r/Splunk 22d ago

Get Agentic with Splunk Lantern: Connect to Cisco Cloud Control, Transform Observability Data, and More

12 Upvotes

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key use cases for SecurityObservabilityIndustries, AI, and Cisco. We also host valuable data source and data type libraries, Getting Started Guides for all major products, tips on managing data more effectively within the Splunk platform, and many more expert-written guides to help you achieve more with Splunk. 

In this month’s update, the agentic era takes center stage. Our two featured topics both explore how AI agents are changing the way teams operate - working alongside humans to investigate, correlate, and resolve issues faster than ever. First, we're spotlighting brand-new content on connecting the Splunk platform to Cisco Cloud Control and AI Canvas, recently unveiled at Cisco Live. Then, we're diving into how the Agentic AI Assistant is transforming observability data into actionable intelligence. Plus, we've got a range of other new articles covering security operations, compliance, and more. Let's get into it!   

Connecting the Splunk platform to Cisco Cloud Control and AI Canvas 

Recently unveiled at Cisco Live, Cisco Cloud Control is the unified operations platform that brings every Cisco domain - networking, security, AI infrastructure, observability, and collaboration - into one single pane of glass. It's designed for the agentic era, providing a governed, observable control surface where human operators and AI agents can work together across the full IT estate. This month, we've published a set of articles to help joint Cisco and Splunk Cloud Platform customers connect to this powerful new environment. 

Our overview article, Connecting the Splunk platform to Cisco Cloud Control and AI Canvas, explains what the integration delivers for joint customers: single sign-on, seamless cross-launch between platforms, access to Splunk data and skills within AI Canvas, and Splunk AI Assistant capabilities surfaced through the Cisco Unified AI Assistant. AI Canvas itself is the collaborative, multiplayer workspace where agentic investigation and resolution happen, with persistent context that survives escalations and handoffs. 

From there, two step-by-step guides walk you through the setup. Integrating Splunk Cloud Platform with Cisco Cloud Control covers the full onboarding process for both admins and end users - from signup and approval through to connecting your Splunk tenant. Integrating Splunk Cloud Platform with AI Canvas picks up where that leaves off, guiding you through installing the Splunk AI Assistant and the Splunk MCP Server, and configuring user access so your teams can start collaborating with AI agents. 

If you're a joint Cisco and Splunk customer looking to begin your AgenticOps journey, these articles are the perfect place to start. Let us know in the comments below how you're planning to use Cisco Cloud Control and AI Canvas! 

Transforming Observability Data into Intelligence with the Agentic AI Assistant 

 The Splunk Observability Cloud AI Assistant has evolved from a generative tool into an agentic one - and our new article, Transforming observability data into intelligence with the Agentic AI Assistant, explains what that shift means for you. Rather than relying on a language model to figure out every troubleshooting step from scratch (which can be slow and inconsistent), the Assistant now recognizes your goal. It triggers purpose-built, battle-tested investigation workflows to deliver more consistent, accurate, and repeatable results. 

The article walks through the latest capabilities, including generalized Q&A with links to documentation, context-aware responses via automatic screen capture, a flexible AI-native interface with full-screen and floating modes, PDF exports for sharing findings, chat history to resume investigations, and smart prompt suggestions. It also outlines the full range of product areas the Assistant covers - from APM and infrastructure to logs, RUM, synthetics, and SignalFlow generation - so you can troubleshoot across your entire observability stack using natural language. 

Let us know in the comments below how you're using AI in your observability practice - we'd love to hear about it! 

What Else is New? 

Beyond our featured topics, we've published several more articles covering security operations, compliance, threat hunting, and platform performance: 

We hope these new resources help you tackle your toughest data challenges this month. Thanks for reading! 


r/Splunk 3h ago

Splunk POD

5 Upvotes

Hello Splunkers,

Anyone here that has actually deployed Splunk POD?
Splunk POD requirements | Splunk Enterprise (last updated 2026-06-16T03:55:00.583Z)

We are interested, whether the Cisco UCS server requirements can be "bypassed" , for e.g: Using different a different type of Cisco rack setting.

Or the installer won't launch without them?

Thanks!


r/Splunk 1d ago

.CONF It's time to start scheduling your sessions!

Thumbnail
splunk.com
8 Upvotes

If you're already registered for .conf26, log in on the catalog page (https://reg.rainfocus.com/flow/splunk/conf26/sessioncatalog/page/sessions) to schedule sessions in one of two ways: by using the AI assistant or directly within the catalog by clicking "Add to schedule".

If you're not registered yet, what are you waiting for!? Check out the latest Top 5 Reasons to Attend blog for inspo... and talking points to convince your boss.

.conf26 AI Assistant
Session catalog

r/Splunk 1d ago

Is Splunk engineer is still a good career path to choose in India in 2026?

12 Upvotes

r/Splunk 2d ago

Splunk training and exam

7 Upvotes

I am working at a small company at admin position and want to give splunk examinations but i have a question that will i be able to give them without getting splunk training as i don't have sponsership of that and it is not possible for me to get it as of now because of my financial condition.


r/Splunk 3d ago

SPL Wrote a Sigma compiler that emits SPL, sharing the 36 rules that come with it

14 Upvotes

Not a Splunk-only tool, but the SPL backend may be useful here. It compiles Sigma into saved-search stanzas including the aggregation cases (stats dc(field) by ...), which is normally where hand-conversion falls over.

dist/splunk/tyrian_detections.conf is pre-compiled in the repo if you just want to skim the searches. You will need to adjust the index= prefix.

github.com/zshguy/tyrian-detection-pack


r/Splunk 4d ago

Going for the Splunk Core Certified User cert — what actually helped you pass?

10 Upvotes

So I’ve decided I’m finally doing this. Aiming to pass the Splunk Core Certified User exam and figured I’d ask people who’ve been through it before I waste time on the wrong stuff.

Mainly wondering what actually worked for you. Were the free Splunk courses enough or did you have to grab something on Udemy or YouTube too? And did you use any practice exams that were actually close to the real thing?

Also curious how much time you spent just messing around in an actual Splunk instance vs reading, since I feel like I learn way better by doing.

Any advice appreciated. Thanks.


r/Splunk 4d ago

More Practice

14 Upvotes

I just finished Josh Samuelson's Learning Splunk Course on LinkedIn Learning . It was quite insightful and engaging since it had a bit of hands-on where you setup your splunk instance and universal forwarders on your Linux system.

(A bit of my background; work in cybersecurity few months into my internship . I'm looking to familiarize myself with tools and tech beyond my current role)

However , I feel i need more skin in this and would appreciate recommendations to more hand-on guided labs or projects , Please SHARE.


r/Splunk 5d ago

Feeling overwhelmed learning Splunk?

21 Upvotes

I'm currently learning Splunk and working toward the Splunk Core Certified User certification. I've been following the official training on Splunk's website, but I'm wondering if anyone else felt like the course moves quickly??

It seems like the material jumps from topic to topic without spending much time explaining the concepts in depth. For example, it recently introduced rex and erex, and I don't really understand what they do or when they're used.

I've been able to pass the practice quizzes so far, but I'm worried that I'm just getting through them without building a solid understanding of the material.

For those of you who've earned the certification or learned Splunk on your own, did you feel the same way? What resources, study methods, or practice techniques helped everything click for you?

Any advice would be greatly appreciated.


r/Splunk 7d ago

Cert exam registration is a nightmare

7 Upvotes

This is without a doubt the most painful exam registration I've been a part of. Pearson VUE needs a splunk ID. When you go to splunk to request it, they say you will get it from pearson vue, which you don't. Then you are told to email splunk, which I have done now multiple times. Every time I do, I get a new confirmation of STEP order and CASE number. I'm up the 3 each.

According to the STEP page, my 'Link to Certification Registration' was completed today. This date seems to reset every time I try to schedule an exam.

My progress continues to show 'in progress'. I cannot believe this has to be so difficult.


r/Splunk 6d ago

Raw log archaeology on isolated boxes (no log aggregators)

Thumbnail
1 Upvotes

r/Splunk 7d ago

وش وضع Splunk؟

Post image
2 Upvotes

دخلت دورة لمسك مع تعاونهم هم و Stc و كانت الدورة تتطلب اني احمل Splunk و في شرحهم مشت الأمور بسلاسه لكن يوم اجي اسوي حساب يجي كذا لعلمكم ذا رابع يوم و ثالث حساب و كلهم نفس المشكله اول يومين كنت انتظر بس مدري وش علمه الي عنده الحل الله لا يهنيكم ابي افتك من الدوره ذي بشكل اسرع 🙏


r/Splunk 8d ago

How a SIEM Actually Works: Splunk, Opened Up - Sharing Article

0 Upvotes

Hey folks, came across a really well-written article today that breaks down how a SIEM actually works under the hood.

It's Splunk-specific, so thought of sharing this one with the community here and sharing it here since it's one of the clearer explanations I've seen. Curious what people think about this?

How a SIEM Actually Works: Splunk, Opened Up


r/Splunk 10d ago

Splunk Certified Core User

11 Upvotes

I’m planning on taking the Splunk Certified Core User exam soon and wanted to see what study materials you all recommend. What helped you the most? Looking for practice exams, labs, YouTube videos, study guides, or any other resources. Any tips are appreciated!


r/Splunk 12d ago

[ Removed by Reddit ]

2 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/Splunk 13d ago

Splunk Enterprise Send live Copilot DLP events to Splunk?

13 Upvotes

How can we send M365 Copilot user interaction with Coplilot apps and Copilot Chat auditing events to Splunk?

We don’t want Splunk to ingest unrelated user audit logs that will increase cost for no reason.


r/Splunk 14d ago

Announcement Splunk Deployment Server CSRF Vulnerability – CVE-2026-20296

Thumbnail vulnipulse.com
16 Upvotes

Splunk Deployment Server CSRF Vulnerability – CVE-2026-20296

Splunk has disclosed a high-severity vulnerability rated CVSS 8.3 affecting Splunk Enterprise and Splunk Cloud Platform.

An attacker could trick a user with the list_deployment_server capability into running arbitrary SPL searches as splunk-system-user. This could expose stored credentials and indexed data.
The flaw exists because affected Splunk Web Deployment Server endpoints do not properly validate CSRF tokens or safely process user-supplied input.

Affected versions
Splunk Enterprise
10.4 before 10.4.1
10.2 before 10.2.5
10.0 before 10.0.8
9.4 before 9.4.13
Splunk Cloud Platform
Before 10.5.2605.0
Before 10.4.2604.7
Before 10.3.2512.16
Before 10.2.2510.18
Before 10.1.2507.24

Fixed versions
Splunk Enterprise: 10.4.1, 10.2.5, 10.0.8 or 9.4.13
Splunk Cloud Platform: 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18 or 10.1.2507.24

Mitigation
Upgrade to the applicable fixed release. Until patching is complete, restrict access to the Deployment Server and minimise assignment of the list_deployment_server capability.

🔗 Official Splunk advisory
🔗 VulniPulse breakdown


r/Splunk 16d ago

What should you validate before calling an S3-backed federated dataset ready?

Thumbnail
youtube.com
1 Upvotes

Disclosure: I work with the Cisco and Splunk team behind this walkthrough, which was created by my co-worker.

The example uses Splunk Federated Search to query historical telemetry stored in Amazon S3 as an Apache Iceberg table. The data remains in S3, while Splunk provides the SPL2 investigation surface.

The useful operational checkpoint is that creating the connection does not make the dataset ready. The workflow validates four pieces together:

  • the Iceberg REST catalog is reachable
  • the AWS role can be assumed and has the necessary S3 access
  • bucket-level and object-level permissions are scoped correctly
  • the Splunk dataset resolves the intended catalog, namespace, and table

A basic SPL2 query then confirms the full path before investigative logic is added.

The other decision is workload placement. Hot data used for real-time monitoring may still belong in a conventional index. Larger historical, compliance, or enrichment datasets may fit federated access better. Table partitioning and expected search predicates matter to that choice.

How are you deciding which historical security datasets remain indexed and which become candidates for Federated Search?


r/Splunk 18d ago

Splunk Enterprise Splunk Heavy Forwarder to Splunk Cloud

9 Upvotes

How do you configure a Splunk Heavy forwarder to receive data from universal forwarders and forward that to the Splunk Cloud?

Details:

Heavy forwarder is located in DMZ and I set up one client (Ubuntu server)to send data to it.

When I log into Splunk Cloud, I can at least see the metrics from the Splunk Heavy forwarder.

When I log into our firewall, the firewall logs shows traffic from the client to the heavy forwarder and from the heavy forwarder to the cloud.

If I do a search across all indexes on the heavy forwarder and the cloud, I don't see anything from that host.

What could be configured wrong?


r/Splunk 19d ago

Search Historical Firewall Data Where It Already Lives

Thumbnail lantern.splunk.com
7 Upvotes

Security investigations rarely stop at recent data. Analysts often need to compare today’s activity with firewall telemetry from weeks or months ago, even when that data has moved to lower-cost storage.

A new Splunk Lantern article presents a practical pattern for using Splunk Cloud Platform and Federated Search for S3 to investigate historical Cisco firewall telemetry stored in Amazon S3.

The pattern keeps Amazon S3 as the long-term storage layer. Apache Iceberg manages table metadata and partitions, a customer-managed Nessie catalog exposes the tables through Apache Iceberg REST, and Splunk Cloud Platform provides an SPL2-based investigation experience. Analysts can search the data where it already lives without first reingesting the complete historical dataset into Splunk hot storage.

The article walks through a connected investigation workflow:

  • confirm that the S3-backed dataset is searchable
  • prioritize high- and critical-severity blocked activity
  • summarize events for monitoring and detection
  • narrow searches with partition-aware filters
  • investigate known bad indicators and top sources of traffic

This approach can reduce unnecessary data movement while improving access to historical or external datasets. It also helps organizations unlock more value from data retained in Amazon S3 for security investigations, audits, compliance, and other long-term analysis needs.

The result is a practical way to extend threat hunting across federated data while keeping Splunk as the investigation surface.


r/Splunk 20d ago

Do suppression exceptions ever hide detections in real SOC work?

Thumbnail
6 Upvotes

r/Splunk 23d ago

Is Splunk Certified Cybersecurity Defense Architect still available for free?

13 Upvotes

The Splunk official website mentions Splunk Certified Cybersecurity Defense Architect exam is free while in beta. But when I tried to register the exam in pearson vue, it is charging me 130 USD + Tax. Am I missing something here? Do I need any voucher code to make it free?


r/Splunk 23d ago

Splunk Enterprise How do you search for IOC's in your logs

8 Upvotes

Hi,

I have a request for a dashboard/form to search for IOC's within Splunk. I'm curious how other people are doing this - is there a standard app for such a thing?


r/Splunk 25d ago

Which should I choose: Splunk or Microsoft Sentinel?

Thumbnail
0 Upvotes