Splunk Announces Intent to Acquire TruSTAR

Being an enterprise security professional has never been an easy job, but in many ways it’s harder than ever right now. SOCs are overwhelmed. Remote work environments continue to create and expose new threats. Security analysts struggle to glean actionable information from fragmented workflows and intelligence sources. And according to our upcoming Splunk State of Security Report, 78 percent of you expect another supply-chain attack of the same magnitude as SolarWinds — or worse.

No matter how difficult or tumultuous the threat environment, and no matter how often you encounter another unprecedented challenge, there is one key truth we’ve learned at Splunk from our experience providing security solutions to the world’s most successful organizations.

Security is a data problem.

Your network provides you with everything you need to keep it secure, in the form of data. The perennial challenge is how to take advantage of the priceless, real-time information available to you. As your networks grow to include on-prem, hybrid cloud and containerized nodes, the volume and complexity of the data grows as well.

That’s why today Splunk is announcing our intent to acquire TruSTAR, to extend our leadership in security analytics through cloud-native threat intelligence integration and automation.

With the acquisition of TruSTAR, Splunk will add key automation capabilities to strengthen our Security portfolio.

Patrick Coughlin and Paul Kurtz launched TruSTAR in 2016 as a cloud-native solution designed to reduce complexity and drive more efficient threat detection and response. They share our passion for the value of data and the power of turning data into doing. I’ve been very impressed with the growth not only of their solution but of their business.

As a cloud-delivered solution designed for the modern threat environment, TruSTAR is perfectly suited to enhance the level of security in the cloud that Splunk offers today. More than 50 companies rely on TruSTAR’s solutions, including Rackspace, BNP Paribas, Box and LogMeIn.

In my view, TruSTAR’s industry-leading intelligence platform shares three core principles that align perfectly with Splunk’s.

1. Organizations need a unified, data-centric view across their cloud environments, paired with the right analytics at the right time, for intelligent detection and response.

Like Splunk, TruSTAR’s platform is data-centric, with an emphasis on integration and automation. TruSTAR’s cloud-native Enclaves and no-code Intel Workflows seamlessly prioritize and integrate intelligence into SIEM and SOAR workflows to provide a single, consolidated view. TruSTAR’s intelligence platform will be integrated into Splunk’s security portfolio (Enterprise Security, Phantom, Security Suites), allowing Splunk customers to enrich their SOC workflows with normalized threat intelligence from third-party sources and from their own historical events and investigations. Ultimately this will reduce the time it takes for customers to detect and remediate issues before they impact the business.

2. The most effective way to accelerate efficiencies in the SOC is to prioritize data with a focus on automation, improving your MTTD and MTTR outcomes.

Applying the power of your own data to normalized and prioritized threat intelligence makes it possible to effectively automate the detection and remediation of threats through reduced false positives and streamlined playbooking, leading to a faster and more effective response. Automation is indispensable to security, and a driver of business transformation in today’s Cloud era. Plus, automation enables your overwhelmed security analysts to concentrate on higher priority challenges.

3. Managing and integrating internal and external sources of intelligence accelerates outcomes across the security operations lifecycle, delivering customers critical and timely value.

TruSTAR shares Splunk’s view of the value of an API-first approach. Their API allows customers to bring intelligence to all stages of the incident response process. TruSTAR’s relationships with industry-leading technology partners and ISAC and ISAO communities means customers have immediate access to the latest threat information and security research. Combined with their robust user community, no platform is better able to bring together all the elements required for a comprehensive, unified, actionable threat intelligence solution.

I’m very excited to see the powerful effects of bringing TruSTAR into the Splunk family. TruSTAR is a member of the Splunk ecosystem and we’ve been able to see the value operationalized intelligence brings to our many mutual customers. I’m convinced that by working even more closely, we’ll be able to significantly advance both the technology and practice of data-centric security automation.

For more information, please read our press release, and join us at RSA Conference 2021 on May 19 to listen to our CEO Doug Merritt’s keynote address.

----------------------------------------------------
Thanks!
Sendur Sellakumar

Related Articles

Security Predictions 2026: What Agentic AI Means for the People Running the SOC
Leadership
10 Minute Read

Security Predictions 2026: What Agentic AI Means for the People Running the SOC

Splunk's Hao Yang shares our security predictions for 2026 and how agentic AI is reshaping how we see the SOC.
The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility
Leadership
4 Minute Read

The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility

Systems show symptoms. Business context shows impact. Discover why the future of observability is understanding what matters most to your customers.
MachineGPT, Agentic AI, and the New Foundation for Digital Resilience
Leadership
4 Minute Read

MachineGPT, Agentic AI, and the New Foundation for Digital Resilience

MachineGPT is foundational to the rise of Agentic AI in the enterprise, which is poised to fundamentally reshape digital operations – and it's advancing faster than we expected.
MachineGPT: Speaking the Language of Machines to Shape the Future of AI
Leadership
4 Minute Read

MachineGPT: Speaking the Language of Machines to Shape the Future of AI

MachineGPT brings the power of generative AI to one of the most overlooked resources: machine data. Splunk SVP & GM Kamal Hathi explains why mastering data as the heartbeat of the digital world is a game changer.
Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25
Leadership
3 Minute Read

Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25

Splunk's Kamal Hathi recaps our innovation highlights from .conf25, marking a pivotal moment for Splunk and Cisco as we deliver significant new value to our customers that make the use of AI a practical reality in their organizations.
Machine Data: Fighting Fire With Fire for Digital Resilience
Leadership
2 Minute Read

Machine Data: Fighting Fire With Fire for Digital Resilience

Kamal Hathi shares how Cisco and Splunk are helping organizations manage the explosion of machine data and AI-driven complexity, delivering real-time digital resilience to counter threats at machine speed and scale.
.conf25: Reinventing Digital Resilience for the Agentic Era
Leadership
3 Minute Read

.conf25: Reinventing Digital Resilience for the Agentic Era

Kamal Hathi shares how Cisco and Splunk deliver the data foundation, agentic intelligence, and cross-domain insights needed to build a more secure, resilient, and always-on digital enterprise.
UK Needn’t Fear The Data Deluge
Leadership
4 Minute Read

UK Needn’t Fear The Data Deluge

UK businesses face a data explosion—fueling growth but also raising risks in security, compliance, and operations. With smart data management strategies, organisations can regain control, boost resilience, and turn data into a true competitive edge.
Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco
Leadership
7 Minute Read

Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco

Cisco and Splunk deliver Digital Resilience by Design with seamless troubleshooting across security, observability, and networking domains, powered by AI innovations to manage complexity and stay ahead of risk.