Splunk at Cisco Live: Building the Intelligence Layer for Trusted Agentic Operations

Leadership Mangesh Pimpalkhare

Key takeaways

  1. Splunk's expanded Federated Search and Machine Data Lake let teams analyze data across multiple platforms from one place, cutting costs and boosting performance by up to 10x.
  2. New AI-powered agents automate threat detection, root cause analysis, and incident response, helping security and IT teams resolve issues before customers are impacted.
  3. Splunk Agent Observability (powered by Galileo) monitors AI agents end-to-end to ensure accuracy, block harmful outputs, and control costs—closing the AI trust gap for enterprises.

Today at Cisco Live, we’re advancing the intelligence layer enterprises need to run agentic AI at scale they can trust. These capabilities address the complexities of the agentic era by eliminating data silos, responding at machine speed with AI-first security and observability, and closing the trust gap in autonomous operations.

With expanded Federated Search coverage, teams can search and correlate distributed data sources from one interface, land machine data affordably, and promote only the data that matters, driving down costs and accelerating investigations creating up to 10x efficiency in cost and performance. Agent Builder in Splunk AI Toolkit democratizes agent creation with a no-code interface, so any team can build and deploy fully autonomous agents at scale. AI SRE in Splunk Observability Cloud delivers automatic root cause analysis and guided remediation for application and infrastructure performance. Also new, Splunk Agent Observability helps close the AI trust gap by giving enterprises visibility into whether their agents are behaving as intended across the entire development lifecycle.

Cross-Domain Insights at Massive Scale

Cisco Data Fabric powered by the Splunk Platform is the architecture that unifies Federated Search, Machine Data Lake, and integrated data capabilities into a single framework for managing data at scale. This unified data layer eliminates fragmented tools, data pipelines, and redundant storage. Teams now conduct cross-domain analysis, provide contextualized insights, and act when it matters, helping organizations control cost, preserve operational context, and drive high-impact outcomes.

Additionally, Splunk Platform, Splunk ITSI and Splunk Observability Cloud are accessible in Cisco Cloud Control, giving teams a unified workflow across their full Cisco and Splunk ecosystems. For customers, this means significantly less tool sprawl, fewer dashboards to manage, and less context switching between environments. Teams and agents can investigate, act, and collaborate from a single, connected experience.

Responding at Machine Speed

Today’s cyber threats are moving faster than ever, and understanding their origin is imperative. Research from The Hidden Costs of Downtime reveals that 36% of security leaders misclassify a downtime incident as an IT issue, giving attackers a head start. The same research states that 98% of all tech executives confirm end-to-end visibility is critical for reducing incidents, highlighting the instrumental role observability plays in reducing downtime.

To proactively predict and remediate threats through shared data, Splunk is expanding intelligent context across security and observability so teams can detect problems earlier, accelerate response, and remediate before customers feel the impact.

For security operations, new agentic solutions and platform updates give teams faster, more automated coverage across the threat lifecycle:

For ITOps and engineering teams, new agentic capabilities will help teams reduce MTTR (mean-time-to-resolve) by accelerating detection, troubleshooting, and remediation, with less manual effort:

These innovations are already resonating across public sector IT, where unified security and observability can transform how agencies manage risk.

“As Cisco and Splunk capabilities converge under one strategic portfolio, the prospect of unifying observability and security telemetry into a single operating model is one of the most consequential developments for state government IT." — Brad Welsh, APM Program Manager, Indiana Office of Technology

Solving the AI Trust Gap

The rise of the agentic workforce is helping to automate and reimagine key business workflows. However, agentic AI also introduces new risks of inaccurate, low-quality agent behavior, resulting in flawed outputs. Organizations are also wrestling with how to control AI costs.

Today's organizations need the ability to ensure agents and models are behaving as intended, with guardrails to block harmful outputs and observability that provides governance and controls token costs. With Galileo’s AI observability and evaluation engineering platform integrated within Splunk Observability, we’re helping enterprises to solve the AI trust gap.

Looking Forward

Enterprises are still in the early innings of the agentic AI era. The strongest organizations are those investing now in the intelligence layer that helps them move fast without losing visibility or control. Research shows that organizations are focusing their AI budgets on high-impact areas, with 85% of technology leaders prioritizing AI-driven security automation and 65% investing in AI-powered observability to gain deeper, real-time insights into their digital ecosystems.

Splunk’s vision for the future is clear: to be the layer that turns machine data into trusted action, at any scale, across any environment.

Available Now:

Planned for This Summer and Fall:

This blog post may contain forward-looking statements regarding future events, plans or the expected financial performance of our company, including our expectations regarding our products, technology, strategy, customers, markets, acquisitions and investments. These statements reflect management’s current expectations, estimates and assumptions based on the information currently available to us. These forward-looking statements are not guarantees of future performance and involve significant risks, uncertainties and other factors that may cause our actual results, performance or achievements to be materially different from results, performance or achievements expressed or implied by the forward-looking statements contained in this blog post.

For additional information about factors that could cause actual results to differ materially from those described in the forward-looking statements made in this presentation, please refer to our periodic reports and other filings with the SEC, including the risk factors identified in our most recent quarterly reports on Form 10-Q and annual reports on Form 10-K, copies of which may be obtained by visiting the Cisco Investor Relations website at investor.cisco.com or the SEC's website at www.sec.gov. The forward-looking statements made in this blog post are made as of the time and date of this blog post. If reviewed after the initial presentation, even if made available by us, on our website or otherwise, it may not contain current or accurate information. We disclaim any obligation to update or revise any forward-looking statement based on new information, future events or otherwise, except as required by applicable law.

In addition, any information about our roadmap outlines or our general product direction is subject to change at any time without notice. It is for informational purposes only and shall not be incorporated into any contract or other commitment. We undertake no obligation either to develop the features or functionalities described, in alpha or beta or in preview (used interchangeably), or to include any such feature or functionality in a future release.

Related Articles

Punycode phishers - All you need to know
Security
2 Minute Read

Punycode phishers - All you need to know

Unicode domains can be used for homograph attacks. Learn what they are and how users can be tricked.
Securing DevSecOps - Threat Research Release October 2021
Security
5 Minute Read

Securing DevSecOps - Threat Research Release October 2021

Learn how you can secure your development security operations with pre-built and tested Splunk detections and automated playbooks.
Beyond Logs: Navigating Entity Behavior in Splunk Platform
Security
7 Minute Read

Beyond Logs: Navigating Entity Behavior in Splunk Platform

Master internal threat detection with Splunk's anomaly detection, finding events like unusual geolocations and spikes in activity, while optimizing security.