Splunk Enterprise Security Features
Response (5)
Resolution Automation
Diagnose and resolve incidents without the need for human interaction.
Resolution Guidance
Guide users through the resolution process and give specific instructions to remedy individual occurrences.
System Isolation
Cuts off network connection or temporarily inactivate applications until incidents are remedied.
Threat Intelligence
Gathers information related to threats in order to gain further information on remedies.
Incident Investigation
Analyzes incidents, correlates related events, and determines the scope and impact of attacks.
Records (2)
Incident Logs
Information on each incident is stored in databases for user reference and analytics.
Incident Reports
Produces reports detailing trends and vulnerabilities related to their network and infrastructure.
Management (3)
Incident Alerts
Gives alerts when incidents arise. Some responses may be automated, but users will still be informed.
Incident Case Management
Ability to track incidents, tasks, evidence, and investigation progress within a structured case.
Workflow Management
Administrators can organize workflows to guide remedies to specific situations incident types.
Network Management (14)
Activity Monitoring
Documents the actions from endpoints within a network. Alerts users of incidents and abnormal activities and documents the access point.
Asset Management
Keeps records of each network asset and its activity. Discovers new assets accessing the network.
Log Management
Provides security information and stores the data in a secure repository for reference.
Network Monitoring
Tracks and makes accessible data on the health of servers and other network components.
Server Monitoring
Continuously scan servers on a designated network to monitor health and search for any irregularities or failures
File Integrity Monitoring
Validating the integrity of an operating system, application, and files by monitoring for probable changes, tempering, or fraud.
Real-Time Monitoring
Active monitoring of systems, applications, or networks
User Management
Manage user accounts, profiles, roles, permissions, and other details across applications, devices or networks
Endpoint Management
Track status, assign actions, and control access to systems for devices within the organization
Compliance Management
Track and manage adherence to policies for any service, product, process, or supplier
Incident Management
Manage and track all disruptions and incidents
Vulnerability Management
Detect (and block) vulnerabilities and threats in your applications based on vulnerability information
Policy Management
Create, manage, and track policies and procedures within an organization
Event Logs
A chronological record of actions or occurrences within a network, software, or process
Incident Management (4)
Event Management
Alerts users of incidents and allows users to intervene manually or triggers an automated response.
Automated Response
Reduces time spent remedying issues manually. Resolves common network security incidents quickly.
Incident Reporting
Documents cases of abnormal activity and compromised systems.
Real-Time Reporting
Active reporting of data and metrics
Security Intelligence (5)
Threat Intelligence
Stores information related to common threats and how to resolve them once incidents occur.
Vulnerability Assessment
Analyzes your existing network and IT infrastructure to outline access points that can be easily compromised.
Behavioral Analytics
Track and analyse user behavior within a system or network
Data Examination
Allows users to search databases and incident logs to gain insights on vulnerabilities and incidents.
Real-Time Data
Receive data and information in real time
Generative AI (3)
AI Text Generation
Allows users to generate text based on a text prompt.
AI Text Summarization
Condenses long documents or text into a brief summary.
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
Agentic AI - Security Information and Event Management (SIEM) (4)
Autonomous Task Execution
Capability to perform complex tasks without constant human input
Multi-step Planning
Ability to break down and plan multi-step processes
Proactive Assistance
Anticipates needs and offers suggestions without prompting
Decision Making
Makes informed choices based on available data and objectives
Threat Detection & Triage - AI SOC Agents (3)
Anomaly Detection & Correlation
Detect and link suspicious activities across systems in real time.
False‑Positive Suppression
Identify and dismiss non‑threats through intelligent pattern recognition.
AI‑Driven Alert Triage
Reduce noise by automatically evaluating and prioritizing alerts based on risk and context.
Investigation & Enrichment - AI SOC Agents (3)
Autonomous Case Investigation
Investigate alerts end‑to‑end, gathering evidence and building incident timelines.
Contextual Enrichment from Multiple Sources
Enrich cases with data from SIEM, EDR, cloud, identity, and threat‑intel feeds.
Attack Path Mapping
Create visual maps of threat propagation and lateral movement through networks.
InfoSec Experience & Governance - AI SOC Agents (3)
Conversational Analyst Interface
Allow SOC teams to query agents via natural language about ongoing cases.
Manual Feedback Learning Loop
Improve agent performance through adaptive learning from security team corrections.
Explainability & Audit Trail
Provide human‑readable reasoning trails and decision justifications.
Response & Remediation - AI SOC Agents (3)
Mean Time Reduction Metrics
Track and lower MTTD/MTTR/MTTC through autonomous reactions.
Playbook‑Free Dynamic Workflows
Adapt remediation actions without requiring static SOAR playbooks.
Automated Response Execution
Execute predefined or adaptive responses (e.g., isolate endpoints, revoke credentials).
Additional Functionality (43)
SSL Security
Security protocol that ensures secure, encrypted communication over the internet, safeguarding sensitive data from unauthorized access
HIPAA Compliant
Compliant with HIPAA, which sets standards for sensitive patient data protection
API
Application programming interface that allows for integration with other systems/databases
Threat Response
Identifying, analyzing, and mitigating security issues and taking appropriate action to protect systems and data from potential harm
Endpoint Protection
Protect users working remotely and provide secure environments for personal devices to access company programs
Maintenance Scheduling
Schedule predetermined or ad hoc maintenance services and labor requests
Third-Party Integrations
Set up connections to third-party platforms to improve business processes
Security Auditing
Systematic evaluation of the security of a company's overall security system and situation
Application Security
Identify and respond to security threats to developed applications
Encryption
Convert data into a code for security
Network Security
Prevent and monitor unauthorized access, misuse, modification, or denial of a computer network and network-accessible resources
Real-Time Reporting
Active reporting of data and metrics
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Authentication
Verify the identity of users/devices to enable secure access
Financial Data Protection
Anti Virus
Prevents, detects and removes malware
Secure Data Storage
Securely stores data to prevent data loss or breaches
Virus Definition Update
Activity Dashboard
Dashboard to view the status of ongoing processes, identify current incidents and track past activities
VPN
Extend virtual private network over public networks to enable protected information exchange
Audit Trail
A record of all activities within the system, including user access, changes made, etc.
Anti Spam
Techniques to prevent and filter unwanted or unsolicited email spam from reaching a user's inbox
Access Controls/Permissions
Define levels of authorization for access to specific files or systems
Data Visualization
Graphical representation of data
Alerts/Escalation
System alerts about the need to escalate an issue or request
Data Security
Protect sensitive data for digital privacy
Real-Time Notifications
Notifications that are delivered to users as soon as an event occurs
Audit Trail
A record of all activities within the system, including user access, changes made, etc.
Application Security
Identify and respond to security threats to developed applications
Risk Analysis
Analyze potential risks across the organization
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Data Import/Export
Import and export data to and from software applications
Alerts/Notifications
Alerts or notifications of various types such as pop-up messages, sounds, banners, or badges
Prioritization
Arrange tasks based on the level of priority or urgency
Security Auditing
Systematic evaluation of the security of a company's overall security system and situation
Search/Filter
Search and filter data across systems to locate required information by entering keywords or certain criteria
Compliance Tracking
Track and report regulatory data to either internal management or external stakeholders
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
API
Application programming interface that allows for integration with other systems/databases
Third-Party Integrations
Set up connections to third-party platforms to improve business processes
Activity Dashboard
Dashboard to view the status of ongoing processes, identify current incidents and track past activities
Data Visualization
Graphical representation of data
AI/Machine Learning (1)
AI/Machine Learning
Software program that continuously adjusts its behavior based on observed data
Reporting/Analytics (1)
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Endpoint Protection (1)
Endpoint Protection
Protect users working remotely and provide secure environments for personal devices to access company programs
Threat Propagation Visualization (1)
Threat Propagation Visualization
Create visual maps of threat propagation and lateral movement
Performance Metrics (1)
Performance Metrics
A set of indicators that tracks the performance of networks, applications, systems, teams, etc.
Natural Language Security Querying (1)
Natural Language Security Querying
Allow SOC teams to query agents via natural language about ongoing cases
Threat Response (1)
Threat Response
Identifying, analyzing, and mitigating security issues and taking appropriate action to protect systems and data from potential harm
Activity Monitoring (1)
Activity Monitoring
Track and report on everything that happens within the system or network
Network Security (1)
Network Security
Prevent and monitor unauthorized access, misuse, modification, or denial of a computer network and network-accessible resources
Automated Threat Containment (1)
Automated Threat Containment
Execute predefined or adaptive responses (isolate endpoints, revoke credentials)
Intelligent Alert Noise Reduction (1)
Intelligent Alert Noise Reduction
Identify and dismiss non-threats through intelligent pattern recognition
Explainable AI (XAI) Audit Trail (1)
Explainable AI (XAI) Audit Trail
Provide human-readable reasoning trails and decision justifications
Predefined Protocols (1)
Predefined Protocols
Use pre-defined security protocols to conduct investigations tailored to different threat types




