Splunk

Splunk v10 Remote Upgrader

Introduction Here is a quick review of the Remote Upgrader Feature provided with the brand new Splunk version 10, that was released in July. This new feature allows you to upgrade (or downgrade) your Agents distributed across your Splunk infrastructure managed by your Agent Management server, formerly known as Deployment Server. Limitations There are not […]

Splunk v10 Edge Processor

Introduction Splunk 10 was released on July 28, 2025. One of the main new feature is the Edge Processor. The Edge Processor solution is “a service hosted within your Splunk Enterprise deployment designed to help you manage data ingestion within your network boundaries. Use the Edge Processor solution to filter, mask, and transform your data […]

Splunk ES 8.0.2 – Response Plans & Investigation types

Table of contents Here is a second post about Splunk Enterprise Security 8.0.2, released on January 22nd. This time, I will give you an overview of the Response Plans feature. You can access to Responses Plans by going to Splunk Enterprise Security > Security Content > Response Plans. What Are Response Plans ? The Splunk […]

Splunk ES 8.0.2 – Versioning feature review

Table of contents Splunk Enterprise Security v8.0.2 is out since January, 22nd. I will present to you a new feature introduced in this version: detection versioning. Long awaited, this functionality is interesting in several ways. First of all, in theory, you can avoid using Git or GitLab to keep versions of your detections, as it […]