[Register Here] This thread is for the Community Office Hours session on Security: Splunk SOAR on Wednesday, Dec 10, 2025 at 11 am PT / 2 pm ET.
Ask the experts at Community Office Hours! An ongoing series where technical Splunk experts answer questions and provide how-to guidance on various Splunk product and use case topics.
What can I ask in this AMA?
- What’s new in the latest Splunk SOAR? Should I upgrade to this version, and what’s the easiest way to make the upgrade happen?
- How does the Splunk Attack Analyzer integration work? And how can playbooks be implemented to automate response processes for the malware and phishing attack?
- What are the practical ways to modernize legacy SOC workflows with Splunk Enterprise Security and build the TDIR workflow.
- How to use Wayfinder?
- How to measure the value of my SOAR investment? Real-world examples of how SOAR enhancements improved efficiency, security, and ROI?
- Anything else you’d like to learn!
Please submit your questions at registration. You can also head to the #office-hours user Slack channel to ask questions (sign in with SSO here).
Pre-submitted questions will be prioritized. After that, we will open the floor up to live Q&A with meeting participants.
Look forward to connecting!