Splunk Mission Control (introduced in ES 8.0+) is the unified SOC work surface that brings detection, investigation, and response into a single interface. Before Mission Control, analysts juggled separate UIs for ES (detection), SOAR (response), and various investigation tools. Mission Control collapses this into one workflow: an analyst sees a Notable Event, investigates with enriched context, and triggers SOAR playbooks — all without leaving the screen.
For architects, Mission Control changes the design conversation. Instead of architecting three separate tool integrations, the architect designs the Mission Control configuration: which cases are surfaced, how response actions are presented, and how SOAR playbooks are triggered from within the investigation view. The architect also configures the Mission Control alert enrichment pipeline — what context (asset info, threat intel matches, related events) is automatically attached to each case.
SOPs (Standard Operating Procedures) are operationalized inside Mission Control. The architect converts manual analyst runbooks into structured SOP documents that guide analysts step-by-step through Mission Control's interface. This ensures consistent response quality regardless of analyst experience level and provides an audit trail of every action taken during an incident.