Splunk Enterprise Security 8.0: Customer Feedback

A few weeks ago, we announced the general availability of Splunk Enterprise Security 8.0 — rolling out right now to customers in Splunk Cloud! This release is a significant leap forward for security operations, delivering exciting new unified investigation and case management workflows that help analysts quickly triage and investigate security alerts. Additionally, with the direct integration of Splunk SOAR and Mission Control, security teams can do everything from detection, triage, investigation, and response in one single unified modern interface.

That’s not all. The team continues to push innovation in new areas like detection engineering and alert aggregation to help our customers drive positive security outcomes and keep their organizations secure. Splunk Enterprise Security now includes a native detection versioning feature that helps content engineers manage the hundreds of security detections in the SIEM. On the alert aggregation front, a new Finding1 Groups feature helps administrators build automatically grouped alerts that analysts can quickly consume and act on - reducing manual steps in the triage process and speeding up response times to potential security incidents.

With so much in this release, it is important to continue our tradition of customer feedback to work hand in hand with existing customers and refine these workflows and gather their feedback via our Voice of the Customer programs. We worked with a couple dozen customers in the Splunk Enterprise Security 8.0 private preview program to gather their feedback as we refine these new capabilities. One of our private preview participants, Matt Snyder, shared his perspective on Splunk Enterprise Security 8.0 in a blog post, "Redefining SIEM: Why Splunk® ES 8.0 Stands Out" that I think everyone should take a look at. As a long time Splunk Enterprise Security user, Matt provides a deep dive into many of the improvements and changes in this release, along with his impressions, and I think he nailed it when he said Splunk Enterprise Security 8.0 is the biggest release yet.

We want to send a big thank you to Matt, and all of the other customers who participated in the Splunk Enterprise Security 8.0 private preview program. We continue to lean on our Voice of the Customer programs like Previews and Splunk Ideas to drive Splunk Enterprise Security development, and together we will partner to build the SOC of the Future.

1 *In preview with Splunk Enterprise Security 8.0

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.