Splunk .conf26
With threats moving at machine speed and attack surfaces expanding across hybrid environments, modern security operations can no longer rely on "business as usual." At .conf26, we’ve structured our learning experiences around real-world outcomes to help you defend at machine speed, unifying your SOC and infrastructure, accelerating threat detection, and unlocking trusted, autonomous response.
Whether you’re exploring the shift toward an Agentic SOC, defending against emerging AI/ML threats, or building resilient detection-as-code pipelines, our hand-picked breakout sessions provide practical, actionable blueprints. From interactive workshops and technical deep dives to peer-led customer panels, explore the sessions below to map out your schedule and maximize your security potential in Denver.
Explore the sessions below and add your favorites to your schedule to make the most of your .conf26 experience!
[SEC1538] The Future is Here: What’s New and Next in Splunk Security
When: Tuesday, September 15 | 10:30 AM – 11:15 AM MDT
Format: Technical Session (Recorded on-site; available on-demand post-event via .conf Online)
Overview: In a landscape where threats move at machine speed, "business as usual" is no longer an option for the modern SOC. Security leaders are under immense pressure to consolidate tools, leverage AI responsibly, and demonstrate clear ROI. In this session, we pull back the curtain on the latest advancements within the Splunk Security portfolio. We will explore the shift toward the Agentic SOC—where AI doesn't just assist but actively orchestrates triage and investigation workflows.
[SEC1073] Supercharge Security Operations for the Agentic Era with Splunk Security
When: Tuesday, September 15 | 1:00 PM – 1:45 PM MDT
Format: Technical Session (Recorded on-site; available on-demand post-event via .conf Online)
Speakers: Brandon Parks (Director, Information Security) and Neal Iyer (Director, Product Management)
Overview: Discuss Splunk SOC's AI transformation journey as "Customer Zero" for Splunk's security products. Get a sneak peek at bleeding-edge areas of innovation that Splunk's product and SOC teams are piloting for the Agentic SOC.
[SEC1918] AI Innovations in Splunk Security Products
When: Tuesday, September 15 | 12:00 PM – 12:20 PM MDT
Format: Theater Session (Not recorded)
Overview: Learn about upcoming AI innovations across Threat Detection, Investigation, and Response (TDIR) workflows in Splunk Security Products, including Splunk Enterprise Security Essentials and Splunk Enterprise Security Premier.
[SEC1272] Closing the Visibility Gap: Lessons from Customers on Building Cyber Resilience
When: Wednesday, September 16 | 2:00 PM – 3:00 PM MDT
Format: Panel Discussion (New for .conf26; recorded on-site and published to .conf Online post-event)
Overview: Security incidents are inevitable, but operational failure isn’t. Effective response hinges on deep asset intelligence, accurate context to identify systems, owners, and priorities. Hear from Devon Energy on overcoming common cyber resilience barriers: fragmented inventories, coverage gaps, asset drift, and hybrid visibility issues with Splunk Exposure Analytics.
[SEC1732] Empowering SOCs with Actionable Threat Intelligence with Splunk Enterprise Security
When: Wednesday, September 16 | 3:30 PM – 3:50 PM MDT
Format: Theater Session (Not recorded)
Overview: Learn how Splunk’s Threat Intelligence capabilities and Cisco Talos are fully embedded into every stage of a TDIR workflow within ES so analysts can reduce alert fatigue, improve accuracy, and make faster, more confident decisions. Walk through how to tap into the knowledge of the Splunk Threat Research team and how analysts can integrate top-tier detections into their security posture—without needing to build them from scratch.
[SEC1712] Beyond the Alert: How Elite SOCs Operationalize the Full Splunk Premier Stack
When: Tuesday, September 15 | 2:30 PM – 3:30 PM MDT
Format: Panel Discussion (New for .conf26; recorded on-site and published to .conf Online post-event)
Overview: Ready to see what Splunk ES Premier can really do? Join our advanced customer panel as they deconstruct their most sophisticated SecOps workflows. From using the new agentic capabilities to automating forensic analysis to orchestrating autonomous response playbooks that neutralize lateral movement in seconds—this is a deep dive into the "Premier" experience. No entry-level overviews here; just raw, technical use cases from the world’s most resilient SOCs.
[SEC1784] From Phish to Compromise: Hands-On Phishing Investigation with Behavioral Context
When: Wednesday, September 16 | 9:00 AM – 10:00 AM MDT
Format: Interactive Workshop Session (Live recording published on-demand via .conf Online exclusively for session attendees)
Overview: Phishing investigations often stop at analyzing the email, missing what users do next. In this interactive workshop, attendees will investigate real-world phishing scenarios by combining Automated Threat Analysis with UEBA to correlate email artifacts with user behavior. Participants will build attack timelines, identify compromised users, and detect early signs of data exfiltration using proxy, identity, and endpoint telemetry.
[SEC1467] The Automation Games: An Interactive Workshop with Splunk® SOAR
When: Wednesday, September 16 | 9:00 AM – 11:00 AM MDT
Format: Interactive Workshop Session (Live recording published on-demand via .conf Online exclusively for session attendees)
Overview: Let's get ready to automate! The Automation Games provides a peek into how automation and orchestration in Splunk® SOAR help security teams eliminate repetitive tasks, accelerate incident response, and boost efficiency. In this interactive session, participants will compete with peers and use the AI Playbook Assistant to build and refine playbooks in real time.
[SEC1483] The Complete Detection Lifecycle Experience with Detection Studio
When: Wednesday, September 16 | 12:30 PM – 1:30 PM MDT
Format: Interactive Workshop Session (Live recording published on-demand via .conf Online exclusively for session attendees)
Overview: Brought to you by the experts behind SnapAttack—in this hands-on workshop, you'll learn how Detection Studio provides the complete detection lifecycle experience within Splunk Enterprise Security. You'll see how detection engineers can seamlessly plan, develop, test, deploy, and monitor detections to enable faster mean-time-to-detect and deploy detections with confidence.
[SEC1371] When the Agent Becomes the Insider: Preparing Security for the Agentic Era
When: Wednesday, September 16 | 10:30 AM – 10:50 AM MDT
Format: Theater Session (Not recorded)
Overview: AI agents are becoming autonomous actors on your network. This session explores how agents behave when simulating real workflows, how to collect and baseline their telemetry, and what distinguishes agent behavior from human interaction. We examine patterns that separate benign automation from misconfiguration and suspicious activity, leaving attendees with a practical framework for detecting and responding to agent-driven threats in the agentic era.
[SEC1049] Detecting AI/ML Threats in Splunk: A Practical MITRE ATLAS Implementation
When: Wednesday, September 16 | 2:30 PM – 2:50 PM MDT
Format: Theater Session (Not recorded)
Overview: MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) is the AI equivalent of ATT&CK. Most Splunk deployments have zero detection coverage for large language model (LLM) threats. This session covers 10 production SPL detection rules mapped to specific ATLAS techniques including prompt injection, jailbreak attempts, model reconnaissance, and training data poisoning. Participants will leave with deployable rules and the data requirements needed to run them.
[SEC1171] Vibe-Splunking: How PEAK Assistant and Splunk MCP Server Redefine Detection as Code in the Agentic SOC
When: Wednesday, September 16 | 4:00 PM – 5:00 PM MDT
Format: Interactive Workshop Session (Live recording published on-demand via .conf Online exclusively for session attendees)
Overview: In this session, we demonstrate how the Cisco PEAK Assistant framework combined with the Splunk MCP Server creates an automated pipeline for building, testing, and deploying detections at scale. See how PEAK Assistant acts as the "brain" of the detection lifecycle—using its agentic capabilities to reason about threat intelligence, map behaviors to MITRE ATT&CK, and generate Splunk SPL detections.
[SEC1276] Bridging the Air-Gap: Deterministic Threat Triage for OT/ICS using Splunk Telemetry
When: Wednesday, September 16 | 4:15 PM – 5:00 PM MDT
Format: Technical Session (Recorded on-site; published to .conf Online post-event)
Overview: Traditional SOCs miss physical OT/ICS constraints. This session integrates Sat-Ark, a deterministic defense architecture, into Splunk to stop SCADA sensor spoofing and kinetic state-desync. We will demonstrate ingesting raw PLC telemetry to build graph-based correlation rules. By cross-checking sensor channels, Splunk triggers automated safe-state holds before physical damage occurs. Includes a simulated demo mapping SWaT datasets to catch anomalies that threshold-based alerts miss.
Ready to sharpen your skills, test hands-on playbooks, and secure your environment against modern threats? Don't wait until you arrive in Denver! Secure your pass today, explore the catalog, and add these can't-miss security sessions to your official .conf26 agenda.
🛡️ Lock in your pass for Splunk .conf26 and build your schedule!
If you’re not subscribed, you’re probably missing something good. Fix that!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.