Enhancing Threat Hunting with Splunk and Generative AI forAutomated Security Operations

preprint OA: closed
Full text JSON View at publisher

Abstract

Abstract Nowadays, organizations are increasingly challenged by the need to detect and mitigate cybersecurity incidents in real time, given the surge in both the volume and sophistication of cyber attacks.Proactive threat hunting has become essential, yet SOC (Security Operations Center) analysts often struggle to analyze the huge volume of logs generated by numerous devices in organizations.Thanks to a Security Information and Event Management (SIEM) tools like Splunk, which provides a centralized, real-time log analysis to support threat detection and response.However, the heavy dependency on skilled human resources to analyze the large volume of logs remains a significant challenge.The labor intensive repetitive task of log analysis leads to alert fatigue to SOC analysts and reducing operational effectiveness.The recent advancements in Generative AI, particularly Large Language Models (LLMs), has offered a solution to address these challenges.The integration of LLM into the SIEM workflow can automate the analysis process, reducing manual tasks, and improving the threat detection process. In this paper, we propose a novel threat hunting framework that leverages LLM insights to analyze logs using a SIEM tool such as Splunk to improve security operations.Moreover, the framework uses cyber threat intelligence tools like Maltego to enrich and validate identified threat indicators, therefore providing actionable and context-rich insights.The framework demonstrates that the integration of LLM with SIEM and CTI tools improves the effectiveness of the threat-hunting process to detect the signs of intrusions.
Full text 12,271 characters · extracted from preprint-html · click to expand
Enhancing Threat Hunting with Splunk and Generative AI forAutomated Security Operations | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Enhancing Threat Hunting with Splunk and Generative AI forAutomated Security Operations Rishikesh Sahay, Manjusha Sumasadan, Bell Eapen, Weizhi Meng, and 1 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-7515771/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Nowadays, organizations are increasingly challenged by the need to detect and mitigate cybersecurity incidents in real time, given the surge in both the volume and sophistication of cyber attacks.Proactive threat hunting has become essential, yet SOC (Security Operations Center) analysts often struggle to analyze the huge volume of logs generated by numerous devices in organizations.Thanks to a Security Information and Event Management (SIEM) tools like Splunk, which provides a centralized, real-time log analysis to support threat detection and response.However, the heavy dependency on skilled human resources to analyze the large volume of logs remains a significant challenge.The labor intensive repetitive task of log analysis leads to alert fatigue to SOC analysts and reducing operational effectiveness.The recent advancements in Generative AI, particularly Large Language Models (LLMs), has offered a solution to address these challenges.The integration of LLM into the SIEM workflow can automate the analysis process, reducing manual tasks, and improving the threat detection process. In this paper, we propose a novel threat hunting framework that leverages LLM insights to analyze logs using a SIEM tool such as Splunk to improve security operations.Moreover, the framework uses cyber threat intelligence tools like Maltego to enrich and validate identified threat indicators, therefore providing actionable and context-rich insights.The framework demonstrates that the integration of LLM with SIEM and CTI tools improves the effectiveness of the threat-hunting process to detect the signs of intrusions. Threat hunting Splunk Security Operation Center LLM CTI Maltego Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-7515771","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":528041633,"identity":"33a653a9-4d9a-457f-8dc5-a1e85aacf11b","order_by":0,"name":"Rishikesh Sahay","email":"","orcid":"","institution":"University of Illinois at Springfield","correspondingAuthor":false,"prefix":"","firstName":"Rishikesh","middleName":"","lastName":"Sahay","suffix":""},{"id":528041634,"identity":"73116eef-4362-4550-9d09-a89dcef61409","order_by":1,"name":"Manjusha Sumasadan","email":"","orcid":"","institution":"University of Illinois at Springfield","correspondingAuthor":false,"prefix":"","firstName":"Manjusha","middleName":"","lastName":"Sumasadan","suffix":""},{"id":528041635,"identity":"05fcd2ac-1ce0-46e5-b74a-00fb10688e2f","order_by":2,"name":"Bell Eapen","email":"","orcid":"","institution":"University of Illinois at Springfield","correspondingAuthor":false,"prefix":"","firstName":"Bell","middleName":"","lastName":"Eapen","suffix":""},{"id":528041637,"identity":"04b05299-2f9b-42a2-b780-da5d067686de","order_by":3,"name":"Weizhi Meng","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA+ElEQVRIiWNgGAWjYPCCGjk+NJEEQlqOGbNBGAZEa2FObCNai8EB7sTHBb/Y0tvYzx788OPPHznzBuaHHxjb0vBo4d1sPLNPJreNJy9ZsrfNwFjmAJuxBGNbDk4tZgd4t0nz9rDltjHkmDHwNhgkzgAKMjC2VeDTsv03bw9zOhv/GzPGP38M6mcwsH8jpGUbM88P5gQ2iRwzZh42gwQJBh6QLbgdZn+Yd7M0b8MxwzaJN8bSsm3GhjOYeYolEs7h9r5ke+/Gzzx/auT5+XMMP775Iycvwd6+8cOHsmScWhiYgZixDV0kAbcGKPhDUMUoGAWjYBSMZAAAeh9IlScHx6wAAAAASUVORK5CYII=","orcid":"","institution":"Lancaster University","correspondingAuthor":true,"prefix":"","firstName":"Weizhi","middleName":"","lastName":"Meng","suffix":""},{"id":528041638,"identity":"f5c078eb-b254-403a-b398-e29aac2c9045","order_by":4,"name":"Md Rasel Al Mamu","email":"","orcid":"","institution":"University of Illinois at Springfield","correspondingAuthor":false,"prefix":"","firstName":"Md","middleName":"Rasel Al","lastName":"Mamu","suffix":""}],"badges":[],"createdAt":"2025-09-02 09:08:41","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-7515771/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-7515771/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":93444828,"identity":"48b05b6c-d5bb-4fea-b3db-d605117492c6","added_by":"auto","created_at":"2025-10-14 01:19:42","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":3195983,"visible":true,"origin":"","legend":"","description":"","filename":"paper.pdf","url":"https://assets-eu.researchsquare.com/files/rs-7515771/v1/576eeccadba0911881df5bad.pdf"},{"id":93444827,"identity":"58cb4b1f-a3bb-45c7-a61c-adbb200441d4","added_by":"auto","created_at":"2025-10-14 01:19:41","extension":"json","order_by":1,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":6666,"visible":true,"origin":"","legend":"","description":"","filename":"2ef1ade3c0c74f3c85ca7394711f1190.json","url":"https://assets-eu.researchsquare.com/files/rs-7515771/v1/ef19df69a9cadd61910dcabb.json"},{"id":96051289,"identity":"159d7315-583f-49f7-a9c8-525f70cbed87","added_by":"auto","created_at":"2025-11-17 06:40:09","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1341348,"visible":true,"origin":"","legend":"","description":"","filename":"paper.pdf","url":"https://assets-eu.researchsquare.com/files/rs-7515771/v1_covered_f98328f2-6f32-4037-91c1-6d06a2e4ab81.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Enhancing Threat Hunting with Splunk and Generative AI forAutomated Security Operations","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Threat hunting, Splunk, Security Operation Center, LLM, CTI, Maltego","lastPublishedDoi":"10.21203/rs.3.rs-7515771/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-7515771/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"Nowadays, organizations are increasingly challenged by the need to detect and mitigate cybersecurity incidents in real time, given the surge in both the volume and sophistication of cyber attacks.Proactive threat hunting has become essential, yet SOC (Security Operations Center) analysts often struggle to analyze the huge volume of logs generated by numerous devices in organizations.Thanks to a Security Information and Event Management (SIEM) tools like Splunk, which provides a centralized, real-time log analysis to support threat detection and response.However, the heavy dependency on skilled human resources to analyze the large volume of logs remains a significant challenge.The labor intensive repetitive task of log analysis leads to alert fatigue to SOC analysts and reducing operational effectiveness.The recent advancements in Generative AI, particularly Large Language Models (LLMs), has offered a solution to address these challenges.The integration of LLM into the SIEM workflow can automate the analysis process, reducing manual tasks, and improving the threat detection process. In this paper, we propose a novel threat hunting framework that leverages LLM insights to analyze logs using a SIEM tool such as Splunk to improve security operations.Moreover, the framework uses cyber threat intelligence tools like Maltego to enrich and validate identified threat indicators, therefore providing actionable and context-rich insights.The framework demonstrates that the integration of LLM with SIEM and CTI tools improves the effectiveness of the threat-hunting process to detect the signs of intrusions.","manuscriptTitle":"Enhancing Threat Hunting with Splunk and Generative AI forAutomated Security Operations","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-10-14 01:19:37","doi":"10.21203/rs.3.rs-7515771/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"31f5264d-add1-477c-bcad-91e07b2fbc3c","owner":[],"postedDate":"October 14th, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2025-11-17T06:39:45+00:00","versionOfRecord":[],"versionCreatedAt":"2025-10-14 01:19:37","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-7515771","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-7515771","identity":"rs-7515771","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2025) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00