# Cisco brings Splunk AI on premises, expands agent observability, monitors token costs

> Source: <https://www.networkworld.com/article/4222333/cisco-brings-splunk-ai-on-premises-expands-agent-observability-monitors-token-costs.html>
> Published: 2026-09-15 18:02:53+00:00

Cisco is expanding [Splunk’s AI capabilities](https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m09/cisco-delivers-trusted-ai-at-scale-through-new-splunk-advancements.html) to self-managed environments and adding [observability tools](https://www.networkworld.com/article/4222273/highlights-from-splunk-conf26-and-what-the-news-means-to-network-engineers.html) designed to help enterprise IT teams monitor AI agents, control token costs, and troubleshoot problems across applications and networks.

Announced at [Splunk’s .conf26](https://conf.splunk.com/) this week, the updates include Cisco AI POD for Splunk, which brings Splunk AI capabilities to on-premises and air-gapped environments. Cisco also expanded Splunk Agent Observability with Tokenomics and introduced Observability Studio and a Network Intelligence App.

The products target challenges enterprises face as they move [AI agents into production](https://www.networkworld.com/article/3957285/ai-agents-vs-agentic-ai-what-do-enterprises-want.html), where IT teams need to know whether agents are behaving as expected, how much they cost to run, and how they affect infrastructure and applications.

Cisco executives said during a press briefing that AI agents are operating across data centers, campuses, and branches, and interacting with enterprise resources and other agents. For example, if an agent deletes thousands of files, IT teams need to determine whether it malfunctioned or was compromised.

Aimed at enterprises that need to keep sensitive machine data within their own environments, Cisco AI POD for Splunk “brings Splunk AI to on-premises customers with new AI runtime software, Cisco infrastructure, Nvidia accelerated computing, and Kubernetes-based architecture, pre-validated and optimized for Splunk AI workloads,” according to Cisco.

“One of the biggest roadblocks to enterprise AI today is that it’s too hard to deploy,” said Jeetu Patel, Cisco’s president and chief product officer, in a [statement](https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m09/cisco-delivers-trusted-ai-at-scale-through-new-splunk-advancements.html). “Customers want to know: Can I trust it to do the job? Can I afford it? And, most importantly, can I secure it? By running Splunk AI on the infrastructure customers already trust, they can move faster to put AI to work in their business with confidence and control.”

The on-premises option could be important for enterprises that need tighter control over corporate data, according to Bob Laliberte, principal analyst and founder at Liberte Research Group.

“This is great news for organizations that require on-premises solutions due to privacy or sovereignty demands,” Laliberte says.

Cisco is also expanding Splunk Agent Observability, which monitors the AI stack, including GPUs, vector databases, memory, and orchestration frameworks, while evaluating agent output and behavior.

Enterprises can assess agent quality and accuracy and apply runtime guardrails intended to block hallucinations, prompt injection, and other unwanted behavior. “It will be imperative for organizations to be able to observe agent behavior and report when it deviates from prescribed guardrails,” Laliberte says.

Agent observability can also help enterprises evaluate agents’ effectiveness, identify where additional training or refinement is needed, and determine when tasks should be handed to humans, he says.

Cisco is also targeting AI token consumption with Tokenomics. This capability tracks and attributes AI token spending and employee use of AI coding agents in real time, according to Splunk. It can help organizations understand costs, route workloads to more cost-effective models, and forecast consumption before a billing period ends.

“Just like the cloud rush, many organizations have learned that tokenmaxxing is budget-depleting,” Laliberte says, adding that understanding token usage and costs across different models is becoming increasingly important.

For network operations teams, Cisco introduced a Network Intelligence App that brings Cisco network topology, device health, and events into Splunk.

The integration targets a troubleshooting problem: application, infrastructure, and network teams often use separate tools and have different views of the same incident. The app lets teams access network information alongside other Splunk telemetry and trace an alert to the associated device and surrounding network without leaving Splunk.

Splunk Observability Studio moves observability earlier in application development by building [OpenTelemetry instrumentation](https://www.networkworld.com/article/3952892/splunk-launches-inventory-tool-to-simplify-opentelemetry-monitoring.html) into development workflows rather than adding it after applications are deployed. Cisco says guided workflows can reduce instrumentation from hours to seconds or minutes.

Building observability into applications from the beginning rather than bolting it on later should improve efficiency and be considered a best practice for new applications, Laliberte says.

“Great to see the progress from last year’s visionary announcements to real capabilities being delivered and improved on over the last 12 months,” he says.

Cisco AI POD for Splunk and Splunk AI Assistant are available now. Agent Launchpad, which will let customers build custom agents within Splunk, is expected later this year. Splunk Agent Observability is now available in Splunk Observability Cloud and Cisco Cloud Control.
