What exactly is the customer looking for Splunk to do? Which attack surface do they want to manage, Splunk's or some other one? Keep in mind that Splunk is a monitor, not a manager, but there may be a solution (perhaps using SOAR) depending what the customer is trying to do.