Scheduled Searches and Alerts That Satisfy Continuous Monitoring

New to how Splunk fits into compliance work? Start with How Splunk Supports Cybersecurity Evidence. Most people in federal IT have written “continuous monitoring” into a security plan before they have actually built anything that monitors continuously. So what turns a ConMon strategy from a paragraph in a document into something an assessor can verify, and what does Splunk actually need to be doing for that to hold up? The Gap Between the Policy and the Platform NIST SP 800-137 describes an Information Security Continuous Monitoring program as an ongoing awareness of risk, vulnerabilities, and threats. DoDI 8510.01 expects that awareness to feed the authorization decision on a continuing basis, not just at the three-year reassessment. The document usually gets written first. The searches that are supposed to produce that awareness get written later, if at all, and often only after an assessor asks to see one running. ...

July 11, 2026 · 5 min · Carlos Henry

How Splunk Supports Cybersecurity Evidence

Wondering how technical output turns into compliance documentation? Start with How ACAS Findings Become Remediation Evidence. Most people in federal IT have watched a Splunk dashboard scroll across a SOC monitor long before anyone explained what it has to do with an authorization. Splunk shows up in job postings next to RMF and eMASS, it gets name-dropped in continuous monitoring meetings, and it sits on the big screen during every assessment walkthrough. What rarely gets explained is why an assessor cares about a search tool at all – and why “we have Splunk” has never answered a single control question. ...

July 6, 2026 · 7 min · Carlos Henry