Splunk introduced a bevy of new features to address the operational demands of autonomous AI agents at its recent .conf26 user conference in Denver. The announcements spanned three areas:
- AI observability to monitor agent and model behavior
- Expanded Agentic Security Operations Center Workforce to defend against machine-speed threats
- Cisco Data Fabric to unify telemetry across security, observability, and business systems without requiring customers to copy it all into Splunk.
Let’s look at what the company announced.
Announcement Details
Splunk’s announcements cluster around AI and agent observability, an agentic security operations center, and a re-architected data platform that underpins both:
- Splunk Agent Observability: now generally available across cloud, on-premises, and as a native Cisco Cloud Control application. It monitors agent and coding-tool behavior in production and introduces Tokenomics, a capability that tracks and forecasts token spend across agents, so cost overruns surface before they reach the finance team.
- Splunk Agentic SOC Workforce: expands automated coverage across detection engineering, triage, investigation, and response by combining enterprise telemetry with specialized agents built on frontier and domain-specific models. Exposure Analytics adds historical change tracking and business context for risk scoring, and Cisco Live Protect adds virtual patching for vulnerabilities customers cannot immediately remediate.
- Observability: Observability Studio and AI SRE detection and troubleshooting agents are now available. Splunk also introduced a remediation agent built with Anthropic that reads telemetry, opens a merge request with a proposed fix, and requires human approval before the change is applied.
- Cisco Data Fabric, powered by the Splunk Platform: adds a Machine Data Lake, a data catalog, expanded federated search, and AI data management. Federated Search now reaches AWS CloudWatch and Databricks in addition to Snowflake, with FedRAMP coverage for the capability planned for January 2027 and on-premises Splunk Enterprise support later that year.
- Cisco extended a multi-year agreement with AWS to co-develop security solutions and deepened its collaboration with NVIDIA to bring Splunk AI on-premises. Cisco AI POD for Splunk is available now as part of Cisco Secure AI Factory with NVIDIA, supporting self-hosted models including Google Gemma 4 and OpenAI‘s GPT-OSS 20B, with NVIDIA Nemotron model support to follow.
- An integration letting any customer with both Splunk Observability and Enterprise Security join those data sets is scheduled to ship by year-end 2026.
Analysis
The announcements extend Splunk’s long-standing position as an operational data platform into the agentic era, leveraging Cisco’s networking, compute, and silicon assets as a differentiator that a pure-play observability or SIEM vendor cannot easily replicate.
Some observations:
- By framing trust (rather than raw AI capability) as the product, Splunk is betting that enterprises adopting agents will pay for the governance layer as much as the automation itself.
- Cisco’s ownership of the network, compute, and now data layers give Splunk a differentiated bundle. One keynote cited data showing that agents consume “450% more network bandwidth” than a human performing the same task, a statistic that supports Cisco’s argument that agentic AI is fundamentally a networking and infrastructure problem, not just a software one.
- The pivot toward unifying security and observability telemetry is a strong strategic bet.
- The heavy reliance on Cisco’s broader AI infrastructure play, including the Secure AI Factory with NVIDIA, ties Splunk’s growth to enterprise AI infrastructure spending holding up. A slowdown in that spending would blunt the value prop of several announced capabilities.
Practitioner Impact
For security and observability teams, the announcements promise fewer blind spots but add integration work:
- Teams adopting Agent Observability and Tokenomics gain real-time visibility into token spend and agent behavior, but they must first instrument agents and coding tools consistently to get usable data.
- The Cisco Data Fabric’s federated search reduces the incentive to copy every data source into Splunk, which can lower ingestion costs, though customers still need to validate query performance against externally held data such as Snowflake or Databricks tables.
- The remediation agent built with Anthropic keeps a human in the approval loop for code changes, a design choice that limits speed but reduces the risk of autonomous agents making unsupervised production changes.
Competitive Landscape
Splunk’s agentic push arrives in a market where nearly every major observability and security vendor has announced its own AI agents over the past year. The company’s differentiation rests on combining security, observability, and network telemetry into a single data fabric, a capability competitors may struggle to match without the broader reach that Cisco enables for Splunk.
| Alternative | Model / Approach | Compared to Splunk’s Agentic Platform |
| Microsoft Sentinel / Security Copilot | Cloud-native SIEM tied to Azure and the Microsoft Defender stack, with Security Copilot as the agentic layer. | Matches Splunk on agentic triage and investigation within Microsoft-centric estates, but lacks Splunk’s breadth of on-premises and multi-cloud telemetry ingestion and the combined observability-security data fabric. |
| Datadog | Cloud-native observability platform extending into security (Cloud SIEM) and adding Bits AI agents for investigation and remediation. | Competes directly on AI-driven observability and cost-of-telemetry concerns, but has a narrower security product line than the combined Splunk-Cisco portfolio and no equivalent to Cisco’s network and infrastructure telemetry. |
| CrowdStrike Falcon | Endpoint-first XDR and next-generation SIEM (Falcon LogScale) with Charlotte AI as its agentic assistant. | Holds a stronger position in endpoint detection and response, while Splunk’s advantage lies in the depth of its data platform and its ability to correlate security with full-stack observability and network context. |
| Google Security Operations (Chronicle) | Cloud-scale security data lake with Gemini-powered detection and response agents. | Offers comparable data-scale ambitions and a maturing agentic layer, but has less presence in enterprise on-premises and hybrid observability deployments than Splunk. |
| Elastic Security | Open-architecture search and analytics platform with AI-assisted detection and an open data format. | Appeals to organizations wanting to avoid platform lock-in and lower licensing costs, though it has a smaller catalog of prebuilt agentic workflows and a thinner network-telemetry integration story than the Cisco-Splunk combination. |
| Dynatrace | Unified observability platform built on a proprietary dependency graph (Davis AI), extending into application security and adding agentic workflows through the Davis CoPilot assistant. | Matches Splunk’s ambition to correlate application, infrastructure, and security context automatically, and its causal AI engine is more mature in root-cause analysis, but it lacks Splunk’s deep integration with Cisco’s network telemetry, and its reach into on-premises and sovereign AI deployments. |
Differentiation is strongest where Splunk can draw on Cisco’s network and infrastructure telemetry alongside its existing security and observability data.
Differentiation is weakest in the specific technical strengths of point competitors, such as CrowdStrike’s depth of endpoint detection, Dynatrace’s causal AI for root-cause analysis, and Elastic’s lower-cost, open-architecture appeal. A broader platform bet does not automatically translate into best-of-breed capability in any single category.
Final Thoughts
Splunk’s .conf26 announcements offer a coherent response to the operational challenges of agentic AI. Enterprises are deploying autonomous agents faster than they can govern them, and the company announced concrete, shipping-ready capabilities, including Agent Observability, Tokenomics, and an expanded agentic SOC workforce.
The most important takeaway for enterprise buyers is that Splunk and Cisco are now positioning the platform as the system of record for what autonomous agents do, a step beyond its dashboards-and-search legacy.
As agent adoption scales, the vendor that can credibly prove and govern agent behavior stands to become the control point for the rest of the AI stack. Splunk clearly wants to be that control point, but so do a broad swath of capable competitors.
This market is far from settled.



