Splunk rebuilds its platform around agents
Cisco Systems Inc.’s Splunk unit today unveiled a broad set of platform, security and observability enhancements intended to reposition the company as a data and governance foundation for the emerging “agentic enterprise.”
Splunk executives said the announcements are a strategic overhaul rather than a routine product refresh. Splunk is adapting its platform for a world in which artificial intelligence agents generate far more telemetry than people, operate at machine speed and make decisions that can have immediate operational, financial and security consequences.
“This is not just an incremental evolution or an additional bunch of features,” said Mangesh Pimpalkhare, senior vice president and general manager of Splunk Platform at Cisco. “We’ve reimagined Splunk so that customers can start to trust AI at scale.”
The strategy spans three broad areas: observing and controlling AI systems, defending organizations at machine speed and turning distributed machine data into actions by people and agents. Underlying all three is a fundamental rethink of Splunk’s data platform, including how information is stored, searched, processed and prepared for AI.
Central fabric
The centerpiece is Cisco Data Fabric, a new architecture powered by the Splunk platform that can analyze information where it resides instead of requiring customers to copy everything into Splunk. The fabric federates data across Splunk, cloud object stores, data lakes and platforms such as Snowflake Inc. and Databricks Inc., then correlates signals across those environments.
It’s intended to address a longstanding criticism of Splunk: the cost of ingesting and indexing large volumes of data. The problem potentially becomes more acute as hundreds or thousands of agents generate logs, events, traces and other telemetry continuously.
“Cost is directly addressed by this federated approach,” Pimpalkhare said. “If you start duplicating data movement and all the processing needed, that is what drives up costs.”
Splunk said the platform can automatically manage data across different storage tiers, turn raw machine data into structured information suitable for AI and search external sources without moving the underlying information. Expanded federated search supports services including Amazon Web Services Inc.’s CloudWatch data lakes and Databricks.
The architecture also incorporates a universal collector for metrics, events, logs and traces, real-time ingest processing and domain-specific AI models trained on operational data. Splunk said the models are designed to complement, rather than replace, frontier models.
Examples of domain-specific models include time-series forecasting, log analysis and graph reasoning. Those smaller models can supply operational context and help frontier models interpret the machine data that enterprises generate.
“We are not reinventing frontier models,” Pimpalkhare said. “Our goal is to complement those frontier models and develop the next level of domain-specific models.”
Partnering for AI
Splunk is also extending AI processing into customers’ own data centers through an expanded partnership with Nvidia Corp. The new Cisco AI POD for Splunk combines Cisco infrastructure, Nvidia accelerated computing, Splunk AI runtime software and a Kubernetes-based architecture validated for Splunk workloads.
The configuration enables Splunk Enterprise customers to run AI in on-premises, private-cloud and air-gapped environments. That is most appealing to regulated businesses, government agencies and other organizations that can’t send sensitive operational data to an external AI service.
Splunk AI Assistant is available on Splunk/Nvidia infrastructure now, while Agent Launchpad, expected later this year, will let customers build customized agents on their own infrastructure using templates, Model Context Protocol connections and human controls. Supported self-hosted models include Cisco’s Deep Time Series Model, Google LLC’s Gemma 4 and OpenAI Group PBC’s GPT-OSS 20B. Nvidia’s Nemotron models will be added in the coming months.
Pimpalkhare said the Nvidia initiative does not require customers to choose between on-premises AI and cloud services. “They can absolutely combine the two,” he said. “The partnerships are orthogonal as well as complementary.”
On the cloud side, a multiyear agreement with AWS will have the companies jointly developing agent-specific security products. Splunk will contribute its data platform, security analytics and investigation tools while AWS supplies cloud infrastructure and security signals. The companies said the relationship will go beyond product integration to include joint development and sales initiatives.
Into the SOC
Security is another major component of the overhaul. Splunk is expanding its Agentic Security Operations Center Workforce with specialized agents for detection engineering, threat hunting, malware analysis, investigation, response and governance.
The agents are designed to share context and work together, much as different specialists do in a security operations center. Customers can determine how much autonomy each agent receives. For example, routine triage could be fully automated, while actions such as isolating infrastructure or disabling an account remain subject to approval.
“A lot of [SOCs] are extremely comfortable going fully autonomous with the triage part, but they still want to build confidence,” Pimpalkhare said. “They want recommendations, but they want some kind of a governance loop or human approval loop from a level-three SOC analyst when it comes to taking actions and mitigations.”
Splunk is packaging the capabilities in Enterprise Security Essentials for organizations that want analysts to make final decisions and Enterprise Security Premier for customers prepared to use more autonomous defenses. Enhancements to Exposure Analytics add broader asset discovery, historical tracking and business context to help security teams prioritize vulnerabilities.
The observability announcements address a growing impediment to agentic adoption: determining whether agents are working correctly and economically.
Watching over agents
Splunk Agent Observability is being made available through Splunk Observability Cloud and Cisco Cloud Control. It monitors the infrastructure, models, orchestration frameworks, memory systems and workflows that support agents. Splunk said it evaluates every event without sampling and can apply runtime guardrails to block unsafe actions or outputs.
“It’s not just passive observability of what the agent is doing,” Pimpalkhare said. “The important part is checking whether the agent is behaving as intended.” Splunk monitors agent actions and detects deviations from expected behavior. “If you don’t want the agent to go outside a certain set of boundaries, then we have a feedback loop to stop that behavior,” he said.
A new Tokenomics capability tracks token consumption across models and employees’ use of coding tools such as Claude Code, Codex and Cursor. It attributes costs to teams and users, links spending to outcomes and uses Cisco’s time-series model to forecast consumption before a billing period ends.
Splunk also introduced Observability Studio, which uses guided OpenTelemetry instrumentation to make applications “born observable” during development. A Network Intelligence App brings Cisco network topology, device health and events into Splunk, while new Essentials and Premier editions simplify the packaging of Splunk Observability Cloud.
Taken together, the announcements show how Cisco is knitting Splunk more tightly into its networking, security, computing and management portfolio. They also expand Splunk’s ambitions beyond searching machine data to making that data usable by agents with cost controls, permissions, operational context and human oversight.
Photo: Paul Gillin/SiliconANGLE
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos , powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.