Better Together with Splunk and Recorded Future

We recently announced a partnership with Recorded Future, and I want to make sure you know why this collaboration is so exciting.

Sometimes we think we know what we’re getting when we hear a term like “threat intelligence” and assume we know all the things it can do for us. I mean, that’s just a list of IPs and domains to match on my network data, right?

Wrong.

If you’re already utilizing the Recorded Future App for Splunk, you will have seen the incredible progression this app has made over the past year. When I first started working with their team to seamlessly integrate Risk-Based Alerting (RBA) into the app, I was already blown away by the amount of functionality and how intuitively it was designed. Seeing every IOC with individual rules which explain why an IP, domain, URL, vulnerability, or hash generated that overall score warmed my heart. It’s that kind of RBA-esque aggregation and cohesive context that analysts desperately need to make accurate and efficient decisions.

If you don’t know me, I’m the gal who won’t keep quiet about the gospel of Risk-Based Alerting, and this is going to set the bar for Splunk apps integrating RBA going forward. The power of having this curated, context-rich threat intelligence in conjunction with RBA is an exciting combination.

Some other recently developed features:

Recorded Future Enrichment / Threat Hunt Adaptive Response Actions

Enrich fields within your already existing notables, or fire off one-time historical searches to automatically integrate that context into your alerts.

Recorded Future’s SIGMA + YARA Ruleset

If you’ve got the right data, just point the app at your relevant Splunk data and you’re set, no custom SPL required for over 100 additional detections.

Recorded Future Playbook Alerts

Continuous monitoring of IOCs – including domain registration information, logo detection, and typosquatting – will automatically update your alerts with relevant information.

And in case you’re not familiar with all of its ongoing features, you’ve got a suite of built-in dashboards for detections of Recorded Future threat intelligence indicators in your environment or exploring the details and interconnections of individual IOCs.

Please join me and Recorded Future CISO Jason Steer for a webinar on October 24th or get in touch with your Splunk sales representative to see a demo and check out how Recorded Future Cloud Intelligence can level up your security operations today.

Related Articles

Unlocking New Possibilities: Splunk and AWS Better Together
Partners
5 Minute Read

Unlocking New Possibilities: Splunk and AWS Better Together

Discover how Splunk and AWS are revolutionizing security and AI/ML for EMEA organizations. Learn about federated search for S3, SageMaker integration, and real-world analytics innovations from the recent Splunk Partner Team event in Amsterdam.
Executive Q&A: Accelerating AI Success with Splunk and AWS
Partners
4 Minute Read

Executive Q&A: Accelerating AI Success with Splunk and AWS

Two leaders discuss shaping the future of AI: Hao Yang, VP & Head of AI at Splunk, and Bill Fine, Product Leader – Agentic AI at AWS.
Accelerate Operations with AI: New Splunk and AWS Integrations
Partners
5 Minute Read

Accelerate Operations with AI: New Splunk and AWS Integrations

Two new integrations with AWS have created seamless workflows that activate your Splunk data where it lives, removing friction and accelerating time-to-value.
Introducing Splunk Victoria Experience on Google Cloud: Faster, Clearer, More Resilient
Partners
3 Minute Read

Introducing Splunk Victoria Experience on Google Cloud: Faster, Clearer, More Resilient

Splunk VE is now available on Google Cloud, giving organizations and admins a more transparent, responsive, and flexible Splunk Cloud Platform experience.
Splunk Cloud Platform: Accelerating Digital Resilience for the Agentic AI Era in Kingdom of Saudi Arabia with Google Cloud
Partners
2 Minute Read

Splunk Cloud Platform: Accelerating Digital Resilience for the Agentic AI Era in Kingdom of Saudi Arabia with Google Cloud

We're thrilled to announce the availability of Splunk Cloud Platform on Google Cloud in the Kingdom of Saudi Arabia.
How Splunk and Dataminr Work Together to Help Accelerate Resilience
Partners
2 Minute Read

How Splunk and Dataminr Work Together to Help Accelerate Resilience

Splunk and Dataminr deliver real-time intelligence and automated response to help organizations anticipate threats, reduce noise, and strengthen cyber resilience.
Splunk Named 2025 Americas Partner of the Year Finalist by Microsoft
Partners
2 Minute Read

Splunk Named 2025 Americas Partner of the Year Finalist by Microsoft

Splunk has been named a 2025 Microsoft Americas Partner of the Year Finalist in the Software Development Company (SDC) award category.
Managed Enterprise Platform: Delivering Mission-Critical Observability with Splunk
Partners
3 Minute Read

Managed Enterprise Platform: Delivering Mission-Critical Observability with Splunk

Learn how Accenture Federal Services partnered with Splunk to deliver a comprehensive observability solution for one of America's largest federal financial agencies.
The Partner Advantage: Splunk .conf25 Unveils the Future of AI-Native Digital Resilience
Partners
5 Minute Read

The Partner Advantage: Splunk .conf25 Unveils the Future of AI-Native Digital Resilience

Splunk .conf25 delivered a clear message to the partner ecosystem: we're entering a new era of AI-native digital resilience, and partners are at the center of this transformation.