As the Splunk Partner Technical Manager dedicated to AWS in the EMEA region, I had the privilege of leading two transformative workshops that highlighted the innovative ways our organizations are collaborating to deliver enhanced security and AI/ML solutions for customers. This event reinforced a powerful truth: when two market leaders align, the possibilities expand exponentially.
Event Overview
At the recent Splunk Partner Virtual Team (PVT) event in Amsterdam—hosted October 28-30, 2025—over 100 hand-picked Splunk Partner Sales Engineers converged to explore a powerful solution: combining Splunk's real-time analytics with AWS to deliver enhanced security and AI/ML capabilities that maintain search power and flexibility..
For over a decade, Splunk and AWS have worked together at the forefront of data innovation. This isn't just a vendor relationship—it's a strategic alignment born from shared vision. In FY24 alone, Splunk achieved over US$1 billion in cloud bookings through AWS Marketplace, demonstrating the real-world impact of this collaboration.
Today, that partnership is accelerating further. Together, we're redefining what's possible for organizations seeking to maximize data value while maintaining security, speed, and scale.
One of the biggest surprises at the Amsterdam event was discovering that approximately half of the attendees were already actively deploying Splunk's AI Toolkit in production environments. This wasn't a theoretical discussion about AI—these were hands-on practitioners, running anomaly detection, forecasting, and behavioral analytics models that were actively operational in their customers' security and observability ecosystems.
What struck me most was that this level of adoption directly challenged one of the most common misconceptions in the industry: that operationalizing machine learning is still an emerging practice. For these 50+ Partner Sales Engineers, it's already table stakes. Their customers aren't asking "if" they should implement AI/ML—they're asking "how" and "what use cases can we deploy first.
One of the highlights of the event was our "Splunk Federated Search for S3" workshop, which explored how Splunk's powerful analytics capabilities can extend seamlessly into AWS's cloud-native infrastructure.
The Challenge Splunk Solves:
Splunk is renowned for real-time data analytics and intelligence. Federated search represents an evolutionary enhancement—it extends Splunk's analytical reach to data stored in Amazon S3, enabling organizations to query vast datasets using the same familiar SPL (Splunk Processing Language) without requiring data ingestion into Splunk itself.
How It Works:
Splunk's search head coordinates with AWS Glue's Data Catalog to identify relevant S3 objects based on your query. The key innovation: WHERE clause filtering is optimized to the S3 layer before streaming to Splunk, reducing data transfer overhead. This intelligent filtering is orchestrated through AWS Glue's metadata layer, which maintains schema and partition information.
The result? Organizations can now conduct sophisticated analytics across larger datasets while leveraging AWS's proven infrastructure for data storage and management.
Real-World Applications:
This federation capability transforms how organizations think about data accessibility—Splunk's analytics engine now reaches further, enabling teams to extract value from data that previously lived outside the platform's analytical scope.
But expanding analytical reach is only half the equation. The second workshop explored how AWS amplifies Splunk's AI/ML capabilities even further.
The second workshop focused on how AWS SageMaker supercharges Splunk's already-powerful AI/ML capabilities.
Splunk's AI Foundation:
Splunk already leads in operationalizing AI through the Splunk Machine Learning Toolkit (MLTK), which offers pre-built models for security and observability use cases, including anomaly detection, forecasting, and behavioral analytics. At our Amsterdam event, we discovered that approximately half of the attendees were actively leveraging MLTK—a clear signal that AI is moving from innovation projects to operational necessity.
Enhancing with AWS SageMaker:
For organizations building custom models or working with particularly complex datasets, Amazon SageMaker complements Splunk's offerings with enterprise-grade ML infrastructure. Key capabilities include:
The Optimal Workflow:
The most powerful approach combines both platforms' strengths:
This architecture ensures that model inference runs where operational data lives—directly within Splunk—while training leverages AWS's unlimited computational resources.
Practical Impact:
Organizations can now:
Over 100 Partner Sales Engineers departed the Amsterdam event equipped with hands-on knowledge of:
These technical leaders are now positioned as trusted advisors, equipped to help customers implement federated search for historical data analysis and accelerate AI/ML model development using AWS SageMaker—creating measurable operational advantages in security and observability.
The Splunk and AWS partnership represents a fundamental shift in how enterprises approach data. Rather than forcing all data into a single system, Splunk now intelligently classifies data and applies federated approaches to maximize value while optimizing cost and performance.
For security teams, this means faster threat detection and investigation capabilities. For observability teams, it enables real-time insights across hybrid cloud environments. For data scientists and business analysts, it democratizes AI/ML model development and deployment.
Organizations seeking to accelerate their security, observability, and AI/ML initiatives should explore how Splunk and AWS together can expand their analytical capabilities and drive operational advantage.
Ready to expand your analytical reach and accelerate AI/ML deployment? Reach out to your Splunk partner for a demonstration of federated search for S3 or to explore how AWS SageMaker can accelerate your custom model development within Splunk.
The world’s leading organizations rely on Splunk, a Cisco company, to continuously strengthen digital resilience with our unified security and observability platform, powered by industry-leading AI.
Our customers trust Splunk’s award-winning security and observability solutions to secure and improve the reliability of their complex digital environments, at any scale.