TL;DR — Key Takeaways

– Splunk is expanding its AI capabilities across observability, security and data management while introducing pricing options designed to better align costs with actual search and ingest activity.

– New capabilities include Splunk AI Assistant, Agent Launchpad, AI-powered data management and expanded observability for monitoring AI agents, token consumption and runtime behavior.

– Splunk is deepening its integration with Cisco infrastructure and management platforms, including Cisco Cloud Control, Cisco networking products and Cisco Secure AI Factory with NVIDIA.

The Splunk arm of Cisco today moved to reduce the total cost of applying analytics to IT operations while at the same time adding additional artificial intelligence (AI) capabilities to manage and analyze telemetry data at scale.

Announced at the .conf26 event, Splunk AI Assistant, now generally available, translates natural language queries into Search Processing Language (SPL) queries and an Agent Launchpad framework that makes it possible to create AI agents with four clicks. Splunk is also working on agent lifecycle management following its acquisition of Galileo earlier this year.

At the same time, Splunk is making available an Activity-Based Pricing option to enable IT teams to align cost to actual activity by weighting search and ingest equally. Splunk is also extending the federated search capability it provides to the AWS CloudWatch Lake service and later this year the data management platform provided by Databricks.

There are also now multiple editions of the observability platform, including Essentials, Premier and Free editions. The latter enables IT teams to get started without upfront cost or procurement barriers or time-bound trials.

Kamal Hathi, senior vice president and general manager for the Splunk business unit, told conference attendees that the Splunk platform is being reimagined to function as a system of record for AI. The goal is to increase the amount of data that IT operations teams can analyze without increasing costs, he added. For example, an AI-Powered Data Management tool, now generally available, optimizes the management of data pipelines to reduce costs.

There is also now a Splunk Agent Observability tool that will be added to the Splunk Site Reliability Engineer (SRE) AI platform that evaluates agent behavior, observes performance across the entire AI stack, enables token usage and cost optimization, and controls agents in real time via runtime guardrails that block harmful actions and outputs for every response.

Splunk also extended its observability capabilities to provide deeper insights into the behavior of AI agents and how AI tokens are being consumed. Additionally, Splunk is tightening integration between its observability portfolio and Cisco Cloud Control, the framework that Cisco makes available to centralize the management of IT operations. There is also now a Network Intelligence App for Splunk that brings Cisco network topology, device health, and events into the Splunk IT analytics platform.

There is also an Observability Studio tool that makes it simpler to instrument applications using the Claude AI tools provided by Anthropic. Splunk is also now making it possible for IT teams to self-host both open and proprietary generative AI models on the Splunk Enterprise platform, including the Cisco Deep Time Series Model, Google Gemma 4, OpenAI GPT-OSS 20B and NVIDIA Nemotron that will be added in the months ahead.

A Universal Collector, expected to be available in beta in 2027, also promises to streamline collection of all types of data using an instance of OpenTelemetry, while an Ingest Processor for streaming detections also due out next year streamlines investigations.

At the same time, Splunk is expanding its agentic security operations center (SOC) offering by adding specialized AI agents that have been trained to analyze telemetry data. There are also now additional AI agents for handling detection, threat hunting, autonomous investigation, coordinated response, and policy governance with others, including a knowledge graph, to follow in 2027.

Splunk is also extending its Exposure Analytics offering to provide deeper visibility into additional assets, historical change tracking, and business-specific risk insights. Extensions to Splunk Enterprise Security Essentials, meanwhile, enable deeper agentic AI autonomy. 

Finally, Cisco unveiled Cisco AI POD for Splunk, a configuration in Cisco Secure AI Factory with NVIDIA for running AI workloads in self-hosted IT environments.

It’s not clear to what degree IT teams are adopting the combined Splunk and Cisco portfolio, but as it continues, the roles and responsibilities of IT teams will evolve as various silos start to finally share access to a common data fabric. The challenge now is streamlining the portfolio of offerings that IT, DevOps and security teams need to navigate as the management of IT becomes more unified.

Frequently Asked Questions

What is Splunk AI Assistant?
Splunk AI Assistant allows users to translate natural-language requests into Search Processing Language (SPL) queries, reducing the expertise required to analyze telemetry data.
What is Splunk Agent Launchpad?
Agent Launchpad is a framework designed to simplify the creation of AI agents, with Splunk claiming agents can be created in as few as four clicks.
How is Splunk changing its pricing model?
Splunk is introducing Activity-Based Pricing, which weights search and data ingest equally in an effort to more closely align customer costs with actual platform usage.