The Partner Advantage: Reimagine the Foundation for the Agentic Era
Partners Jason CongerKey takeaways
- Cisco AI POD for Splunk brings AI capabilities to on-premises and air-gapped systems, closing the gap for sensitive-data customers who couldn't use cloud AI before.
- Cisco Data Fabric lets teams search and use data wherever it lives without moving it, cutting storage costs while keeping full visibility for security and analysis.
- Splunk's Agentic SOC and Agent Observability tools help security teams detect threats faster and build trust in AI agents through guardrails, tracking, and human oversight.
Splunk .conf26 arrived with a name for what's happening across the industry right now: Splunk Reimagined. It is all about what becomes possible once the constraints that have quietly shaped enterprise data architecture for twenty years get lifted, all at once rather than chipped away at one at a time. For partners, that claim isn't abstract. Every constraint removed opens a service line.
Kamal Hathi, SVP and GM of Splunk, named the three constraints directly on stage: spend (the cost of data and AI), skill (the headcount you can't hire), and speed (the need to respond faster than the threats you're facing). Splunk Reimagined is the bet that all three get lifted together now rather than someday or incrementally over time. That's the lens for everything below.
Trust AI On-Prem: Cisco AI POD for Splunk
For customers who can't move sensitive data to the cloud, AI has been out of reach... until now. Cisco AI POD for Splunk, the newest member of the Cisco Secure AI Factory with NVIDIA, brings a fully turnkey and pre-validated hardware-and-software stack for running Splunk AI on-premises, in private cloud, or fully air-gapped. Need more flexibility? AI Tier gives you the same capability as a software layer on the infrastructure of your choice.
The Vision: Splunk AI Assistant and the newly-GA Agent Launchpad now run on this on-prem foundation, with model choice built in - Cisco Deep Time Series Model, Google Gemma 4, OpenAI GPT-OSS 20B, with NVIDIA Nemotron on the way.
Partner Edge: This closes a gap that's held back every customer who couldn't take their sensitive data to the cloud. The same AI capabilities customers have come to expect from Splunk Cloud (assistants, agent building, model choice) now run on-premises, in an air-gapped environment, or in a sovereign deployment, with nothing lost in the translation. That's an entirely new conversation for partners to have with regulated, defense, and data-residency-constrained customers who've been sitting on the sidelines of the AI conversation: the capability gap between cloud and on-prem just closed.
Turning Machine Data into Agentic Action: Cisco Data Fabric
"Listen to your data" was Splunk's tagline for the better part of two decades, and it held up because it captured something true: your infrastructure is already telling you what's wrong if you're willing to listen. What's changed is how to listen. Indexing everything, everywhere, forever isn't how you listen anymore at agentic scale. Cisco Data Fabric powered by the Splunk Platform is the new mechanism for listening to your data no matter where it lives, indexed or not, structured or not, cloud or on-prem. Federated Search continues to expand its reach now including AWS CloudWatch Lake and Databricks. Machine Data Lake provides a catalog across the Cisco Data Fabric to make it easier to find, understand, and use data with context wherever it is. This helps both people and agents find the right data with the right business context without moving it first.
The Vision: Customers no longer have to choose between a lean cost structure and full visibility. Federated search and intelligent data tiering let high-value, frequently searched data live in Splunk for real-time analysis, while lower-priority data stays exactly where it already is (S3, Snowflake, Databricks, Azure Blob, and more) while being fully queryable without ever being moved or duplicated. That's real cost reduction without giving up the fidelity that resilience actually depends on.
Partner Edge: New Value Insights capabilities put a number on this for every customer, not just the showcase ones. In the .conf26 keynote demo, it surfaced a 30% capacity expansion at zero added cost, just by identifying data that hadn't been searched in 30 days. That's a ready-made FinOps consulting engagement: walk a customer's Splunk footprint, run the what-if scenarios, and hand them an executive-ready cost report. Activity-Based Pricing (coming fall 2026) gives you another lever to model for them.
Defending at Machine Speed: The Agentic SOC
Security is where the AI-era stakes are most visible. Agentic attacks have escalated from theoretical risk to proven incidents. Frontier AI Models have chained low and high-severity vulnerabilities into working exploits which then reappeared in widely available guardrail-free open models. These attacks are now demonstrating supply-chain compromise, convincing AI-driven social engineering, and even agents "recruiting" other agents into a campaign.
The Vision: Splunk's answer is an expanded Agentic SOC Workforce including purpose-built agents across detection engineering, threat hunting, investigation and response, and governance. Feeding the agents is enterprise-wide visibility including over 1,300 security integrations that help trigger action, instead of after an attacker's already moved laterally. Expanded Exposure Analytics adds the proactive half of the equation, prioritizing what's actually exploitable before it's exploited. Bringing it all together aides in defense against attacks that chain vulnerabilities and recruit other agents into the campaign. The goal is not unchecked autonomy, but trusted AI that helps teams move from detection to validation to action with human oversight.
Partner Edge: The business case is concrete: early agentic SOC deployments have cut cloud identity-threat response time from 20 minutes to under a minute. But the more useful lesson for partners is a cautionary one - organizations that rolled out risk-based alerting before their asset and identity data was mature enough have seen it backfire: alert fatigue, false positives, a forced step back to rebuild the foundation. That's a real service opportunity. Data and identity foundation work has to come before agentic security automation, not after. Partners who lead with that discipline will get better outcomes than partners who lead with agent count.
Building Trust in AI: Agent Observability and Tokenomics
The biggest barrier to agent adoption in production isn't the model - it's trust. Splunk Agent Observability is now generally available everywhere: in Observability Cloud, on-prem, and as a native Cisco Cloud Control app. It evaluates agent behavior, applies runtime guardrails against hallucinations and unsafe actions, and now includes Tokenomics - tracking and soon forecasting AI token spend across agents and coding-agent in real time. Check out this blog to learn more about Agent Observability and this blog to learn more about Tokenomics.
The Vision: Verizon's enterprise AI governance lead put it as plainly as it can be put, on the .conf26 main stage: "You cannot govern what you cannot see." Their operational model of “validate, observe, evaluate, optimize” is a governance blueprint anyone can adapt. Splunk also showed what production trust actually looks like working with a live demo of Claude reading Splunk telemetry and the customer's codebase to investigate and remediate an incident end-to-end, opening a pull request for human review rather than acting unilaterally.
Partner Edge: This is the foundation for an "AI Governance and Observability" practice - helping customers evaluate agents before production, instrument the guardrails, and build the trust ladder that lets autonomy expand safely. Pair it with Cisco AI Defense, which discovers AI assets across an environment (LLMs, RAG apps, agents, MCP servers), red-teams them before they ever reach production, and protects against prompt injection and data leakage at runtime. Together, that's a full lifecycle offering including discovery of the AI assets that already exists in a customer's environment, secure them before it ships, and govern their behavior once live. That combination is what turns AI governance into a durable, high-value practice. The new Observability Cloud Free Edition and simplified Essentials/Premier packaging make this an easy motion to lead with, too. Get a customer started with zero procurement friction, prove the value, then expand into Premier as their agentic footprint (and their tokenomics story) grows.
The Partner Advantage: Foundation Before Automation
Across every one of these announcements, one thread repeats: the customers getting real results built the foundation first. And, the cornerstone of that foundation is data strategy - getting the right data to the right place to drive the right action.
That's the actual Partner Advantage this year - not being first to deploy the most agents but being the partner who insists on the foundation that makes agentic action trustworthy. Every capability covered here from on-prem AI, to data strategy, to autonomous security, to governed observability only pays off when it sits on top of that foundation. Customers don't need a partner who can stand up the most agents the fastest. They need one willing to tell them, honestly, when they're not ready for autonomy yet and who has the foundation-first playbook to get them there. That's a harder sell than a demo. It's also the one that still holds up after the first incident.
Your Path Forward:
- Get on the on-prem AI list - build AI POD/AI Tier deployment expertise now, while it's a new category, and open the conversation with regulated and data-residency-constrained customers who've been sitting on the sidelines.
- Turn Value Insights into a service - a data strategy engagement, built on "listen to your data no matter where it is" that you can run for every customer, not just the ones already asking.
- Lead security with data foundation, not agent count - mature identity and asset data has to come before agentic security automation, not after. Organizations that skip that step see it backfire; the ones that get it right cut response times from minutes to seconds.
- Build the AI Governance and Observability practice - trust ladders, guardrails, and tokenomics, paired with full-lifecycle coverage are a genuinely new discipline customers need help designing.
- Anchor every conversation in spend, skill, or speed - whichever constraint is hurting a customer most, that's the entry point. Splunk Reimagined only works as a partner motion if you diagnose the constraint before you propose the fix.
Conclusion
Splunk .conf26 didn't just add features - it answered the three questions blocking enterprise AI adoption: trust, security, affordability. For partners, each answer is a door. The partners who walk through it are the ones who build the foundation first.
Ready to dive deeper? Visit the Cisco and Splunk partner page to access training, resources, and support for implementing these capabilities with your customers.
Related Articles

Building At-Scale User Behavior Analytics for Splunk UBA: Enhance Performance of Account & Device Exfiltration Models

Crossed Swords 2025: Lessons From the Frontlines of Cyber Defense with Splunk Enterprise Security
