What's Happening?
Splunk, a cybersecurity and observability leader based in San Francisco, California, is undergoing significant changes to its Security Orchestration, Automation, and Response (SOAR) platform. Starting with the September 2026 release, Splunk SOAR will
end support for Python 3.9, necessitating a migration of active automation to Python 3.13. This forced rewrite of playbooks is a primary driver for many security teams to re-evaluate their current SOAR solutions. Additionally, Splunk's SOAR capabilities have been repackaged under Cisco, with SOAR and User and Entity Behavior Analytics (UEBA) now integrated into the Enterprise Security Premier edition as of ES 8.2. This means standalone SOAR is no longer offered as a separate product but as a component within a broader bundle, impacting pricing and deployment strategies. These developments are leading organizations to consider alternatives to Splunk SOAR, with various options emerging in the market.
Why It's Important?
These changes to Splunk SOAR carry significant implications for U.S. organizations relying on the platform for their cybersecurity operations. The mandatory migration from Python 3.9 to 3.13 for all active automation playbooks represents a substantial investment of time and resources for security teams. This effort could divert personnel from other critical security tasks, potentially increasing operational costs and introducing new vulnerabilities during the transition period. The repackaging of SOAR under Cisco's Enterprise Security Premier edition also alters the purchasing and licensing model, which may not align with all organizations' existing budgets or infrastructure. Companies that previously used standalone Splunk SOAR will now need to consider a more comprehensive, and potentially more expensive, bundled solution. This shift could lead to a fragmented security landscape for some, as they might seek alternative, more flexible SOAR solutions while retaining other Splunk products. The re-evaluation of SOAR platforms highlights a broader industry trend towards more integrated and AI-driven security operations, pushing organizations to adapt their strategies to maintain robust defense mechanisms against evolving cyber threats.
What's Next?
Organizations currently utilizing Splunk SOAR will need to assess their existing Python 3.9 playbooks and plan for the mandatory migration to Python 3.13 before the September 2026 deadline. This assessment will involve evaluating the effort required for the rewrite and determining whether to undertake the migration or explore alternative SOAR solutions. Many teams are using this juncture to conduct a comprehensive review of their security automation platforms, considering options that offer different architectural models, such as agentic investigation or enhanced workflow automation. Vendors like D3 Morpheus, Tines, Torq, Palo Alto Cortex AgentiX, Swimlane, and Google SecOps SOAR are being considered as alternatives, each offering distinct approaches to security orchestration. The decision will likely hinge on factors such as the desire to maintain a workflow-first approach versus transitioning to an agentic model, integration with existing security ecosystems, and pricing structures. Cisco's continued integration of Splunk products will also influence future developments and support for the platform, requiring organizations to stay informed about the evolving product roadmap.
Beyond the Headlines
The changes to Splunk SOAR underscore a significant evolution in the cybersecurity industry, moving beyond traditional playbook-driven automation towards more intelligent and integrated security operations. The shift towards AI-powered solutions and agentic security models, as demonstrated by the Agentic SOC at Cisco Live Americas 2026, suggests a future where AI assists analysts in making faster, more defensible decisions, rather than replacing human judgment entirely. This transition raises important questions about the future of human-in-the-loop security, the ethical implications of AI in decision-making, and the need for robust governance and auditability in automated security processes. The repackaging of SOAR within broader enterprise security suites also reflects a trend towards consolidation in the cybersecurity market, where vendors aim to offer comprehensive, unified platforms. This could lead to increased vendor lock-in but also potentially more streamlined security management. Ultimately, these developments are pushing organizations to rethink their entire security posture, emphasizing adaptability, continuous learning, and the strategic integration of advanced technologies to combat increasingly sophisticated cyber threats.











