Enhancing Threat Hunting with Splunk and Generative AI forAutomated Security Operations | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Enhancing Threat Hunting with Splunk and Generative AI forAutomated Security Operations Rishikesh Sahay, Manjusha Sumasadan, Bell Eapen, Weizhi Meng, and 1 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-7515771/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Nowadays, organizations are increasingly challenged by the need to detect and mitigate cybersecurity incidents in real time, given the surge in both the volume and sophistication of cyber attacks.Proactive threat hunting has become essential, yet SOC (Security Operations Center) analysts often struggle to analyze the huge volume of logs generated by numerous devices in organizations.Thanks to a Security Information and Event Management (SIEM) tools like Splunk, which provides a centralized, real-time log analysis to support threat detection and response.However, the heavy dependency on skilled human resources to analyze the large volume of logs remains a significant challenge.The labor intensive repetitive task of log analysis leads to alert fatigue to SOC analysts and reducing operational effectiveness.The recent advancements in Generative AI, particularly Large Language Models (LLMs), has offered a solution to address these challenges.The integration of LLM into the SIEM workflow can automate the analysis process, reducing manual tasks, and improving the threat detection process. In this paper, we propose a novel threat hunting framework that leverages LLM insights to analyze logs using a SIEM tool such as Splunk to improve security operations.Moreover, the framework uses cyber threat intelligence tools like Maltego to enrich and validate identified threat indicators, therefore providing actionable and context-rich insights.The framework demonstrates that the integration of LLM with SIEM and CTI tools improves the effectiveness of the threat-hunting process to detect the signs of intrusions. Threat hunting Splunk Security Operation Center LLM CTI Maltego Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-7515771","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":528041633,"identity":"33a653a9-4d9a-457f-8dc5-a1e85aacf11b","order_by":0,"name":"Rishikesh Sahay","email":"","orcid":"","institution":"University of Illinois at Springfield","correspondingAuthor":false,"prefix":"","firstName":"Rishikesh","middleName":"","lastName":"Sahay","suffix":""},{"id":528041634,"identity":"73116eef-4362-4550-9d09-a89dcef61409","order_by":1,"name":"Manjusha Sumasadan","email":"","orcid":"","institution":"University of Illinois at Springfield","correspondingAuthor":false,"prefix":"","firstName":"Manjusha","middleName":"","lastName":"Sumasadan","suffix":""},{"id":528041635,"identity":"05fcd2ac-1ce0-46e5-b74a-00fb10688e2f","order_by":2,"name":"Bell Eapen","email":"","orcid":"","institution":"University of Illinois at Springfield","correspondingAuthor":false,"prefix":"","firstName":"Bell","middleName":"","lastName":"Eapen","suffix":""},{"id":528041637,"identity":"04b05299-2f9b-42a2-b780-da5d067686de","order_by":3,"name":"Weizhi Meng","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA+ElEQVRIiWNgGAWjYPCCGjk+NJEEQlqOGbNBGAZEa2FObCNai8EB7sTHBb/Y0tvYzx788OPPHznzBuaHHxjb0vBo4d1sPLNPJreNJy9ZsrfNwFjmAJuxBGNbDk4tZgd4t0nz9rDltjHkmDHwNhgkzgAKMjC2VeDTsv03bw9zOhv/GzPGP38M6mcwsH8jpGUbM88P5gQ2iRwzZh42gwQJBh6QLbgdZn+Yd7M0b8MxwzaJN8bSsm3GhjOYeYolEs7h9r5ke+/Gzzx/auT5+XMMP775Iycvwd6+8cOHsmScWhiYgZixDV0kAbcGKPhDUMUoGAWjYBSMZAAAeh9IlScHx6wAAAAASUVORK5CYII=","orcid":"","institution":"Lancaster University","correspondingAuthor":true,"prefix":"","firstName":"Weizhi","middleName":"","lastName":"Meng","suffix":""},{"id":528041638,"identity":"f5c078eb-b254-403a-b398-e29aac2c9045","order_by":4,"name":"Md Rasel Al Mamu","email":"","orcid":"","institution":"University of Illinois at Springfield","correspondingAuthor":false,"prefix":"","firstName":"Md","middleName":"Rasel Al","lastName":"Mamu","suffix":""}],"badges":[],"createdAt":"2025-09-02 09:08:41","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-7515771/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-7515771/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":93444828,"identity":"48b05b6c-d5bb-4fea-b3db-d605117492c6","added_by":"auto","created_at":"2025-10-14 01:19:42","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":3195983,"visible":true,"origin":"","legend":"","description":"","filename":"paper.pdf","url":"https://assets-eu.researchsquare.com/files/rs-7515771/v1/576eeccadba0911881df5bad.pdf"},{"id":93444827,"identity":"58cb4b1f-a3bb-45c7-a61c-adbb200441d4","added_by":"auto","created_at":"2025-10-14 01:19:41","extension":"json","order_by":1,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":6666,"visible":true,"origin":"","legend":"","description":"","filename":"2ef1ade3c0c74f3c85ca7394711f1190.json","url":"https://assets-eu.researchsquare.com/files/rs-7515771/v1/ef19df69a9cadd61910dcabb.json"},{"id":96051289,"identity":"159d7315-583f-49f7-a9c8-525f70cbed87","added_by":"auto","created_at":"2025-11-17 06:40:09","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1341348,"visible":true,"origin":"","legend":"","description":"","filename":"paper.pdf","url":"https://assets-eu.researchsquare.com/files/rs-7515771/v1_covered_f98328f2-6f32-4037-91c1-6d06a2e4ab81.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Enhancing Threat Hunting with Splunk and Generative AI forAutomated Security Operations","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Threat hunting, Splunk, Security Operation Center, LLM, CTI, Maltego","lastPublishedDoi":"10.21203/rs.3.rs-7515771/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-7515771/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"Nowadays, organizations are increasingly challenged by the need to detect and mitigate cybersecurity incidents in real time, given the surge in both the volume and sophistication of cyber attacks.Proactive threat hunting has become essential, yet SOC (Security Operations Center) analysts often struggle to analyze the huge volume of logs generated by numerous devices in organizations.Thanks to a Security Information and Event Management (SIEM) tools like Splunk, which provides a centralized, real-time log analysis to support threat detection and response.However, the heavy dependency on skilled human resources to analyze the large volume of logs remains a significant challenge.The labor intensive repetitive task of log analysis leads to alert fatigue to SOC analysts and reducing operational effectiveness.The recent advancements in Generative AI, particularly Large Language Models (LLMs), has offered a solution to address these challenges.The integration of LLM into the SIEM workflow can automate the analysis process, reducing manual tasks, and improving the threat detection process. In this paper, we propose a novel threat hunting framework that leverages LLM insights to analyze logs using a SIEM tool such as Splunk to improve security operations.Moreover, the framework uses cyber threat intelligence tools like Maltego to enrich and validate identified threat indicators, therefore providing actionable and context-rich insights.The framework demonstrates that the integration of LLM with SIEM and CTI tools improves the effectiveness of the threat-hunting process to detect the signs of intrusions.","manuscriptTitle":"Enhancing Threat Hunting with Splunk and Generative AI forAutomated Security Operations","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-10-14 01:19:37","doi":"10.21203/rs.3.rs-7515771/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"31f5264d-add1-477c-bcad-91e07b2fbc3c","owner":[],"postedDate":"October 14th, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2025-11-17T06:39:45+00:00","versionOfRecord":[],"versionCreatedAt":"2025-10-14 01:19:37","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-7515771","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-7515771","identity":"rs-7515771","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.