Accelerating the Agentic Enterprise: New Splunk Platform Innovations at Cisco Live Las Vegas 2026

Platform JK Lialias

Key takeaways

  1. Splunk is launching AI-powered data management and expanded Federated Search to break down data silos, helping teams query and act on data faster regardless of where it lives.
  2. A new Machine Data Lake and built-in Data Catalog make it easier and more cost-effective to store, organize, and use growing volumes of machine data to fuel AI and analytics.
  3. New tools like Agent Builder and AI Canvas let security and IT teams build custom AI agents and investigate issues using natural language, shifting operations from reactive to predictive.

This year at Cisco Live Las Vegas 2026, we are unveiling the next evolution of digital resilience. If you’ve been waiting for the moment when security and observability converge in a truly unified, agentic ecosystem, this is it.

At the core of this year’s excitement is the Cisco Data Fabric powered by the Splunk Platform—designed to become the system of record and intelligence layer for the agentic enterprise. Since joining forces with Cisco, we’ve been working tirelessly to bridge the gap between network infrastructure and data-driven insights. At Cisco Live, we’re pulling back the curtain on a wave of innovations designed to make your data work harder, smarter, and faster than ever before.

What to Expect: Innovation Highlights

This week in Las Vegas, you’ll see the future of the Splunk Platform in action. We’re organizing our latest Splunk Platform innovations into three key areas:

1. Unify your data at scale for faster, safer AI

We are breaking down the barriers that keep your data trapped in silos. With AI-Powered Data Management, we are making it easier to build and maintain data pipelines, using AI to automate data onboarding and pipeline management tasks. Combined with our expanded Federated Search capabilities, you can now query across your entire environment with unprecedented speed and precision, regardless of where your data resides..

Autodesk's story offers a strong example of what this can look like in practice. By using Federated Search, Autodesk improved data quality, optimized costs, and built a stronger foundation for AI. They reduced costs by 28% and reduced MTTR to under 30 minutes, while sustaining 15–30 second latency for critical application metrics to give SRE teams near-real-time visibility.

2. Fuel intelligence with contextualized machine data

Data is only as valuable as your ability to store, access, and act on it. With the Machine Data Lake (currently in Alpha), a scalable, high-performance storage foundation, you will be able to manage growing volumes of machine data more cost-effectively. It provides a secure landing environment where data can be automatically cataloged, enriched, and governed at scale without requiring immediate indexing, giving teams greater flexibility in how they store and access telemetry. For example, a global insurance company modeled approximately 50% lower spend while maintaining full-fidelity retention using Machine Data Lake.

Built-in Data Catalog capabilities help contextualize machine data, so it is easier to discover, understand, and use across analytics, investigations, and AI workflows. The result is a more efficient data strategy that preserves full-fidelity data, reduces unnecessary indexing costs, and helps ensure analytics and AI systems are fueled with the right data at the right time.

3. Activate agentic operations to move from reactive to predictive

This is where the full potential of the Splunk Platform comes to life. We are putting AI directly into the hands of your security, IT, and engineering teams with new capabilities designed to accelerate investigations, simplify operations, and help organizations move from reactive response to predictive, agentic action across the following areas:

First, we are introducing Agent Builder, the simplest, no-code way of building AgenticOps in Splunk for your security, network, and IT operations. You can build these agents customized around your data, tools, runbooks, and workflows. Users can define objectives in natural language, connect approved tools and knowledge sources, and deploy agents that run from Splunk searches and alerts. Teams can then review, validate, and interrogate results directly with the agent. Customers in the alpha program have already built custom automated triage, cross-stack IP investigation, and risk-summary agents. Agents are governed within Splunk with full transparency into agent activity. Agent Builder is an AI Toolkit feature that will be generally available on Splunk Cloud Platform Fall 2026.

Next, we are continuing to innovate with our Cisco Time Series Model by adding multivariate and covariate forecasting to deliver more accurate predictions and anomaly detection that adapt to your business cycles. The Cisco Time Series Model provides zero-shot forecasting, anomaly detection, and richer correlation across security, observability, and network data. These new capabilities will be released on Hugging Face as an open-weight model later this year.

Finally, with AI Canvas, teams can use natural language exploration and guided workflows to speed triage and root-cause analysis, while persistent, shareable context helps improve collaboration across sessions and teams. In addition, Splunk Platform, Splunk ITSI, and Splunk Observability Cloud will be available in Cisco Cloud Control, providing a unified operations front door across Cisco and Splunk environments. Organizations can reduce tool sprawl and context switching while gaining more correlated and explainable insights across domains.

Join the Journey

The innovation doesn’t stop when the lights go down in the convention center. Every feature we are showcasing is part of a deliberate, high-velocity roadmap. We’re committed to transparency and want customers and partners with us every step of the way as these innovations move from the demo stage to General Availability (GA).

Throughout the week, we’ll be hosting deep-dive sessions, hands-on labs, and exclusive "Meet the Engineer" roundtables. This is your chance to get under the hood, influence the roadmap, and see exactly how these solutions will solve your most pressing challenges.

Together, Cisco and Splunk are delivering powerful outcomes for the agentic era. As an added benefit of the combined Cisco and Splunk value, eligible Cisco Networking, Cisco Security and Firewall customers automatically benefit from enhanced value when bringing Cisco data into Splunk, reducing overall total cost of ownership and accelerating the Cisco and Splunk experience. Customers and partners should contact their Cisco account representatives for more information.

Tune Into Our Lineup of Sessions and Keynotes To Learn More

The highlight of our technical agenda is the Keynote Deep Dive session: Digital Resilience in the AI Era: Building a Secure and Trusted Agentic Enterprise. This session will explore how organizations can harness the power of autonomous agents while maintaining the rigorous security, trust, and governance necessary to thrive in an increasingly complex threat landscape. We’ll show you how to move from reactive defense to a predictive, agentic posture that anticipates disruptions before they impact your bottom line.

You can also attend—or watch replays of—our Product Strategy Overview (PSO) sessions featuring Splunk's platform product leaders:

Seth Brickman, VP, Global Product - Splunk Platform, Cisco

Tuesday, Jun 2, 2:00 PM - 2:30 PM PDT

Hanlin Fang, VP of Product Management - Splunk, Cisco

Monday, Jun 1, 1:00 PM - 1:30 PM PDT

Michael Sondag, GVP, Splunk Platform Specialists, Cisco

Wednesday, Jun 3, 2:30 PM - 3:00 PM PDT

Finally, be sure to visit the demo pods within the Digital Resilience area in the Showcase area. We will have experts ready to take you through a tour of these capabilities and answer your questions.

Stay Connected

The future of digital resilience is being built right here, right now, and it’s powered by you. We can’t wait to see you at Cisco Live Las Vegas 2026 in person or virtually. Let’s make this the most transformative year yet!

Related Articles

Macro-ATT&CK 2024: A Five-Year Perspective
Security
6 Minute Read

Macro-ATT&CK 2024: A Five-Year Perspective

Splunk’s Ryan Fetterman and Tamara Chacon dive into attacker techniques, trends, and blue team tips for analyzing and visualizing data from the past year.
What You Need to Know About Boss of the SOC
Security
3 Minute Read

What You Need to Know About Boss of the SOC

We introduced a new security activity at .conf2016 called “Boss of the SOC” (or BOTS), born from our belief that learning can be both realistic and fun.
Splunk Named #1 SIEM Provider in the 2022 IDC Market Share for SIEM for 3rd Time in a Row
Security
2 Minute Read

Splunk Named #1 SIEM Provider in the 2022 IDC Market Share for SIEM for 3rd Time in a Row

Splunk has been named as the #1 SIEM provider in the 2022 IDC Market Share for SIEM for the third time in a row.