What's new

Learn about what's new in this release of Splunk Cloud Platform.

This page summarizes the new features and enhancements in each release of Splunk Cloud Platform. Use the Version drop-down list to see information for other versions of Splunk Cloud Platform.

The product features deployed in your environment might vary depending on your topology, deployment type, and configuration settings.

Also discover what's new in the following features of Splunk Cloud Platform:

Version 10.6

Learn about what's new in this release of Splunk Cloud Platform.

New feature, enhancement, or change Description

Splunk support for $8$ encryption

Splunk is migrating to a a new FIPS-compliant implementation, $8$, that uses independently-derived, high-entropy keys.

The Splunk CLI includes a migration tool to assist customers with migration to $8$:

  • splunk reencrypt secrets
  • splunk reencrypt shcluster-secrets

Note that this command will only operate on non-$8$ values so re-running it on previously-migrated keys is a no-op.

Splunk Enterprise customers have access to these fixes starting with Splunk 10.6. Splunk Cloud will be addressed in the next minor release.

Improved security of Splunk to Splunk connections for Federated Search for Splunk

Federated Search for Splunk now verifies and validates connections between federated and remote search heads. This update enables an automated exchange of capabilities, allowing search heads to optimize performance and ensure searches run efficiently. By proactively confirming compatibility, this feature significantly increases the overall stability and reliability of your distributed search environment.

NOTE: With this change, federated searches will fail if any remote search head is running a version lower than Splunk Enterprise 10.4 after upgrade. If you use Federated Search for Splunk, upgrade all remote search heads to Splunk Enterprise version 10.4 or higher before upgrading your deployment. See About upgrading to 10.6 READ THIS FIRST.

Secure Forwarder Bootstrap with Uniquely Identifiable Certificates

Universal Forwarders can now securely acquire a unique TLS certificate in support of secure communication and mTLS. ​Configure autoCertRotation = true in outputs.conf to enable this functionality.

Predefined schema templates for Federated Search for Amazon S3

Predefined Schema Templates provide customer-selectable AWS CloudTrail Log and VPC Flow Log schemas for the creation of Amazon S3 federated datasets. They reduce manual schema entry and improve onboarding consistency for common AWS log sources.

See Create an Amazon S3 dataset for federated search that is backed by a Splunk-native data catalog in Federated Search.

Enterprise Managed Encryption Keys (EMEK) support for DDAA on GCP

Splunk Cloud Platform now supports customer-managed encryption key onboarding for GCP stacks that use Dynamic Data Active Archive (DDAA). During onboarding, existing archived DDAA receipts are rotated to the customer-managed GCP KMS key. Archived data objects are not re-encrypted, and archive and restore behavior is unchanged.

Universal Forwarder Certification on Splunk 10.6

Universal Forwarder is certified on Splunk Enterprise 10.6 and Splunk Cloud 10.6.

Fewer app management operations require Splunk platform restarts.

Due to internal improvements in our app management tooling, app uninstall operations are ~50% less likely to require Splunk platform restarts. After upgrading to Splunk platform version 10.6, Splunk Cloud customers will have this feature incrementally enabled or can reach out to Splunk Support for scheduling. Splunk Enterprise customers can enable this feature by updating the limits.conf stanza [reload_on_delete] to disabled = false. Note that the feature can be rolled back by setting disabled = true. Enabling or disabling this feature requires a Splunk platform restart.

Identity enablement in support of AI Canvas and Cisco Cloud Control CA

In order to onboard customers to participate in the AI Canvas CA and Cisco Cloud Control (C3) CA, missing customer data will be collected.   After that is done, the Cloud Control and AI Canvas experience, once customers are approved for access, will be supported through secure identity integration and Splunk RBAC enforcement. Customers will have access to login to Cisco Cloud Control through Splunk, they will be able to cross launch between Splunk and Cisco Cloud Control without additional authentication, and they will be able to use the products within Cisco Cloud Control that are integrated with Splunk (linked) in a secure manner.

Cisco Unified AI Assistant (interim double assistant)

Give Splunk customers using Cloud Control the ability to access the Cisco Unified AI Assistant (UAIA) or Splunk Assistants from a single entry point.

SCIM-based user deprovisioning for Entra ID Customers - CA

This feature lets customers using Entra ID for SAML authentication configure their Splunk search head to use SCIM to automatically remove SAML users when the user is deleted from Entra ID or loses Splunk access.

Modern Navigation with Cloud Control

Cloud Control customers can seamlessly navigate between Splunk and other Cisco products while getting the full power of Cloud Control capabilities.

Removal of Client Authentication Extended Key Usage (EKU) from Public TLS Certificates

To enhance security and comply with industry changes, the Client Authentication Extended Key Usage (EKU) has been removed from Public TLS Certificates. Detailed guidance is available on Splunk Help.

Integrated Enterprise Value

Deliver Integrated Enterprise Value reporting that gives customers clear visibility into Cisco data consumption, weighted usage, and remaining entitlement across Ingest in CMC and MC.

Splunk Enterprise Versioning Change

Starting with Splunk Enterprise and Splunk Cloud Platform release 10.6, Splunk introduces a unified four-segment version format (Major.Minor.Maintenance.Patch, e.g., 10.6.0.3) across Splunk Cloud and customer-managed platform builds to provide consistent and transparent release tracking. This update does not alter standard Splunk Cloud operations, service consumption, or deployment schedules. Customers utilizing custom scripts, CMDB integrations, or automated tooling that parse Splunk version strings should verify compatibility with the four-segment format.

Deprecation of Custom Visualizations support in Classic dashboards

A new custom visualizations framework is supported in Dashboard Studio that provides a modernized and secure method for customers to use third party custom visualizations in their dashboards. Therefore, Splunk is deprecating support for custom visualizations in Classic dashboards. Users should migrate dashboards which require custom visualizations to Dashboard Studio.

Removal of Splunk Analytics Workspace

Splunk has removed Analytics Workspace. Any alerts configured in Analytics Workspace will continue to work. You can create metrics searches and charts in Splunk Search and Dashboards.

Log Essentials in Splunk Observability Cloud

Log Essentials in Splunk Observability Cloud is a low-cost, observability-native logs offering for greenfield customers. Its MVP combines a streamlined Splunk Cloud Lite stack, a native logs experience inside Splunk Observability Cloud, and a Unified Identity model with centralized RBAC and data-level access control, where Splunk Cloud acts as the identity provider for Observability Cloud.

Search-time field extraction and knowledge object discovery for Federated Search for DDSS

This feature allows federated searches of DDSS datasets to return extracted fields and knowledge objects such as field aliases, calculated fields, event types, and tags in a way that feels closer to familiar Splunk index search. Customers can reuse existing Splunk field knowledge for supported source types and datasets, reducing manual setup and making federated investigations more predictable and easier to trust.

See Activate knowledge object discovery for federated searches of DDSS datasets in Federated Search.

Federated Search for Cisco Security Analytics and Logging (SAL)

Federated Search for Cisco Security Analytics and Logging (SAL) brings Cisco SAL data into the standard Federation search model, allowing Cisco Security Analytics Lake customers to access data from the Splunk analytics plane for a 360-degree security visibility posture.

See About Federated Search for Cisco Security Analytics and Logging in Federated Search.

Federated Search for 3rd party data sources - Schema Inference Review & Editing

Federated Search Schema Inference Review and Editing lets admins validate and correct inferred schema and partitions for Amazon S3, Microsoft Azure, and DDSS federated datasets before they are broadly used. This makes setup easier, improves trust in field behavior, and helps customers turn routed or discovered data into searchable datasets without redefining schema and partitions from scratch.

For an Amazon S3 federated search example, see Review the crawler-discovered schema and partitions for an Amazon S3 dataset in Federated Search.

Federated Search for AWS S3 (Legacy) EOL

Federated Search for AWS S3 (Legacy) EOL retires the older S3 federation path and moves customers toward the modern Federated Search 2.x architecture. This gives customers a clearer S3 search-in-place story, a supported migration path, and a more consistent experience across Federation setup, search, governance, and support.

Federated Search for AWS CloudWatch Unified Data Store

Federated Search for AWS CloudWatch Unified Data Store lets customers use Splunk analytics on CloudWatch Lake data without first moving all of that data into Splunk. AWS-centered security teams can investigate, hunt, and analyze AWS telemetry through a familiar Splunk workflow while preserving the data gravity and marketplace motion of the AWS environment.

See About Federated Search for CloudWatch Unified Data Store in Federated Search.

mTLS Support for Federated Search for Splunk - Hybrid Model

mTLS is now supported for customers using Federated Search for Splunk - Hybrid Model. Customers are now able to install a client certificate on their Splunk Cloud stack for this feature to function. File a Splunk Support case to update this configuration.

Cisco AI Canvas + Splunk Cloud Platform Integration (GA)

Cisco AI Canvas is a multiplayer, generative workspace for IT operations that brings together cross-domain telemetry, teams, and AI agents in one synchronized environment. Splunk Cloud Platform is integrated with AI Canvas, enabling customers to correlate log and event with data from across their Cisco environment, using natural language to generate SPL for investigations.

Start a Splunk Observability Cloud free trial from Splunk Cloud Platform

In Splunk Cloud Platform 10.6, you can request and set up a free Splunk Observability Cloud trial directly from your Splunk Cloud Platform environment.

This release includes the following enhancements:

  • Self-service trial provisioning: If you have the sc_admin role, you can use the Splunk Observability Cloud app to request and provision a Splunk Observability Cloud trial organization.

  • Automated log discovery: After you access Splunk Observability Cloud, you are guided through an interactive Log Discovery view that enumerates paired Splunk Cloud indexes and identifies OpenTelemetry (OTel) compliant log sources.

See Get Free Edition from Splunk Cloud Platform.

Data Management Service Cloud API

The Data Management Service Cloud API enables programmatic management of Edge Processor configuration and instance inventory, onboarding and offboarding script generation, shared settings, destination discovery, SPL2 pipeline definitions and lifecycle operations for Edge Processor and Ingest Processor runtimes, and sourcetype synchronization. Before creating the first Edge Processor pipeline through the API, initialize the tenant’s pipelines workspace in the Splunk Data Management UI.

For more information, see Data Management Service API - Splunk Cloud Platform

Updates to Splunk AI Assistant on Search page

The Splunk AI Assistant is seamlessly integrated into the Search & Reporting experience and brings the latest AI-agentic-powered capabilities directly into your search workflow, including support for SPL2 search authoring. The AI Assistant also helps you create SPL2 searches for Federated Search and MDL datasets.

TLS 1.0 and TLS 1.1 removal

The Splunk platform no longer supports TLS 1.0 or TLS 1.1 protocols. Please ensure you are migrated to TSL 1.2 or TLS 1.3.

GA feature: Field filters for the Splunk platform are now generally available and on by default to protect sensitive fields in search time results

To protect your personal identifiable information (PII) and protected health information (PHI) data, and meet data privacy requirements such as General Data Protection Regulation (GDPR) or other privacy regulations, you can use field filters in the Splunk platform to limit access to your sensitive data. Field filters let you limit access to confidential information by redacting or obfuscating fields in events within searches, with optional role-based exemptions. For more information about field filters, see Protect PII, PHI, and other sensitive data with field filters and Plan for field filters in your organization.

READ THIS FIRST: Should you deploy field filters in your organization? Field filters are a powerful tool that can help many organizations protect their sensitive fields from prying eyes, but field filters might not be a good fit for every deployment.

If your organization uses downstream configurations, such as accelerated data models, Splunk Enterprise Security (ES) detections using those data models, or user-level search-time field extractions, ensure you sufficiently plan for your field filter use cases on those configurations before deploying field filters in your environment. See READ THIS: Downstream impact of field filters.

If your organization runs Splunk Enterprise Security or if your users rely heavily on commands that field filters restricts by default (mpreview and mstats), do not use field filters in production until you have thoroughly planned how you will work around these restricted commands. See READ THIS: Restricted commands do not work in searches on indexes that have field filters.