Splunk® Enterprise Security Content Update

Release Notes

What's new

Enterprise Security Content Updates version 5.7.0 was released on June 4, 2025 and includes the following enhancements:

Key highlights

ESCU 5.7.0 brings tighter integration with Cisco Security Products and a number of fixes and improvements to existing content:

  • Cisco Secure Firewall Threat Defense Integration: Improved and tested several ESCU detections to work with Event Streamer (eStreamer) data collected by the Cisco Secure Firewall Threat Defense (FTD) platform. For more information about Cisco Secure Firewall, go to the Cisco Secure Firewall site or refer to the Cisco Secure Firewall Threat Defense Analytics analytic story.
  • Bugfixes based on community feedback: Feedback from community members and users continues to be one of the best paths to improve the quality and performance of ESCU content. This release includes a number of bug fixes that reduces false positives and improves the risk entities and fields returned from searches.

New analytics

Updated analytics

Lookups added

  • cisco_secure_firewall_appid_remote_mgmt_and_desktop_tools

Lookups Updated

  • cisco_secure_firewall_filetype_lookup
  • cisco_snort_ids_to_threat_mapping

Other updates

Detections scheduled for removal: For a list of detections that are scheduled to be removed from the ESCU version 5.8.0, see List of detections scheduled for removal in ESCU version 5.8.0.

Last modified on 04 June, 2025
 

This documentation applies to the following versions of Splunk® Enterprise Security Content Update: 5.7.0


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters