Splunk SOAR 6.2 Introduces New Automation Features, Workload Migration, and Firewall Integrations

The Splunk team is proud to announce the release of Splunk SOAR 6.2 (Security Orchestration Automation and Response). We’ve been hard at work developing the latest and greatest features for this update, several of which have come from requests and suggestions from our users over on Splunk Ideas. SOAR 6.2 allows users to configure logic loops directly in the Visual Playbook Editor with an intuitive user interface, eliminating the need for custom code, as well as integrating the Splunk SOAR cloud environment with CyberARK's privileged access management solution. In addition to these features, the release also includes a new set of firewall management apps for two highly requested products and a new user interface that will allow customers to convert playbooks developed in the classic Visual Playbook Editor to modern playbooks.

Let’s take a closer look at some of the new features and updates for Splunk SOAR 6.2

Over the coming weeks, we’ll provide an in depth look at each of these new features in dedicated blogs and videos. Be sure to check back each week in the month of December for more information.

What’s on the Horizon

The Splunk SOAR team is already hard at work on the next version release and we’ll have more to share about the newest features, playbooks, and much more in 2024. One upcoming change that we want to make sure our users know about involves the classic version of the Visual Playbook Editor.

When version 6.3 of Splunk SOAR arrives next year, we will be removing the classic version of the Visual Playbook Editor. The modern version of the Visual Playbook Editor isn’t going anywhere. Back in version 5.0.1, we introduced the modern version of the Visual Playbook Editor, which made it easier than ever for users to create and modify playbooks, regardless of their level of coding experience. This version added improved readability, vertical orientation, and a slew of new options for creating playbook blocks.

We want to make it as easy as possible for users currently using any playbooks made with the classic editor to be able to convert their playbooks to the modern editor. In our previous release, (6.1.1) we added a command line interface (CLI) tool for on-premises users to migrate their classic playbooks to modern playbooks. With the release of Splunk SOAR 6.2, the same migration capability is available from the Splunk SOAR user interface (UI) and is available for both cloud and on-premises users.

Upgrade to SOAR 6.2 Today

Splunk SOAR 6.2 updates are available today in both cloud and on-prem environments. We are excited to see how users will apply these new features and updates to enhance their approach to automation. Be sure to let us know what you think of Splunk SOAR 6.2 over in the Splunk SOAR Community and if you have an idea or request for a new feature, please let us know by submitting them to Splunk Ideas.

If you didn’t have the chance to join our recent Tech Talk that went over this release, be sure to give the On-Demand recording of the session a watch here.

For more information about Splunk SOAR 6.2, be sure to check out the release notes. Over the coming weeks, we’ll also have individual blogs that take a deeper look at the new features found in this release which you won’t want to miss.

Get out there and get automating!

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.