Splunk Rebuilds Platform for Agentic AI Era, Partners with NVIDIA for On-Premises Deployment

4 Sources

Share

Cisco's Splunk unit announced a strategic platform overhaul at .conf 2026 to position itself as the data foundation for enterprises deploying AI agents. The company unveiled Splunk Agent Observability with Tokenomics capabilities to track token spend in real time, expanded its NVIDIA partnership to bring Splunk AI to on-premises customers via Cisco AI POD for Splunk, and introduced specialized security agents for autonomous operations.

Splunk Positions Trust as Core Product in Agentic AI Shift

At Splunk .conf 2026 in Denver, Cisco and its Splunk unit unveiled a comprehensive platform transformation designed to address what executives identified as the scarcest resource in enterprise AI adoption: trust

1

. Cisco President Jeetu Patel framed the transition around four critical vectors—inference as the new workload, AI agents as the new workforce, tokens as the new currency, and trusted AI as the adoption gatekeeper

1

. Patel revealed that agents consumed five times more tokens than humans by September 2026, just seven months after first surpassing human consumption in February, while roughly 60% of global AI compute capacity now goes to inference rather than training

1

. This consumption shift means agentic AI operates continuously at machine speed, generating far more telemetry than people and making decisions with immediate operational, financial, and security consequences

2

.

Source: SiliconANGLE

Source: SiliconANGLE

Mangesh Pimpalkhare, senior vice president and general manager of Splunk Platform at Cisco, emphasized that these announcements represent a strategic overhaul rather than incremental updates, stating the company has "reimagined Splunk so that customers can start to trust AI at scale"

2

. The strategy spans three areas: observing and controlling AI systems, defending organizations at machine speed, and turning distributed machine data into actions by people and agentic AI

2

.

Cisco and NVIDIA Expand Partnership for On-Premises AI Deployment

Cisco and NVIDIA extended their collaboration to bring self-managed AI directly to Splunk Enterprise customers across on-premises, private cloud, and air-gapped environments

3

. The companies introduced Cisco AI POD for Splunk, combining Cisco infrastructure, NVIDIA accelerated computing, Splunk AI runtime software, and Kubernetes-based architecture pre-validated for Splunk AI workloads

4

. This configuration addresses data sovereignty requirements for regulated businesses and government agencies that cannot send sensitive operational data to external AI services

2

.

Splunk AI Assistant is available immediately on this infrastructure, while Agent Launchpad, expected later this year, will enable customers to build customized agents using templates, Model Context Protocol connections, and human controls

3

. Customers can self-host generative AI models including the Cisco Deep Time Series Model, Google Gemma 4, and OpenAI GPT-OSS 20B, with NVIDIA Nemotron open models coming in subsequent months

4

. Justin Boitano, Vice President of Enterprise AI at NVIDIA, noted that enterprises need to bring AI where their data lives, especially when security and data sovereignty requirements mandate critical workloads remain on-premises

3

.

Source: SiliconANGLE

Source: SiliconANGLE

Tokenomics Solution Addresses Hidden AI Cost Crisis

Splunk Agent Observability now includes Tokenomics capabilities that track and attribute token expenditure across AI agents and employees' use of coding agents like Claude Code, Codex, and Cursor in real time

4

. The solution forecasts consumption patterns using the Cisco Deep Time Series Model to project spending before billing periods end, helping organizations operationalize a tokenomics framework and tie AI spend to business outcomes

3

.

A live demonstration at .conf 2026 illustrated the financial risks of unmonitored agentic AI: a retailer's shopping agent, instructed to increase customer satisfaction, honored an expired $300 promotion that engineers estimated could cost roughly $500,000 per hour at scale

1

. The fix involved converting a custom evaluator into a small language model guardrail running inline with sub-350-millisecond latency to cut evaluation costs

1

. Splunk Agent Observability, initially announced as an on-premises offering, is now available in Splunk Observability Cloud and Cisco Cloud Control, extending visibility across the Cisco portfolio

4

.

Observability and Security Operations Converge for Agentic Enterprise

Patel explained why observability and security operations can no longer function separately in the agentic era: "It is actually very hard to distinguish between whether there's a breach, or some agent was poisoned because of an external prompt, or the agent just exercised poor judgment because it was very literally following your instructions"

1

. Nondeterministic systems fail in ways that look identical to compromise, making the classic security operations center triage question of "bug or attack?" unanswerable with security telemetry alone

1

.

Splunk's response places agent traces, evaluator scores, application telemetry, network data, and security signals on a single correlated fabric through the new Cisco Data Fabric architecture

2

. John Morgan, Splunk's senior vice president and general manager of security, previewed an integration shipping at year-end that lets customers with both Splunk Observability and Enterprise Security join those datasets while respecting organizational boundaries: "We want to respect that the observability and the security teams are different. We know they often have different budgets, but at the same time they have the same business goal"

1

.

Splunk expanded its Agentic Security Operations Center Workforce with specialized agents for detection engineering, threat hunting, malware analysis, investigation, response, and governance

2

. These agents combine enterprise-wide telemetry with leading frontier and domain-specific models to deliver deep reasoning and transparent verdicts that reduce alert noise and accelerate mean time to remediate

4

.

Source: CXOToday

Source: CXOToday

Cisco Data Fabric Tackles Cost and Federation Challenges

The Cisco Data Fabric represents a fundamental rethink of how Splunk stores, searches, processes, and prepares data for AI agents

2

. The architecture federates data across Splunk, cloud object stores, data lakes, and platforms such as Snowflake and Databricks, then correlates signals across those environments without requiring customers to copy everything into Splunk

2

. Pimpalkhare stated that "cost is directly addressed by this federated approach," noting that duplicating data movement and processing drives up expenses—a problem that intensifies as hundreds or thousands of agents generate logs, events, traces, and other telemetry continuously

2

.

The platform automatically manages data across storage tiers, converts raw machine data into structured information suitable for AI, and searches external sources without moving underlying information

2

. Expanded federated search now supports services including Amazon Web Services CloudWatch data lakes and Databricks

2

. The architecture incorporates domain-specific AI models trained on operational data for time-series forecasting, log analysis, and graph reasoning, designed to complement rather than replace frontier models by supplying operational context

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved