In this complexity, it is critical not only to see what is happening, but also to understand why it is happening, to detect potential issues in advance, and to respond effectively. The innovations announced at Splunk’s 2025 .conf25 conference elevate these critical capabilities by combining observability and security with artificial intelligence. This new vision offers significant opportunities for both decision-makers and engineers.
As a Tier Elite Partner of Splunk with extensive and advanced experience in Splunk solutions, Netsmart is committed to helping organizations swiftly adopt and benefit from this new vision.
Below are the key announcements that stand out in terms of security, SIEM, automation, and artificial intelligence:
AI-Powered Security Operations
The most prominent security theme at Splunk’s .conf25 event was the concept of “Agentic AI.” This new approach aims to transform AI from a passive data analysis component into an active security operator.
With the release of Splunk Enterprise Security (ES) version 8.2, AI-powered SecOps capabilities now unify threat detection, investigation, and response (TDIR) processes under a single framework.
New AI agents are designed to ease the daily workload of SOC teams:
With this integrated structure, Splunk brings together ES + SOAR + UEBA modules, allowing analysts to operate with holistic visibility, without getting lost across multiple screens and systems.
Agentic AI: The Next Generation of Security Assistants
At .conf25, Splunk and Cisco jointly introduced the concept of “Agentic AI,” a transformative vision poised to shape the future of security operations centers.
These agents are not just systems that interpret data, they act as digital security assistants capable of establishing correlations, performing root cause analysis, and recommending actions.
When Splunk’s vision is integrated with Cisco’s data infrastructure (such as Cisco Data Fabric), incident management will no longer be confined to the SIEM layer; signals from network, endpoint, and application layers can be analyzed within the same flow.
This approach enables security teams to adopt a new working model based on the principle of “human + machine collaboration”: while analysts focus on strategic decisions, agents take on operational workloads.
Reducing Alert Noise: Event iQ and Episode Summarization
One of the biggest challenges for security teams alert fatigue, can be significantly reduced with Splunk’s new Event iQ and Episode Summarization features.
Event iQ uses a correlation engine to group related alerts into a single event cluster.
Episode Summarization (currently in Alpha) generates meaningful summaries from these clusters, reporting the causes and impacts of incidents with AI support.
This capability allows analysts to manage what would otherwise be hours of log review in just minutes, thanks to concise, AI-generated reports.
A New Era in Application Security: Application Vulnerability Detection
The new Application Vulnerability Detection module in Splunk Observability Cloud brings security and observability together on a single platform.
With this feature, Splunk agents can detect vulnerabilities in applications during runtime and directly correlate them with system performance metrics.
For example, a performance drop observed in an API call can be linked to a potential security flaw and presented to the analyst through a unified interface.
This approach goes beyond traditional SIEM capabilities, strengthening the integration of “observability + security” in a seamless and intelligent way.
Data Access and Cost Efficiency: Cisco Firewall Log Integration
Another major development announced after .conf25 is the enhanced log-sharing integration between Splunk and Cisco.
Under the new licensing model, logs from Cisco security devices, especially Cisco Secure Firewall, can be transmitted to Splunk via a free or low-cost data pipeline.
This creates a significant improvement in security visibility. Data sources that were previously excluded due to log volume constraints can now be actively utilized within the SOC.
As a result, more comprehensive correlation, more accurate threat detection, and lower-cost security monitoring become achievable.
The central theme of .conf25 revolves around a vision of “not just seeing data but deriving meaning from it.” Under the Cisco umbrella, Splunk is placing artificial intelligence at the heart of operational intelligence.
Key Innovations:
The common thread across these innovations is Splunk’s vision to transform data-centric analytics into “learning systems.”
Splunk is no longer just a system that tells you what happened, it’s a platform that understands why it happened and recommends what to do next.