AI Assistant improvements
Release notes for Splunk Enterprise Security
What's new in 8.2.1
- Splunk Enterprise Security version 8.2.1 was released on September 17, 2025 and includes the following new enhancements:
- AI Assistant improvements: You can now use the AI Assistant to summarize individual findings in the analyst queue. For details, see Summarize findings with the AI Assistant.
You can also choose between Frontier or Splunk-hosted models for the AI Assistant to use based on your organization's compliance requirements. See Choose which models the AI Assistant uses. - Hybrid pairing with Splunk SOAR: You can now pair Enterprise Security (Cloud) with a single Splunk SOAR (On-premises) instance. For details, see Splunk SOAR compatibilitylater in the release notes and Pair Splunk Enterprise Security with Splunk SOAR.
Splunk Enterprise Security 8.2.1 fixed issues
- BLUERIDGE-19064 : Detections with use_index_time should not run all time searches
- BLUERIDGE-18821 : Incorrect Risk Object Count for a Multiple Finding