Splunk Core & Enterprise Security — Stakeholder Operating Model
A SABSA-aligned view of how the Splunk platform delivers security outcomes: who uses what,
for which use cases, and how data flows in and out of each platform. Layered by SABSA, navigated by stakeholder.
Telemetry enters via forwarders, is normalised in Splunk Core, enriched and
correlated in Enterprise Security, then drives action for each stakeholder — with
intelligence and response looping back. Click any node to isolate its flows and read its role; toggle the animation
to see data move.
Highlight stakeholderAnimate flow
i
Click a node to inspect
Select any source, platform component, or stakeholder to isolate the flows it participates in and read how it fits the operating model.
Tip: use the stakeholder chips above to trace one audience end-to-end. Toggle off animation to reduce motion.
SABSA layer model mapped to Splunk
Each SABSA layer answers a different question and serves a different audience. Below, every layer is
expressed concretely in Splunk Core and Enterprise Security terms.
SABSA Layer
Splunk Core expression
Enterprise Security expression
Stakeholder operating model
What each audience owns, the questions they ask, and the platform surface they live in day to day.
Use case catalogue
Filter by stakeholder to see the use cases each audience runs, and which platform delivers them.
Filter
Where Core ends and ES begins
A clean platform boundary prevents overlap and tool sprawl. Core is the data and search foundation;
ES is the security analytics and workflow layer that sits on top of it.
Operating principle: if it concerns getting data in, storing it, or
asking arbitrary questions of it, it belongs to Core. If it concerns detecting, prioritising, investigating, or
reporting on security risk, it belongs to ES. ES consumes Core; it never replaces it.
SABSA operating model · Splunk Core & Enterprise Security · Generated as an interactive reference.
SABSA layers: Contextual · Conceptual · Logical · Physical · Component · Operational (Service Management).