# Cisco brings Splunk AI to its own data center and puts a counter on every token

> Source: <https://itdaily.com/news/software/cisco-brings-splunk-ai-to-its-own-data-center-and-adds-a-counter-to-every-token/>
> Published: 2026-09-16 08:46:48+00:00

**At .conf26 in Denver, Cisco is making Splunk AI available to customers who cannot or are not permitted to move their data to the cloud. Simultaneously, a module is being introduced that tracks AI agent consumption in real time.**

Since Cisco [acquired Splunk for 28 billion dollars](https://itdaily.be/nieuws/network/cisco-splunk/), the network manufacturer has been increasingly positioning its machine data platform as a foundation for AI. At the annual .conf26 conference, the emphasis is not on new models, but on trust. “One of the biggest hurdles for AI in enterprises is that it is too difficult to deploy,” says Jeetu Patel, President and Chief Product Officer at Cisco. According to him, customers want to know if they can trust, afford, and secure AI.

Figures from Splunk’s own *Machine Data Outlook* underscore this: 74 percent of respondents say that AI and automation cause moderate to severe data management issues, and 53 percent regularly or always lack the machine data needed for AI to make decisions.

## AI to the data, not the other way around

Those who are not permitted to move sensitive data to the cloud have, until now, been deprived of Splunk AI. Cisco and Nvidia are therefore expanding their collaboration with the Cisco AI POD for Splunk, a pre-validated building block within the Cisco Secure AI Factory with Nvidia. The POD bundles new AI runtime software, Cisco infrastructure, Nvidia accelerators, and a Kubernetes architecture, and is available immediately, including for air-gapped environments. Splunk AI Assistant is already running on it today; Agent Launchpad for building custom agents will follow later this year.

Customers choose for themselves which models they host locally: the Cisco Deep Time Series Model, Google Gemma 4, and OpenAI GPT-OSS 20B, with Nvidia Nemotron coming in the following months. With this, Cisco is following a broader movement where [AI moves to the corporate data instead of the other way around](https://itdaily.com/news/business/cloudera-and-mistral-bring-sovereign-ai-to-enterprise-data/).

## What does that agent cost?

Last year at .conf, Cisco already put [AI agents to work in Splunk Observability](https://itdaily.com/news/cloud/cisco-splunk-ai-observability/). This Agent Observability is now also available in Observability Cloud and in [Cisco Cloud Control](https://itdaily.com/news/cloud/cisco-cloud-control/), and is gaining a financial dimension with Tokenomics. The module tracks token consumption per agent and per employee, including coding assistants such as Claude Code, Codex, and Cursor, and uses the Deep Time Series Model to predict where consumption is headed before the billing period ends. Additionally, runtime guardrails block unsafe actions such as hallucinations or data leaks.

That strikes a chord. Gartner previously spoke of [total chaos in AI licensing](https://itdaily.com/news/cloud/gartner-total-chaos-in-ai-licenses/), with tokens, credits, and bundles that are hard to compare, and the [rising cloud costs of AI](https://itdaily.com/blogs/cloud/ai-is-becoming-unaffordable-in-the-cloud-can-local-ai-keep-costs-under-control/) are also pushing companies toward local alternatives. Splunk is therefore announcing Activity-Based Pricing, which will give search queries equal weight starting this fall.

## Agents in the SOC

In the area of security, Splunk is expanding its Agentic SOC Workforce with agents for detection engineering, threat hunting, investigation, response, and policy management. Exposure Analytics is gaining broader asset coverage and historical change tracking. For the underlying data, Federated Search is now also moving toward AWS CloudWatch Lake and Databricks, after [it was Snowflake’s turn](https://itdaily.com/news/cloud/cisco-splunk-federated-search-snowflake/) last year.

MCP-based Catalog Discovery is intended to help both analysts and agents find the right datasets. Finally, Splunk and AWS have signed a multi-year agreement for joint product development around the agentic SOC.
