Announcing Splunk Cloud Platform 10.6 and Splunk Enterprise 10.6
Platform Michelle Corpora , Aqib KaziKey takeaways
- Cut data movement while expanding visibility.
- Investigate and resolve issues faster with AI assistance.
- Reduce administrative effort and upgrade with greater confidence.
Today we are excited to announce Splunk Cloud Platform 10.6 and Splunk Enterprise 10.6. These releases help security, IT, engineering, data, and observability teams turn more distributed operational data into useful context and action without adding manual work. We’re introducing broader ways to analyze data where it lives, AI-assisted workflows that help more people participate in investigations, and stronger operational controls for the teams that run the Splunk platform every day.
What’s New in Both Splunk Cloud Platform 10.6 and Splunk Enterprise 10.6
Automate Repeatable Data Management Workflows With Data Management Service APIs
Data Management APIs give customers and partners a supported way to automate common Edge Processor and Ingest Processor workflows across cloud and on-premises deployment paths. Repeatable automation can shorten onboarding, reduce configuration drift, and make data management easier to integrate into broader platform engineering practices. Customers and partners can spend less time reproducing administrative steps and more time improving how data is filtered, routed, and prepared for use.
What’s New in Splunk Cloud Platform 10.6
Search More Data in Place With Expanded Federated Search
Federated Search continues to extend the Splunk search experience to data that customers already keep in other environments. With version 10.6, planned support for AWS CloudWatch Lake and Cisco Security Analytics Lake (SAL) helps AWS-and Cisco-centered teams investigate remote telemetry through familiar Splunk workflows without moving every dataset into the Splunk platform first.
Recent additions that Splunk delivered with Splunk Cloud Platform version 10.5 include Federated Search for Microsoft Azure Data Lake Storage, Snowflake, and Dynamic Data Self-Storage (DDSS). Together, these options give teams more flexibility to correlate operational, business, cloud, and historical data while preserving existing storage and governance choices.
Security teams can investigate older DDSS data without a complex restore-and-reindex process, analysts can combine Snowflake business context with operational telemetry, and cloud teams can analyze supported Azure and AWS data through the Splunk platform. The result is broader visibility with less unnecessary data movement and fewer separate analytics workflows to maintain.
Customers using the legacy Federated Search for Amazon Simple Storage Service (S3) experience should also plan to migrate to the supported Federated Search version 2.x architecture. Moving to the modern path gives customers a clearer long-term S3 federation experience across setup, search, governance, and support.
Retain More Data Economically - And Find It When It Matters
Splunk Machine Data Lake and Catalog, introduced with Splunk Cloud Platform 10.5, strengthen the foundation for customers managing rapidly growing machine data. Machine Data Lake provides an economical, Splunk-managed place to retain full-fidelity machine data, while Catalog helps users find, understand, and activate datasets across Machine Data Lake, Splunk indexes, and supported federated sources.
Teams spend less time hunting for data and face fewer high-cost retention tradeoffs. They can retain a more complete operational record, discover the right datasets faster, and prepare trusted context for security, observability, analytics, and AI workflows without keeping every byte constantly indexed.
Bring AI into the flow of an investigation
The common theme across version 10.6 is that AI shows up inside the tools your teams already use. Not a separate app to go find, not a side panel bolted onto the console, but a capability sitting in the search bar, in your existing agent tooling, and in the shared workspace where investigations play out.
Splunk AI Assistant, installed by default
In eligible Splunk Cloud Platform version 10.6 environments, Splunk AI Assistant is more deeply integrated with Search & Reporting and is now installed by default. Agent Mode is what makes the difference, letting Splunk AI Assistant do so much more than generate and explain SPL and SPL2. Ask a question in plain English, and the assistant reasons through the request, breaks it into the tool and skill calls it needs, and runs the search when you approve it. This holds true for your data wherever it lives, including supported federated and Machine Data Lake datasets. You don't have to write SPL to get an answer, and if you already know SPL, you spend less time on syntax.
Splunk MCP server, ready out of the box
Splunk MCP server becomes a default app alongside Splunk AI Assistant. It gives AI assistants and agents a standardized, governed way to reach data in the Splunk platform, and it puts administrators in control of what those agents can access. You can turn tools on or off at the server level, so the setting applies across the deployment and access is granted through a role capability rather than left open. Becoming a default app removes the download, install, and configuration steps that used to sit between a team and their first approved agentic workflow.
Cisco AI Canvas, now generally available
Cisco AI Canvas moves from controlled availability in version 10.5 to general availability in version 10.6, for US customers that use Cisco Cloud Control. It gives eligible teams a persistent, shared workspace that brings together Splunk platform data, supported federated sources, IT Service Intelligence context, and Splunk Observability Cloud signals. Bi-directional cross-launching lets people move between the Splunk platform and AI Canvas without rebuilding the investigation each time they switch.
Together, these change what a typical investigation looks like. New users get to a useful search faster. Experienced practitioners spend less time on repetitive query work. Teams hold onto context across handoffs instead of restarting from the ticket. Human review and tool approvals stay in the loop throughout, so the increased speed doesn't come at the cost of control.
Investigate Logs Alongside Metrics and Traces With Log Essentials
Log Essentials in Splunk Observability Cloud provides a low-cost log storage option built specifically for observability, bringing logs into the observability experience as a native signal alongside metrics and traces. Teams can affordably retain the log data they need to search, chart, alert on, and investigate problems, without leaving the workflows that they already use to understand service health.
By bringing logs, metrics, and traces together, engineers spend less time switching tools and reconstructing context when a service degrades. Unified identity, centralized role-based access control, and data-level access controls simplify administration, while streamlined onboarding helps teams quickly gain useful log context without requiring deep Splunk expertise. Customers can start with a cost-effective, observability-native logs experience and expand into broader Splunk Cloud Platform use cases as their needs grow—without rebuilding their identity and access foundation.
Move More Easily Between Splunk and Cisco Experiences
For customers with access to Cisco Cloud Control, the version 10.6 unified navigation experience makes it easier to move between the Splunk platform and other Cisco product experiences. With Cisco Cloud Control, users spend less time hunting for the right entry point and lose less context when workflows cross product boundaries. It reduces time spent hunting for the right entry point and helping users maintain context across product boundaries.
What’s New in Splunk Enterprise Version 10.6
Track Supported Configuration Changes With Greater Clarity
Splunk Enterprise version 10.6 extends cloud-aligned configuration change tracking to Splunk-supported on-premises UI and API workflows. Administrators can more quickly answer who changed what, when the change occurred, which supported path was used, what object was affected, and whether the change succeeded.
Better change evidence can shorten troubleshooting, strengthen change-management and audit workflows, and reduce reliance on manual file inspection or custom scripts. When unexpected system behavior appears, administrators have a clearer place to begin correlating it with recent supported configuration changes.
Plan Long-Term Upgrades on an LTS Foundation
Splunk plans to offer Splunk Enterprise version 10.6 as a Long-Term Support (LTS) release. Customers should review the final release notes, compatibility guidance, and app requirements as they plan their upgrade.
LTS release gives customers that prioritize a longer support horizon a clearer planning point for platform modernization. Pairing the upgrade with TLS validation, application review, and supported product-identification methods can help preserve the data flows and integrations teams rely on.
Upgrade Readiness for Splunk platform version 10.6
Before upgrading to version 10.6, review the final release notes (linked below) and breaking-change guidance for changes that could affect platform connections, applications, and automation.
Prepare Platform Connections for the Latest Transport-Security Requirements
Before upgrading, customers should validate that network connections between Splunk platform components and dependent applications use transport layer security (TLS) protocol version 1.2 or higher. Identifying older protocol dependencies early reduces the risk of connection failures and helps security, compliance, and platform teams maintain a stronger baseline.
Keep Apps and Integrations Ready for Updated Versioning
Starting with version 10.6, applications and automation should use supported product identification methods instead of relying on the version number alone to distinguish Splunk Enterprise from Splunk Cloud Platform. This helps app owners avoid compatibility issues as Splunk's release cadence evolves.
Turn More Operational Data Into Action With Splunk Platform Version 10.6
Splunk Cloud Platform version 10.6 and Splunk Enterprise version 10.6 give customers more ways to reduce the work between signal and action. Whether that means searching data where it lives, bringing AI into an investigation, keeping log analysis closer to the observability workflow, or tracing a configuration change faster, the outcome is the same: less operational friction and more time focused on resilience.
Related Articles

Staff Picks for Splunk Security Reading August 2021

Cybersecurity Awareness Month Spotlight: Insights from the Cisco Talos & SURGe Teams
