Home Solutions Services About Us Discovery Contact Us

Strawinskylaan 411 1077XX,
Amsterdam, Netherlands

Wilhelmina van Pruisenweg 35,
2595 AN Den Haag

+31 6 11 10 62 26

[email protected]

Splunk

A New Era of Security with Splunk .conf25: Agentic AI and the Smart SecOps Approach

Digitalized systems are becoming increasingly complex with microservices architectures, cloud infrastructures, and artificial intelligence components.

Estimated reading time: 5 minutes
H. F. G. - Netsmart
 - 11 November 2025, Tuesday

In this complexity, it is critical not only to see what is happening, but also to understand why it is happening, to detect potential issues in advance, and to respond effectively. The innovations announced at Splunk’s 2025 .conf25 conference elevate these critical capabilities by combining observability and security with artificial intelligence. This new vision offers significant opportunities for both decision-makers and engineers.

As a Tier Elite Partner of Splunk with extensive and advanced experience in Splunk solutions, Netsmart is committed to helping organizations swiftly adopt and benefit from this new vision.

.conf25 and Beyond: Security / SecOps-Focused Innovations

Below are the key announcements that stand out in terms of security, SIEM, automation, and artificial intelligence:

AI-Powered Security Operations

The most prominent security theme at Splunk’s .conf25 event was the concept of “Agentic AI.” This new approach aims to transform AI from a passive data analysis component into an active security operator.

With the release of Splunk Enterprise Security (ES) version 8.2, AI-powered SecOps capabilities now unify threat detection, investigation, and response (TDIR) processes under a single framework.

New AI agents are designed to ease the daily workload of SOC teams:

  • Triage Agent automatically prioritizes incidents, surfacing the most critical alerts.
  • Malware Reversal Agent analyzes malware behavior and clusters related threats.
  • AI Playbook Authoring generates SOAR playbooks automatically based on natural language instructions.
  • Detection Studio enables rapid development of custom threat detection rules and scenarios.

With this integrated structure, Splunk brings together ES + SOAR + UEBA modules, allowing analysts to operate with holistic visibility, without getting lost across multiple screens and systems.

Agentic AI: The Next Generation of Security Assistants

At .conf25, Splunk and Cisco jointly introduced the concept of “Agentic AI,” a transformative vision poised to shape the future of security operations centers.

These agents are not just systems that interpret data, they act as digital security assistants capable of establishing correlations, performing root cause analysis, and recommending actions.

When Splunk’s vision is integrated with Cisco’s data infrastructure (such as Cisco Data Fabric), incident management will no longer be confined to the SIEM layer; signals from network, endpoint, and application layers can be analyzed within the same flow.

This approach enables security teams to adopt a new working model based on the principle of “human + machine collaboration”: while analysts focus on strategic decisions, agents take on operational workloads.

Reducing Alert Noise: Event iQ and Episode Summarization

One of the biggest challenges for security teams alert fatigue, can be significantly reduced with Splunk’s new Event iQ and Episode Summarization features.

Event iQ uses a correlation engine to group related alerts into a single event cluster.

Episode Summarization (currently in Alpha) generates meaningful summaries from these clusters, reporting the causes and impacts of incidents with AI support.

This capability allows analysts to manage what would otherwise be hours of log review in just minutes, thanks to concise, AI-generated reports.

A New Era in Application Security: Application Vulnerability Detection

The new Application Vulnerability Detection module in Splunk Observability Cloud brings security and observability together on a single platform.

With this feature, Splunk agents can detect vulnerabilities in applications during runtime and directly correlate them with system performance metrics.

For example, a performance drop observed in an API call can be linked to a potential security flaw and presented to the analyst through a unified interface.

This approach goes beyond traditional SIEM capabilities, strengthening the integration of “observability + security” in a seamless and intelligent way.

Data Access and Cost Efficiency: Cisco Firewall Log Integration

Another major development announced after .conf25 is the enhanced log-sharing integration between Splunk and Cisco.

Under the new licensing model, logs from Cisco security devices, especially Cisco Secure Firewall, can be transmitted to Splunk via a free or low-cost data pipeline.

This creates a significant improvement in security visibility. Data sources that were previously excluded due to log volume constraints can now be actively utilized within the SOC.

As a result, more comprehensive correlation, more accurate threat detection, and lower-cost security monitoring become achievable.

Splunk .conf25: From Seeing Data to Learning from It

The central theme of .conf25 revolves around a vision of “not just seeing data but deriving meaning from it.” Under the Cisco umbrella, Splunk is placing artificial intelligence at the heart of operational intelligence.

Key Innovations:

  • AI Troubleshooting Agents — AI agents are deployed for root cause analysis in complex infrastructures, identifying potential causes and offering automated solutions.
  • Business Insights — This feature links technical metrics directly to business KPIs, making the connection between “system performance” and “business progress” visible.
  • Federated Search for Snowflake — Combines Splunk and Snowflake data under a single query, eliminating data silos.
  • AI Infrastructure Monitoring & Agent Monitoring — Enables monitoring of AI infrastructure and agent health.
  • AI-Powered SecOps and Enterprise Security 8.2 — Expands the boundaries of automation in threat detection, investigation, and response.
  • New Interface (GenUI) and Cisco AI Canvas Integration — Simplifies user experience while making AI capabilities more accessible.

The common thread across these innovations is Splunk’s vision to transform data-centric analytics into “learning systems.”

Splunk is no longer just a system that tells you what happened, it’s a platform that understands why it happened and recommends what to do next.

Post-Quantum Cryptography: A Strategic Roadmap for Cybersecurity

Thales

The rise of quantum computing introduces significant challenges to existing cryptographic systems.

More
In today’s post we’ll explain how to simulate Active Directory attacks using Splunk and various tools to improve an organization's security posture.

Simulation of Active Directory Attacks with Splunk

Splunk

In today’s post we’ll explain how to simulate Active Directory attacks using Splunk and various tools to improve an organization’s security posture.

More
In this blog post, we will cut through the confusion and explain the core differences between SIEM and SOAR, two essential security tools used to protect your organization.

SIEM vs. SOAR

Versus

In this blog post, we will cut through the confusion and explain the core differences between SIEM and SOAR, two essential security tools used to protect your organization.

More
In this blog post, we will explore how to strengthen the security of CyberArk by leveraging Hardware Security Modules (HSMs).

Integration of CyberArk with HSM

CyberArk

The privileged accounts of organizations play an important role in today’s cybersecurity ecosystem. Protecting these accounts and the critical resources they access has become crucial for organizations to manage, control, and audit all privileged account activities.

More