From Vision to Value: New Splunk Platform Innovations Supporting Cisco Data Fabric Are Generally Available

Platform Mangesh Pimpalkhare

Key takeaways

  1. New Splunk Platform capabilities help organizations find, connect, and manage machine data across environments without moving everything into one place.
  2. Better data management gives people and AI trusted, high quality context to investigate issues, make decisions, and respond faster.
  3. Built in AI agents and reusable agent skills help teams automate common tasks while maintaining visibility, governance, and control.

At .conf25, we announced our vision for Cisco Data Fabric, an architecture designed to help organizations unlock the value of machine data, fuel AI with trusted context, and support more intelligent and resilient operations.

Today, that vision has become reality.

Key Splunk Platform innovations including Machine Data Lake, Catalog, and Agent Launchpad, together with expanded Federated Search and Data Management capabilities, are now generally available. You can begin using these Splunk Platform innovations today to federate data, correlate at scale and unlock machine data for AI.

This milestone reflects a journey from intent to value—Cisco Data Fabric powered by the Splunk Platform is the system of record and intelligence for the agentic enterprise. It represents the architecture for connecting and activating distributed operational data, while the Splunk Platform is the data platform that brings the architecture to life through capabilities for managing, accessing, understanding, and acting on that data.

Together, these innovations move the architecture from vision to an operational foundation you can put to work today—turning distributed machine data into the trusted context that humans and AI need to act.

The AI Challenge Amplifies the Age-Old Data Challenge

Security, IT, engineering, observability, and network teams are already managing unprecedented volumes of operational data across cloud platforms, on-premises systems, applications, networks, SaaS services, and data lakes.

AI compounds this challenge in two directions. AI applications and agents generate additional telemetry, while also requiring timely access to more of an organization’s existing data. They need to find and reason across information that spans different systems, formats, owners, retention policies, and governance requirements.

As organizations scale AI, these demands expose the limits of architectures built around moving all data to one place. They also expose operational processes that still depend on manual onboarding, normalization, and maintenance.

The result is a difficult cycle: more data creates more cost and complexity, while fragmented, inaccessible, or poorly understood data limits the value organizations can realize from AI.

The answer is not simply to collect more. Organizations need the flexibility to place data according to its value, find and search it across environments, maintain its quality, and activate it with the appropriate context and controls.

Today, Cisco Data Fabric powered by the Splunk Platform helps them to do that —at machine speed, at scale—delivering a unified data journey into a cohesive source of truth.

From Security Signals to Autonomous Response

Consider a security team investigating suspicious activity involving a privileged account. The initial signal is visible in Splunk, but the full story may span identity events, endpoint telemetry, network activity, cloud logs, and historical data retained elsewhere.

To connect activity across these sources, the team first needs the data onboarded, normalized, and kept Common Information Model (CIM) compliant. Our latest Data Management enhancements help compress work that can take weeks into minutes. Guided Onboarding acts as an in-product expert, leading administrators through best-practice setup, while Auto Schematization recommends CIM mappings and generates the configuration artifacts needed to correlate events sooner.

As data sources evolve, Self-Healing Pipelines detect CIM compliance drift and surface AI-generated remediation recommendations for administrators to review, helping keep the data accurate and useful throughout the investigation.

The team also needs access to historical and distributed evidence. The new Machine Data Lake provides a Splunk-managed environment for landing and retaining full-fidelity machine data at scale, making the data available for promotion across higher-performance tiers when premium costs warrant. Catalog helps the investigator identify relevant datasets and understand their metadata. Expanded Federated Search capabilities extend the investigation across supported external data environments without requiring every dataset to be moved or duplicated.

With the evidence assembled, Agent Launchpad then helps the analyst move from investigation to action. Analysts can build an agent, choose the LLM, connect to tools, select agent skills, without coding or data science expertise. If a suspicious activity was detected in the privileged account login pattern, the alert can launch the agent - with relevant context already attached - to investigate related activities, summarize evidence, and recommend or take approved next steps. Administrators retain control through role-based access control, governing who can access agents, data, and approved tools. Every agent run remains traceable, so the team can review the evidence, inspect tool usage, and ask follow-up questions before responding.

To further accelerate agentic operations in the enterprise, we just launched Splunk agent skills, available in Github to the open source community. Splunk agent skills give agents reusable, task-specific instructions that help them perform common security and operations workflows more consistently and accurately. This initial release introduces the first three Splunk-built skills as a curated starting point, making it easier for customers to add proven expertise to their agents.

Instead of spending valuable time locating data and moving between disconnected systems, practitioners can focus their expertise on understanding risk and determining the appropriate response.

Turn Machine Data Into Agentic Action

The above security scenario illustrates three outcomes that help you turn machine data into agentic action.

Federate Data: Analyze Data Where It Lives at Lower Costs

Data economics improve when organizations can align storage, search, and processing with the value their data offers the organization, instead of treating every dataset alike. Splunk Platform capabilities like Machine Data Lake and Federated Search provide that flexibility, helping reduce unnecessary data movement and duplication while preserving access to operational context when it is needed.

This approach also extends to Cisco-generated telemetry. Eligible Cisco security, network, and operational data is automatically recognized in Splunk and receives a built-in 50% weighted ingest rate. This helps organizations bring more Cisco telemetry into Splunk cost-effectively, expanding the operational context available through the Splunk Platform.

Correlate at Scale: Connect Data in Real-Time Across Domains

When data is easier to onboard, maintain, discover, and search, teams gain a more complete view of an incident. Trusted context helps practitioners investigate and respond faster without sacrificing visibility or oversight.

Operating at machine speed requires more than accessible data. Teams need real-time connections across applications, identities, assets, and networks. Splunk correlates signals and governed context across domains, helping IT and security teams understand an incident’s scope, assess its impact, and act before the underlying threat creates enterprise-wide risk.

Unlock Machine Data for AI To Power Resilient Agentic Operations

AI is only as effective as the information and context available to it. Raw data alone is not enough.

AI systems need data that is discoverable, accurate, relevant, and governed, along with clear boundaries defining which tools and knowledge sources they can access. Practitioners also need visibility into the evidence supporting AI-generated recommendations.

By improving data quality and discoverability and integrating traceable agents into existing Splunk workflows, these capabilities help organizations move from isolated AI experiments to practical, governed, and resilient agentic operations.

Start Putting the Architecture to Work

The general availability of these innovations is an important step forward for achieving AI readiness —and for every customer working to turn growing volumes of machine data into meaningful outcomes.

Over the coming weeks, we will publish a series of blogs examining each release in greater detail, including how the capabilities work and how teams can apply them within their environments.

For now, I encourage you to begin using these innovations and consider where more flexible data management, unified discovery and search, and governed agent assistance can make the greatest difference in your organization.

And join us at .conf26, September 14–17 in Denver, where we will share how Cisco Data Fabric powered by the Splunk Platform will continue to evolve. I look forward to seeing you there.

Related Articles

Add to Chrome? - Part 2: How We Did Our Research
Security
5 Minute Read

Add to Chrome? - Part 2: How We Did Our Research

SURGe explores the analysis pipeline in more detail and digs into the two main phases of this research – how the team collected the data and how they analyzed it.
Detecting Copy Fail (CVE-2026-31431)– Phenomenal Power, Ity Bity Script
Security
15 Minute Read

Detecting Copy Fail (CVE-2026-31431)– Phenomenal Power, Ity Bity Script

The Splunk Threat Research Team analyzes the VIP Keylogger malware to help improve your detection and threat-hunting strategies.
Staff Picks for Splunk Security Reading October 2022
Security
3 Minute Read

Staff Picks for Splunk Security Reading October 2022

Check out October's list of presentations, whitepapers, and customer case studies that our Splunk security experts feel are worth a read.