An interactive, customer-friendly read-ahead for understanding what becomes available—and what preparation is required—across Splunk Platform, Splunk Enterprise Security, Splunk IT Service Intelligence, and Splunk Observability Cloud.
Choose a product first, then select its deployment context, current release, and destination. The explorer builds a tailored view of:
- Product-aware release journeys for Splunk Platform, Enterprise Security, ITSI, and Observability Cloud
- Supported Splunk Enterprise step-upgrade paths
- Splunk Cloud Platform capability milestones
- Enterprise-to-Cloud readiness gates and migration approaches
- Enterprise Security and ITSI compatibility checks against the selected Splunk platform line
- A direct platform-upgrade route when the selected premium-product target requires Splunk Enterprise to move first
- Dated Observability Cloud milestones with separate OpenTelemetry Collector and instrumentation prerequisites
- Version-aware Splunk Cloud Migration Assessment App (SCMA) guidance
- New features grouped by customer outcome
- A collapsed, route-specific technical delta covering runtimes, data stores, protocols, cryptography, host requirements, APIs, permissions, and operating-model changes
- A dedicated, route-aware view of potential breaking changes, migration blockers, and delay risks
- Release-specific validation work and planning considerations
- Direct links to the relevant official Splunk documentation
- Shareable report URLs that preserve the selected journey and releases
- A print-optimized report that can be saved as PDF from the browser
- Read-only WebMCP tools for agents to discover supported releases and retrieve cited comparisons from the same data
No registration, lead form, subscription, or customer information is collected.
| Platform | Included releases |
|---|---|
| Splunk Enterprise | 8.1 through 10.4 |
| Splunk Cloud Platform | 9.2.2406 through 10.5.2605 |
| Enterprise → Cloud | Enterprise 8.1–10.4 to Cloud 9.2.2406–10.5.2605 |
| Splunk Enterprise Security | 7.3 through 8.7 |
| Splunk IT Service Intelligence | 4.15 through 5.0.2 |
| Splunk Observability Cloud | Dated milestones from November 2024 through September 2026 |
The platform content is organized around five value themes: Search & AI, Platform Operations, Data Management, Security & Compliance, and Dashboards & Experience. Product-specific themes are added for security operations, service intelligence, and observability. A separate technical layer explains the documented before-and-after state, why it matters, and the recommended action without treating every component change as a breaking change. Enterprise-to-Cloud recommendations cover mobilization, assessment, migration-motion selection, app and data preparation, connectivity, access, acceptance testing, cutover, and retirement.
The September 2026 Observability milestone includes the September 23 APM, RUM, Synthetics private-runner, Observability Logs, detector, and Cloud-connected trial announcements alongside customer-managed component guidance through standalone Splunk OpenTelemetry Collector 0.161.0, Kubernetes chart 0.161.0 (which packages Collector 0.161.0), .NET instrumentation 1.16.0, Node.js instrumentation 4.12.0, Java instrumentation 2.31.3, and Browser RUM 3.2. Detector Optimization remains Controlled Availability and never applies recommendations automatically. Browser RUM 3.1's changed defaults remain part of the readiness record; 3.2 keeps the old spaMetrics key as a deprecated alias while new configuration uses navigationMetrics. These versioned components remain distinct from the rolling Observability Cloud service milestone. The timeline's scoped reference to a Splunk Cloud Platform 10.6 free-edition flow does not create a 10.6 platform route: the current Cloud release-note and service-details sources still identify the 10.5 line.
Splunk Enterprise 10.4 comparisons identify 10.4.4 as the current maintenance target and retain 10.4.3 as the documented minimum. Splunk advises against 10.4.2 because acknowledged tcpout forwarding can block; the selector remains at the supported 10.4 release-line level while the report separates the current patch from the safety floor.
See docs/product-tracks.md for the premium-product and Observability model, docs/technical-changes.md for the technical-delta content model, and docs/enterprise-to-cloud.md for the migration guidance model, source map, and maintenance notes.
Material changes and published maintenance outcomes are summarized by Eastern date in docs/releases. Each daily note records what changed, why it matters, authoritative sources, and publication status. Outcome-only entries do not advance factual review dates or content-change cycles.
Version Compass is maintained through four scheduled reviews running in Codex:
- A daily release watch checks for newly published versions, maintenance releases, security notices, compatibility changes, and customer-managed component updates.
- A dedicated daily ES editions watch reviews Essentials/Premier capabilities, prerequisites, licensing qualifications, and source questions.
- A dedicated daily CSP/FedRAMP watch checks hosting regions, service differences, and separate Moderate/High evidence.
- A twice-weekly guidance audit rechecks upgrade paths, platform dependencies, recommended actions, citations, links, and report behavior.
When authoritative evidence clearly supports a change, the maintenance workflow updates the relevant site content and documentation, validates representative journeys, commits the reviewed change, and republishes versioncompass.com. If the evidence is ambiguous, conflicting, incomplete, or would require an unsupported inference, publication stops and the item is held for human review. A factual no-change review publishes only its bounded operational outcome; it does not advance factual review dates, lifecycle dates, or content-change cycles.
Maintenance validation also covers the shared WebMCP comparison contract and its citations; uncertain findings remain subject to the same human-review stop.
Published maintenance changes are recorded in the daily release notes. See Scheduled maintenance for the review cadence, evidence standards, publication safeguards, and conceptual guidance for adapting the approach.
Cloud, migration, Observability, and ES Editions views offer independent hosting-provider, region, and Commercial/FR-M/FR-H filters. Source-backed differences appear in the page, shared links, and reports; unknown or conflicting evidence remains explicit. Current service evidence is separate from historical release availability and product compatibility. See Cloud environments for coverage, limitations, and the maintenance model.
Open Version Compass in a WebMCP-capable browser to let an agent list supported releases, compare up to five routes, or read the current report. Results include compatibility warnings, technical changes, readiness work, official citations, review metadata, and shareable links. The tools use the same data and comparison logic as the interface, so scheduled content updates reach both.
This is browser-scoped WebMCP; the site does not expose a standalone remote MCP server endpoint. See docs/webmcp.md for tool names, input examples, limitations, and validation.
Platform and Enterprise-to-Cloud content is centralized in dist/data.js. Premium-product and Observability content lives in dist/product-data.js. To extend the explorer:
- Add the release identifier to the platform's
releasesarray. - Add its date, official release-note URL, notable capabilities, technical changes, and readiness requirements under
releasesData. Set the optional fifth requirement value totruewhen the official source identifies a potential breaking or material behavior change. - For Splunk Enterprise, add supported transitions to the
edgesupgrade-path map. - For Enterprise Security or ITSI, reconcile the official product compatibility matrix at the maintenance-release level and update the simplified platform-line mapping. Recheck the current Cloud service pairing separately.
- For Observability Cloud, add a dated service milestone and keep versioned Collector, Kubernetes chart, instrumentation, and semantic-convention dependencies distinct from rolling SaaS availability.
- Update the applicable
latestvalue, the reviewed date, and the reviewed badge's direct link to that date's release note indist/index.html.
Each technicalChanges record identifies the component or contract, technical area, change type, action level, documented before-and-after state, implication, recommended action, and official source. Preserve important scope distinctions such as bundled versus app-owned, default versus optional, deprecated versus removed, and platform-managed versus customer-managed.
Enterprise-to-Cloud content is kept in the top-level migration object. It contains the SCMA compatibility floor, official source links, operating-model benefits, migration approaches, technical operating-model changes, potential breaking changes, and recommended actions. When the latest Cloud destination changes, review both the Cloud release record and migration defaults.
Enterprise Security remains the security-product route even as Splunk expands integrated SIEM, SOAR, UEBA, threat-intelligence, exposure, and AI capabilities. These should be described with their documented edition, deployment, entitlement, and availability boundaries instead of being presented as universally included or as separate top-level version lines without an official version contract.
The selectors, path visualization, metrics, filters, capability cards, collapsed technical delta, breaking-change report, readiness guidance, citations, and shareable URL are generated automatically from that data. The Print / save PDF action temporarily includes every value category, expands the technical detail, and uses the browser's native print dialog to create a portable report without sending data to a server.
Updates, corrections, and improvements are encouraged—especially:
- New Splunk Platform, Enterprise Security, and ITSI releases, plus Observability Cloud milestones
- Corrected upgrade paths or readiness requirements
- Corrected platform-to-premium-product compatibility or Cloud-managed availability guidance
- Improved Enterprise-to-Cloud assessment, preparation, validation, or cutover guidance
- Additional source-backed technical transitions and clearer implementation actions
- Additional customer-value context backed by official documentation
- Accessibility, responsive-design, and usability improvements
- Clearer language for customer-facing read-aheads
Open an issue to discuss an idea or submit a pull request with the proposed change. Please keep factual additions traceable to official Splunk documentation. Preserve the distinction between customer-managed Enterprise upgrades, Splunk-managed Cloud releases, and an Enterprise-to-Cloud migration program whose final sequence depends on the customer's environment.
See CONTRIBUTING.md for the content model, workflow, and review checklist.
This is a dependency-free static site. Serve the repository root with any local HTTP server and open /dist/:
python -m http.server 8000Then visit http://localhost:8000/dist/.
The explorer summarizes official Splunk documentation, Splunk Lantern migration guidance, and the supplied product-innovation timeline. It is a planning aid—not a substitute for release notes, compatibility guidance, a Statement of Work, or an environment-specific upgrade or migration plan.
Version Compass is independently developed. It is not affiliated with, sponsored by, endorsed by, or an official product of Cisco or Splunk. Splunk is a Cisco company, and Splunk and related marks are the property of Cisco and/or its affiliates.
Released under the MIT License. This license covers the project source and original project content; third-party names, trademarks, and linked documentation remain the property of their respective owners.
Reports include a cited route takeaway and expandable support lifecycle context. Older valid URLs preserve comparisons and explain relevant changes; unrecognized routes require review. New links carry the guidance review date. See report guidance for behavior and maintenance.
Compare ES Essentials and Premier, including public-source capability scope, deployment requirements, source questions and a printable report. The older preview links remain compatible.
Agent task guides are checked alongside the aggregate compatibility table. Where minimum versions or pricing eligibility differ, the comparison preserves both cited statements rather than certifying a lower baseline or universal commercial entitlement. See the September 23 evidence review.

