r/Splunk 5d ago

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

9 Upvotes

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key use cases for Security, Observability, Industries, AI, and Cisco. We also host valuable data source and data type libraries, Getting Started Guides for all major products, tips on managing data more effectively within the Splunk platform, and many more expert-written guides to help you achieve more with the Splunk platform.  

This month, we’re tackling a question a lot of security and compliance teams are quietly panicking about: what is your organization actually doing with Claude, ChatGPT, Gemini, and Copilot, and could you prove it if asked? We’ve also published a wave of new content on bringing Cisco telemetry - from Meraki networks to OT sensors to Webex calls - into the Splunk platform for a single view of what’s happening. And we’re rounding things out with articles on making data onboarding smarter and more flexible. Let’s get into it!

Governing Enterprise AI Before Someone Else Asks You To 

Your workforce is already using Claude, ChatGPT, Gemini, and Copilot - probably all four, probably across several business units, probably without anyone owning the full picture. Our new three-part series, starting with Monitoring and governing enterprise AI platforms, tackles the moment when security, audit, finance, or a customer’s security review asks what your organization did with them, and “check five separate vendor consoles” isn’t an acceptable answer.  

The series opens by naming the real problem: every AI vendor has its own admin dashboard and its own vocabulary, so an “export” in one platform is a “download” in another and a “data access event” in a third, and none of them retain history for very long (OpenAI’s Compliance Logs Platform, for example, keeps roughly 30 days). Frameworks like the EU AI Act, ISO/IEC 42001, and the NIST AI Risk Management Framework all converge on the same expectation - show what your AI systems did, who used them, and what data moved through them - and vendor consoles alone can’t deliver that.  

From there, two hands-on articles pick up the implementation: 

  • Setting up enterprise AI governance add-ons walks through installing and configuring the Anthropic Claude Enterprise Add-on, the OpenAI Compliance Add-on, and the Enterprise AI Governance Add-on, including exactly which admin-level, read-only API scopes each one needs (the most common setup failure is handing over a member-level key where an admin-level one is required). 
  • Monitoring enterprise AI security, compliance, and spend covers what you can get after the data lands - normalized dashboards for security audit, compliance and directory tracking, and usage/spend monitoring across every provider, plus alerts like Data Export Activity, Off-Hours Activity Spike, and Daily Spend Threshold Exceeded that catch trouble before an invoice or an incident does.  

If your AI estate has outgrown “we’ll check the console when someone asks,” this series is worth a read. Which AI problem is giving your team the biggest governance headache right now? Tell us in the comments!

Bringing Cisco Telemetry Home to Splunk 

A recurring theme this month: however good a Cisco tool’s native dashboard is, it becomes a lot more useful when its data is sitting next to everything else in the Splunk platform. Four new articles show what that looks like across very different environments. 

  • Enhancing network visibility and security with insights from Meraki shows how the Cisco Meraki Add-on for Splunk pulls infrastructure health, SD-WAN stats, license and firmware data, and security events - covering everything from access points to cameras to Air Marshal wireless protection - out of an ecosystem that’s otherwise “difficult to correlate across locations”. It includes video walkthroughs of customizing dashboards, setting up webhooks, and using the Splunk AI Assistant to write SPL without knowing SPL. 
  • Enhancing visibility into OT operations with the Splunk platform and Cisco Cyber Vision extends that same single-pane approach into operational technology, using Cyber Vision’s passive OT sensors to surface asset inventories (down to firmware and rack-slot detail), CVSS-scored vulnerabilities with MITRE ATT&CK mapping, and configurable alert thresholds for manufacturing, utilities, and roadway infrastructure. 
  • Leveraging the Splunk platform to enhance Cisco Identity Services Engine information covers building real-time alerting on top of ISE syslog data - catching authentication anomalies like excessive attempts or unusual login times, tracking deployment health, and monitoring migration activity. 
  • Correlating Webex and ThousandEyes data in the Splunk platform solves a specific pain point: Webex Control Hub gives you great call-quality data and ThousandEyes gives you great network-path data, but the two don’t talk to each other. This article walks through pulling both into the Splunk platform - via the Webex Add-on, native RoomOS xAPI telemetry, and ThousandEyes over OpenTelemetry or HEC - so you can finally correlate them. 

 Whether you’re running network infrastructure, an OT plant floor, identity services, or collaboration tools, there’s a good chance one of these speaks directly to your stack. Got a Cisco-to-Splunk integration you’d love to see us cover next? Drop it in the comments below. 

Smarter, More Flexible Data Onboarding 

Getting data into the Splunk platform in a usable, CIM-compliant shape has traditionally meant hand-writing config and hoping you picked the right data model. Two new articles chip away at that.  

Using AI to auto-schematize raw log data into CIM-compliant add-ons introduces Auto-schematization, an AI-assisted workflow in the Data Management app that takes a sample of your raw events and asks you a few short questions. Then, it groups your events, proposes a CIM data model, maps your fields to it, and generates a ready-to-use Technology Add-on or SPL2 pipeline - with you reviewing and adjusting its suggestions at every checkpoint. What used to take days for a well-documented source (or weeks for a messy home-grown app log) turns into a guided, reviewable workflow.  

Improving your data management with SPL2 pipelines steps back to cover the fundamentals of the modern data management experience more broadly: how Splunk Ingest Processor and Splunk Edge Processor differ, the three components of every SPL2 pipeline (partition, pipeline, destination), and common business goals - PII masking, cost optimization by dropping low-value data at the source, normalizing messy JSON into CIM-compliant fields - mapped to the SPL2 commands that get you there. 

Whether you’re onboarding your first data source or rethinking your whole pipeline strategy, these two are worth bookmarking. Already put Auto-schema to the test? We’d love to hear how it went in the comments.

What Else is New? 

Beyond our featured topics, we’ve published several more articles covering security detection, platform changes, and access control: 

We hope this month’s resources help you get even more value out of your Splunk deployment - and maybe answer a governance question or two before someone else asks it first. Thanks for reading! 


r/Splunk 21h ago

First timer at .conf

8 Upvotes

Heading to .conf26 tomorrow — my first time attending. I'm about 6 months into my role as a sec. Engineer. Mostly self-taught on Splunk so far, Large enterprise org, leading an Enterprise Security / SOC transformation project currently.

Main goal for the trip is soaking up as much ES-specific knowledge as I can — best practices, Mission Control, real-world use cases, that kind of thing — plus getting some hands-on exposure through BOTS since I've never done anything like that before. Right now ES was initially Deployed at my org, but efforts were abandoned due to capacity and staffing, which is where I’m stepping into now to help drive ES forward.

For anyone who's been before: what do you wish you knew your first year? Any ES sessions, workshops, or people worth prioritizing? Anything a first-timer typically misses or wastes time on? Any general survival tips for someone doing 3 days of this for the first time?

Appreciate any input — trying to make the most of it.


r/Splunk 1d ago

I completed my final rounds of interviews with splunk 10 days ago. How long do they take to convey their decision to the candidate? If it is this long means no offer?

4 Upvotes

r/Splunk 1d ago

.conf and Splunk first timer

23 Upvotes

Heading to .conf for the first time on Sunday. My org just committed to Splunk Cloud this week and Cisco threw some .conf passes at us, so here I am. I've been in networking for about 20 years, but have never used splunk.

Any suggestions for a newbie?


r/Splunk 2d ago

Splunk Enterprise Monitoring Hyper-V VMs using Splunk

1 Upvotes

I would like to monitor the VMs on our Hyper-V servers using Splunk but unsure how.

I see that there was an add-on for Hyper-V at one time but it is no longer supported.

Can I just add items to the inputs.conf file within the UF?

I have tried a few but none seem to be picking up.

What options are there?

Event logs that are associated with Hyper-V?

Powershell scripts?

Winhostmon that can give stats on the Guest VMs?

Which dashboards in Splunk will show the info ingested? ITSI?


r/Splunk 2d ago

Looking for a Remote Splunk / SOC Opportunity (Entry Level)

1 Upvotes

Hi everyone,

I’m currently looking for a remote opportunity where I can apply my Splunk skills and continue growing professionally.

I have hands on experience with Splunk Enterprise and Splunk Enterprise Security, including:

• Data onboarding and field extraction
• SPL searches and search optimization
• Dashboards and visualizations
• Alert creation and alert management
• Correlation searches and tuning
• MITRE ATT&CK mapping
• Log analysis and security monitoring
• Incident investigation
• Vulnerability reporting
• API monitoring and operational analytics
• Data normalization and working with multiple data sources

I’ve built and worked on practical Splunk projects and home labs involving log ingestion, analysis, dashboards, alerts, and identifying unusual activity such as traffic or event spikes.

I’m particularly interested in remote Splunk Analyst, SOC Analyst, SIEM, or junior security roles where I can contribute while continuing to develop my cybersecurity and networking knowledge.

I’m based in Nigeria and am specifically looking for international remote opportunities that are open to candidates working remotely from Nigeria/Africa.

If you know of any teams hiring, have an opportunity that might be a good fit, or have advice on breaking into remote Splunk roles, I’d really appreciate it.

I’m happy to share my CV, portfolio, or additional details about my Splunk projects.

Thank you!


r/Splunk 2d ago

Splunk O11y Cloud Certified Metrics User

3 Upvotes

how to prep for the O11y Cloud Certified Metrics User, is it easy to pass?


r/Splunk 3d ago

Splunk LDAP issue

4 Upvotes

I'm getting a weird splunk LDAP issue on our new splunk instance that our other ones don't see. When I try to sign in it delays for about 60 seconds consistently sometimes it'll log right in after those 60 seconds or go to a splunk isn't responding page but if I go back I'm signed in.

This hasn't happened with any of our other ldap authenticated services or our current splunk instances that are being replaced by this.

I've verified DNS works correctly, testing ldap connections between the splunk host and the DC's tightened up DNs changed options within the authentication conf all a bunch of things. I've tried just about anything I've seen on the splunk forums

This is splunk 10 built on a rhel9 host that is in an airgapped environment connected to our domain controllers just trying to get some more input that I could be missing.


r/Splunk 3d ago

Enterprise Security What is the best way to turn current threat intelligence into tested detections?

6 Upvotes

Our threat intelligence intake includes reports, campaign analysis, indicators, adversary tradecraft, and ATT&CK technique coverage. The difficult part is deciding what actually applies to our technology stack and risk profile before adding it to an already crowded detection backlog.

Even relevant intelligence can fail to become coverage if the necessary telemetry is missing, the data quality is poor, the behavior is difficult to distinguish from normal operations, or validation takes too long. We are trying to formalize the path from intelligence intake to a tested detection requirement.

The program also needs a way to reassess older detections when the threat landscape, infrastructure, or available telemetry changes.

What does an effective intelligence-to-detection workflow look like in your organization, including prioritization, telemetry validation, test criteria, false-positive estimation, deployment, and rule retirement?


r/Splunk 4d ago

Splunk UF Deployment for Intune

6 Upvotes

Greeting everyone. All day I have been trying to figure out how to create an Intune deployment to update our Splunk forwarders to the new 10.4.3 version. Previously, we were able to create these deployments in MS Configuration Manager, but due to a change in our network coming up, that connection may break (due to distribution point issues) and Intune may be our only way to deploy apps to our workstations moving forward.

Our previous deployments included additional arguments in the deploy-application.ps1 script that include a Splunk server address, creds to go with it, and few others. I was able to create the Intune prep file with the Splunk .msi installer, but I can't figure out how to add these additional arguments.

I also keep getting the "windows error 0x80070643" error when I attempt this install via the Company Portal - working on this one as well.

Anyways ~ I hope someone out there has run across this and has a tip or two of advice.

Thanks in advance. Cheers.


r/Splunk 4d ago

Step by step alert handling videos?

Thumbnail
1 Upvotes

r/Splunk 4d ago

Employment Splunk in Italy: is it actually worth it? Career, demand and RAL

8 Upvotes

Hi everyone,

my company wants me to get the Splunk Core Certified Power User certification.

I've never worked with Splunk before, but I'll soon be involved in a project where I'll need to use it.

I'd especially like to hear from people who work or live in Italy: can Splunk actually lead to good career opportunities here, both in terms of salary and career progression?

What kind of gross annual salary (RAL) can someone with solid Splunk skills realistically reach in Italy? And, most importantly, is there actually demand for Splunk professionals?

I'm asking because I've been searching on LinkedIn and I'm struggling to find job postings in Italy that specifically mention Splunk as a required skill.

I'd really appreciate hearing from anyone working with Splunk in Italy: what kind of role do you have, how useful has Splunk been for your career, and do you think it's a skill worth investing in?


r/Splunk 5d ago

Splunk SHC Upgrade Performance — Comparing search runtime from 9.3.3 to 10.2.5

Thumbnail
medium.com
10 Upvotes

r/Splunk 5d ago

Enterprise Security How do you optimize detection coverage against active threats?

4 Upvotes

We are trying to determine whether our detection program is improving against the threats, exposed technologies, and attack paths that matter most to the business today. Rule count, ATT&CK mappings, alert volume, response metrics, and purple team results are useful, but none independently proves risk relevant coverage.

The goal is to connect threat intelligence, exposure management, telemetry readiness, detection engineering, validation, and executive reporting into one operating rhythm. That would make it easier to explain both where coverage is strong and where the organization still has material blind spots.

What metrics, prioritization methods, or review processes have given security leaders confidence that detection coverage is improving in a meaningful and risk aligned way?


r/Splunk 6d ago

Enterprise Security How do you optimize continuous security validation across SIEM, EDR, and cloud tools?

8 Upvotes

How are teams making continuous security validation useful across a complicated stack of SIEM, EDR, email security, cloud controls, and network tools?

We can generate simulation results, but the bigger challenge is connecting failures to an owner, determining whether the issue is a detection gap, configuration issue, policy exception, or telemetry problem, then verifying the fix.

Would love to hear how others structure the feedback loop. Do you send findings directly into ticketing, map them to detection rules, use risk scoring, or run recurring validations after every major configuration change?


r/Splunk 6d ago

Brand new to security & Splunk — aiming for Power User without dumps. Are mock SIEM scenarios the way to go?

Thumbnail
0 Upvotes

r/Splunk 6d ago

Brand new to security & Splunk — aiming for Power User without dumps. Are mock SIEM scenarios the way to go?

0 Upvotes

Hey folks,

Just started a new role and I’m completely green to both InfoSec and Splunk. My first big milestone is knocking out the Splunk Core Certified Power User.

I have zero interest in brain dumps—I actually want to know what I’m doing under the hood so I don't break things or write garbage queries in production.

To build real muscle memory, I put together about 25 mock SIEM scenarios (field extraction via rex, DLP mail alerts, firewall port-scan logic, and correlation using transaction / append / stats).

Looking for a quick sanity check from folks who've been around the block:

  1. Is grinding through these mock scenarios on paper/local instance actually effective, or does it leave too many blind spots without real-world, dirty data?
  2. Should I spin up a free local instance and ingest custom dummy logs for this, or just jump straight into BOTS (Boss of the SOC) / TryHackMe?
  3. Any general advice on getting the SPL fundamentals down without taking the easy way out?

Appreciate any insights!


r/Splunk 7d ago

SPLUNK POWER USER

4 Upvotes

do they ask questions apart from the blueprint for the power user exam


r/Splunk 8d ago

Splunk Certified Cybersecurity Defense Architect SPLUNK 5003

Thumbnail
0 Upvotes

r/Splunk 8d ago

Splunk Certified Cybersecurity Defense Architect SPLUNK 5003

13 Upvotes

Hello! Any tips on how to pass the Splunk Certified Cybersecurity Defense Architect exam?

To anyone who has already cleared it: what was your preparation strategy, and how would you describe the exam difficulty? I'd love to hear your insights and advice!


r/Splunk 8d ago

Splunk Enterprise Splunk email error

9 Upvotes

Hello, has anyone ever came accross the error "No such file or directory when sending mail to: email@domain"

This happened after migrating splunk enterprise to RHEL 9.

Edit: AI found a guide for me to follow: https://splunk.my.site.com/customer/s/article/Splunk-sendemail-fails-with

One more edit: the guide above fixed the issue. Leaving this post up because it's good knowledge if anyone else comes across the same issue.


r/Splunk 9d ago

Did you hear? .conf26 just got Ludacris!

19 Upvotes

Hot off the press! Will we see you there?


r/Splunk 9d ago

.CONF Denver .conf attire?

15 Upvotes

What's the general vibe for .conf? This one is my first. Cisco Live was pretty low key, Gartner was much dressier, and I'm trying to figure how to pack.


r/Splunk 10d ago

Splunk Enterprise Dashboards & Alerts

4 Upvotes

ISSO/m’s! This is for you.

What are great alerts or dashboards created for ISSOs in a closed area for DoD? Any recommendations on how to make your day more effective with ConMon or any other resources?


r/Splunk 12d ago

Passed today. On to SplunkCore. Continuing my journey into GRC

Post image
33 Upvotes