Purpose-Built AI Agents for the Agentic SOC
Splunk Enterprise Security 8.6 expands AI in Security with purpose-built AI capabilities built into the workflows analysts already use across detection, triage, investigation, automation, malware analysis, and response. These capabilities help teams summarize findings, prioritize and explain alerts, create and tune detections, build response workflows, analyze malware behavior, and apply standard operating procedures directly within Enterprise Security.
The focus is practical: reduce the manual work that slows analysts down and helps teams move faster from alert to action. Analysts stay in control of key decisions, while AI helps gather context, recommend next steps, and make routine tasks more consistent. For SOC teams, this means more capacity across day-to-day operations without adding more disconnected tools or losing governance, accountability, and confidence in the response process. And for the organization this means proactively reducing risk exposure.
Translate Multilingual Phishing Threats Directly in ES
Automated Threat Analysis (available in ES Premier 8.5+) now includes built-in translation, enabling security analysts to quickly understand phishing emails and documents written in virtually any language. This helps global SOCs investigate multilingual phishing campaigns without relying on external translation tools or language expertise. When an analyst receives a suspected document or email in a language their analysts aren’t familiar with, they can:
See the original content extracted by Automated Threat Analysis
Click “View translation” to see a translated version of the content
By eliminating the language barriers directly within ES, analysts gain immediate context to assess suspicious content, reducing investigation time and accelerating phishing response all without leaving their existing workflow or switching to a separate translation tool.
Accelerate Investigations with Entity Intelligence and Attribution
ES 8.6 expands Exposure Analytics from continuous entity discovery into deeper, actionable intelligence. Building on the foundation introduced in ES 8.5, analysts can now move faster from visibility to investigation with new Entity Discovery Insights dashboards that highlight asset trends, operating systems, cloud environments, default accounts, and non-human identities. From these insights, teams can drill directly into Entity Discovery Inventory and pivot into Entity Analysis for focused investigation.
Exposure Analytics in ES 8.6 also adds improved context for investigations and prioritization. New subnet discovery data helps analysts understand unfamiliar IPs or subnets by showing related assets within the same network boundary, while Historical Entity Intelligence tracks how assets and users change over time to support forensics and timeline reconstruction. With customizable Inventory Enrichment, teams can align discovered entities to business-specific context such as locations, legacy operating systems, and default account standards. Together, these capabilities help SOC teams investigate threats more efficiently, reduce analyst efforts, and make faster, more confident decisions all from within ES. These capabilities are available across all ES editions.
Unified View into Threat Intelligence Data
We’ve introduced a Threat Intelligence dashboard that provides a unified view of the threat intelligence ingested in your environment across TIM Cloud and ES Native data sources that's used for threat matching. Analysts can quickly understand the quality and coverage of their threat intelligence by viewing ingested threat intelligence sources including quantity, associated threat actors, MITRE TTPs, and malware indicators within your collections.
As a reminder, for customer-managed environments, access to Threat Intelligence Management is available now via Cloud Connect.
We’ve also enhanced Threat Intelligence Management documentation, making it easier to integrate and operationalize Cisco Talos intelligence to enrich investigations, improve threat attribution, and accelerate threat hunting.
Elevating Federal Security with FedRAMP Moderate Authorization
And finally, we are excited to announce a significant milestone in our commitment to the public sector. ES Premier has achieved FedRAMP Moderate authorization (as of June 25, 2026). The complexity of modern cyber threats requires a unified approach. ES Premier provides the visibility and intelligence necessary to unify data across hybrid and multi-cloud environments. With this new authorization, agencies can now harness the full power of our premier security analytics platform to defend their perimeters, detect lateral movement, and automate incident responses all within a secure, FedRAMP-compliant framework.
Ready to experience ES 8.6? Upgrade today!
... View more