>2026-03-31T03:12:35Z</dc:date>
    </item>
  </channel>
</rss>

