Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced capabilities for security, monitoring, and troubleshooting. In this release, we’re excited to introduce several new features that streamline workflows, enhance security, and offer deeper insights across your infrastructure and applications. Below, we break down each highlight with its core benefits.
What's New
Secure Application on Splunk Observability Cloud
The Secure Application feature helps engineering teams transition from reactive vulnerability management to proactive defense, all without the burden of toggling between multiple tools or deploying additional agents. By seamlessly unifying security and observability within Splunk Observability Cloud, this feature detects runtime vulnerabilities in real time using existing agents and correlates security risks with application context—such as services, environments, and libraries. Teams gain actionable insights to accelerate secure code delivery, continuously scan code, and prevent exploits—moving from constant firefighting to continuous protection.
Read more about Secure Application for Splunk Observability Cloud in this blog.
Connect User and Network Insights: Real User Monitoring Integration with ThousandEyes
With the integration of Splunk’s Real User Monitoring (RUM) and ThousandEyes, organizations get unified visibility into global user experience and network performance. This solution combines real-user data from Splunk with network insights from ThousandEyes, enabling engineering teams to quickly determine if issues originate from the application or the network. The result is faster troubleshooting, reduced mean time to resolution, and an improved user experience. This integration is GA and available at no extra cost for joint customers. For more information check out our docs here.
RUM URL Grouping List View
This new view aggregates all URL Groups—including those for pages, route changes, and network requests—across both BRUM and MRUM types. Users can easily drill down from any problematic URL to the tag spotlight for deeper insights on metric trends or specific sessions. No manual actions are required, as customers are automatically enabled, providing instant visibility into all generated URL Groups and facilitating more effective troubleshooting. For more information check out our docs here.
RUM Session Details UX Enhancements
Based on customer feedback, the Session Troubleshooting Experience has been overhauled for greater usability. The new design of the Session Details page seamlessly integrates Session Replay with troubleshooting data, offering bi-directional navigation between replays and metrics. Users can link each page in a session replay to the corresponding troubleshooting data, quickly investigate issues, and customize or pin key attributes for rapid access. The streamlined interface reduces clutter and enhances readability, providing a faster, more intuitive troubleshooting process with prioritized insights. For more information check our or docs here.
Token-Based License Allocation & Visibility
Admins can now centrally assign and manage RUM session licenses across multiple teams, apps, or business units with token pools. Each team is allocated a specific token limit, ensuring monthly usage stays within bounds and overages require admin approval. Real-time visibility into token consumption allows for agile allocation adjustments and automatic license compliance, all within the Token Management section of Splunk RUM. This promotes transparency, accountability, and flexible usage planning. For more information check out our docs here.
Kubernetes Monitoring 2.0
Kubernetes Monitoring 2.0 delivers a more intuitive and comprehensive monitoring experience, tailored for the challenges of dynamic Kubernetes environments. Enhancements include customizable tables, enriched filters, in-context navigation, and real-time problem isolation, empowering teams to correlate metrics, logs, events, and configurations for faster root cause analysis. New support for YAML manifest integration and Horizontal Pod Autoscalers further optimizes monitoring and scaling, helping teams prevent configuration drift and operate more confidently.
For more information check out our docs here.
Archiving and Restoring Histogram Metrics
Customers can now archive and restore histogram metrics in addition to standard metrics, optimizing observability costs. Archived metrics count as one-tenth of a real-time metric toward license limits. This is accessible via Metric Pipeline Management, allowing users to flexibly manage storage and retrieval of metrics as needed for improved cost efficiency and data management.
For more information check out our docs here.
API Admin Token
Admins can now create access tokens with admin roles directly via the API, enabling automated management of administrator permissions and license extraction. This streamlines automation and integration workflows for administrative tasks, reducing dependency on manual UI operations. For more information check out our docs here.
Encrypt SAML SSO Assertions for Observability Cloud
This feature encrypts SAML SSO assertions for enhanced security of user authentication data during transmission between identity providers (like OKTA) and Splunk. Administrators can enable this during OKTA integration setup, ensuring all users benefit from stronger data protection and compliance with security best practices—critical for federal and regulated environments. For more information check out our docs here.
Persistent & Context-Aware Logs Experience in Service-Centric View
A new persistent, context-aware logs experience in Service-Centric Views ensures that log connections are always aligned with selected environments, eliminating unreliable legacy configurations. This unified Entity–Index Mapping system enhances troubleshooting predictability and reliability, making it easier for teams to find relevant logs and speed up incident resolution. For more information check out our docs here.
Optimizing Log Searches in OOTB Dashboards
The Logs Component in out-of-the-box dashboards now uses existing Entity-to-Index Mappings for log searches, ensuring faster, more efficient, and contextually relevant insights. This update reduces unnecessary resource consumption, lowers Splunk Virtual Core (SVC) costs, and improves the user experience without requiring additional setup.
For more information check out our docs here.
Auto Entity–Index Mapping Generation at User Context
Entity–Index mappings are now automatically generated in the background when users access key log experiences, eliminating the need for manual admin setup. This ensures up-to-date, accurate log correlation across environments, supporting seamless and automated troubleshooting while retaining manual override controls. For more information check out our docs here.
Database Monitoring PostgreSQL
Native PostgreSQL monitoring allows teams to track and analyze key database metrics, visualize performance data, and proactively optimize queries. Features include slow query identification, execution plan analysis, correlation with application traces, and AI-driven query recommendations. Teams can optimize, secure, and scale PostgreSQL environments directly within the platform—without switching tools. For more information check out our docs here.
Database Monitoring UI Improvements
The refreshed database monitoring UI offers clearer visualization of health and performance metrics, with actionable insights surfaced contextually. This streamlines troubleshooting, allowing users to rapidly detect and resolve anomalies and maintain optimal database performance with less effort. For more information check out our docs here.
Comprehensive Service Monitoring: Multi-dimensional MMSs
Splunk APM now supports Monitoring Metric Sets (MMS) with up to five custom dimensions, allowing for granular filtering and grouping. Users can analyze by service version, HTTP status, feature flag, region, or environment, supporting more complex use cases within the UI. This enhancement delivers deeper insights and accelerates issue detection and resolution across diverse services and environments.For more information check out our docs here.
What’s in Preview
Mobile Real User Monitoring Hybrid Framework Support
Developers can now leverage Splunk Observability for mobile apps built with React Native and Flutter, with the same out-of-the-box metrics provided for native iOS and Android apps, and see all of their mobile observability data in a unified view. Sign up on this page.
Splunk Observability Network Monitoring with Isovalent
Network Explorer in Splunk Observability can now help customers wanting deeper visibility into networks using eBPF. Sign up on this page.
Observability AI Admin Assistant - Custom Role Creation and Management via MCP Sign Up
Splunk Observability Cloud admins can now create Custom Roles via an MCP to control granular read and write capabilities for end users to ensure appropriate access across the product, like having a user be able to create a dashboard but not an alert. Please sign up to be considered for the Alpha. Sign up on this page.
Splunk Observability Cloud self-service experience to access audit logs
Splunk Cloud observability introduces self-service APIs to access audit logs enabling them for security, compliance use-cases by tracking user actions and system changes. Sign up on this page.
ITSI Episode Summarization
Episode summarization provides enterprise support teams accurate, concise, and contextually rich episode summarization and basic root cause analysis by leveraging LLMs, cutting down the number of clicks from 8-10 down to 1 to get most relevant context of an episode including actionable insights. Sign up on this page.
Business Insights in Observability Cloud Alpha Program
Business Journeys, the key feature of Business Insights in Splunk Observability Cloud, empowers business owners and product managers to visualize, analyze, and optimize end-to-end business processes. Leveraging APM and RUM data, it simplifies troubleshooting by correlating technical performance with business impact. Features include up to 50 milestones, auto-discovery, and multi-application connection via transition keys, enabling cloud-based business process optimization. Sign up on this page.
Digital Experience Analytics in Observability Cloud Alpha Program
The preview program for O11y Digital Experience Analytics (DEA) offers selected customers an exclusive opportunity to explore and test this brand-new offering alongside RUM before its general release.
Sign up on this page.
Thanks for reading to the end! Splunk Observability Cloud’s latest features deliver on the promise of unified security, smarter monitoring, and more efficient troubleshooting. Whether you’re optimizing user journeys, scaling cloud-native environments, or securing your applications, these enhancements empower your teams with the context and agility needed to stay ahead.
... View more