Cisco and NVIDIA Bring Splunk AI to Enterprises

Cisco and NVIDIA Bring Splunk AI to Enterprises

Analyst(s): Fernando Montenegro
Publication Date: September 18, 2026

Cisco and NVIDIA expanded their partnership to bring Splunk AI into customer-controlled environments. Local deployment addresses sovereignty requirements, while the broader security and cost-management announcements leave operational results to be demonstrated.

What Is Covered in This Article:

  • The Cisco–NVIDIA relationship and local Splunk AI deployment.
  • Sovereignty requirements and the need for hybrid data access.
  • Token spending visibility and changes to platform pricing.
  • Agentic security operations and Splunk’s development agreement with AWS.

The News: Cisco introduced Cisco AI POD for Splunk at Splunk .conf in Denver on September 15, 2026, extending its NVIDIA partnership to support self-managed Splunk AI. The AI POD and AI Assistant are available now; Agent Launchpad is due later this year, with NVIDIA Nemotron models following in the coming months.

The company also announced Tokenomics capabilities, expanded Agent Observability into its cloud offerings, and added agentic security and Exposure Analytics capabilities. Splunk and AWS agreed to multi-year joint security development, while Activity-Based Pricing is scheduled for this fall.

Cisco and NVIDIA Bring Splunk AI to Enterprises

Analyst Take: Cisco’s most consequential move here is bringing Splunk AI to customers who need to keep sensitive data in their own environments. The NVIDIA partnership provides the infrastructure for that step, while support for local and cloud environments reflects the different restrictions customers place on their data. Customers now have more options for deploying AI, although allowing agents to take on more security work still requires evidence of their effectiveness.

NVIDIA Gives Splunk AI a Way Into the Data Center

The Cisco–NVIDIA partnership extends Splunk AI to customers that previously could not use it because their sensitive data had to remain outside the cloud. Cisco AI POD for Splunk brings together Cisco infrastructure, NVIDIA accelerated computing, and Splunk’s Kubernetes-native runtime in a configuration validated for Splunk workloads.

Customers can also deploy the software on their own infrastructure, with implementation support available from partners. The rollout remains incomplete: AI Assistant is available now, while Agent Launchpad is due later this year, and NVIDIA Nemotron models will follow in the coming months. For buyers, the immediate benefit is access to local Splunk AI, and deployment decisions should reflect what the companies can deliver today.

Hybrid Support Reflects How Customers Must Handle Data

Some organizations have no option but to move sensitive data to the cloud, regardless of the AI capabilities available there. Splunk AI now supports on-premises, private cloud, and air-gapped environments, while Agent Observability also extends into Splunk Observability Cloud and Cisco Cloud Control. These deployment options are particularly relevant to the healthcare, finance, and government organizations whose data must remain within their own environments.

Federated Search extensions to AWS CloudWatch Lake and Databricks, together with MCP-enabled Catalog Discovery, address another part of the problem by helping teams find and analyze distributed data without first migrating it. Customers should assess deployment and data access together, since keeping AI within an approved environment is useful only if it can reach the information needed for its work.

Customers Need to Know What Their Agents Cost

Tokenomics tackles a familiar budgeting problem: spending that becomes apparent only when the invoice arrives. It tracks token expenditure across agents and employee use of Claude Code, Codex, and Cursor, with consumption forecasting through Cisco Deep Time Series Model still to come.

Agent Observability brings spending information together with performance evaluation and runtime guardrails intended to block unsafe or inaccurate actions. Activity-Based Pricing adds a further consideration this fall, when Splunk plans to give search and ingest equal weight in its pricing. Buyers should use these capabilities to assess the cost of individual workloads before deciding whether wider agent adoption makes financial sense.

AWS and Splunk Still Have Details to Provide

The AWS agreement sets a direction for joint security development, although customers still need to know which products it will produce and when. Splunk’s expanded Agentic SOC Workforce covers detection engineering, threat hunting, investigation, response, and governance, with more than 1,300 security integrations.

Exposure Analytics adds asset coverage and historical context, but the announcement gives buyers no quantified measure of the resulting improvement in security operations. The Futurum Group’s 1H 2026 Cybersecurity Market Sizing & Five-Year Forecast projects $77 billion in incremental annual spending by CY2031 across Cloud Security, Security Operations & GRC, Data Security, and Application Security. Cisco is pursuing a substantial opportunity, and earning more responsibility inside the SOC will require evidence that these capabilities improve investigations while keeping analysts in control.

What to Watch:

  • Will Agent Launchpad and NVIDIA Nemotron models arrive within the announced windows, and which local workflows will each support at release?
  • How effectively will Federated Search and MCP-enabled Catalog Discovery provide relevant context across data sources that customers keep in separate environments?
  • When will Tokenomics forecasting become available, and how accurately will it project consumption before a billing period ends?
  • What will Activity-Based Pricing mean for customers with different search and ingest patterns?
  • Can the Essentials and Premier security editions demonstrate reduced alert noise and faster remediation while preserving analyst control?
  • Which products will emerge from the AWS agreement, and when will customers be able to evaluate them?

See the complete announcement on Splunk AI and its expanded security capabilities on Cisco’s website.


Declaration of generative AI and AI-assisted technologies in the writing process: This content has been generated with the support of artificial intelligence technologies. Due to the fast pace of content creation and the continuous evolution of data and information, The Futurum Group and its analysts strive to ensure the accuracy and factual integrity of the information presented. However, the opinions and interpretations expressed in this content reflect those of the individual author/analyst. The Futurum Group makes no guarantees regarding the completeness, accuracy, or reliability of any information contained herein. Readers are encouraged to verify facts independently and consult relevant sources for further clarification.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Read the full Futurum Group Disclosure.

Other Insights From Futurum:

Cisco Q4 FY 2026 Earnings Point to Broader AI Infrastructure Demand

Cisco Live 2026: Platform, Silicon, and Security for the Agentic Era

Can Cisco Widen Splunk’s Agentic SOC Capabilities With WideField?

Author Information

Fernando Montenegro

Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.

Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.

Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

Related Insights
Salesforce and Google Cloud Expand Access to CRM Workflows
September 18, 2026

Salesforce and Google Cloud Expand Access to CRM Workflows

Keith Kirkpatrick, Research Director at The Futurum Group, examines Salesforce’s Google Cloud expansion and the tests ahead for enterprise workflows and commerce....
Zscaler Launches Agentic SOC, Betting on Telemetry Over Model Horsepower
September 18, 2026

Zscaler Launches Agentic SOC, Betting on Telemetry Over Model Horsepower

Fernando Montenegro, VP at Futurum, analyzes Zscaler's launch of Agentic SOC and why its inline telemetry, decoy mesh, and Red Canary detection matter more than the AI agents themselves....
Thales HexaForce: Can Sovereign AI C2 Capture NATO's Next Wave?
September 18, 2026

Thales HexaForce: Can Sovereign AI C2 Capture NATO's Next Wave?

Thales launched HexaForce, an AI-enhanced command and control system validated at NATO CWIX 2026, positioning the company to capture growing allied defense spending on interoperable security solutions....
Sierra's AIUC-1 Certification Sets a New Bar for Agentic AI Trust
September 18, 2026

Sierra's AIUC-1 Certification Sets a New Bar for Agentic AI Trust

Sierra achieves AIUC-1 certification, the first standard purpose-built for AI agent behavior. Independent audit and adversarial testing validate reliability and security for regulated industries....
Can AWS and Salesforce Turn Connected Data Into Better Execution
September 17, 2026

Can AWS and Salesforce Turn Connected Data Into Better Execution?

Keith Kirkpatrick, Research Director at The Futurum Group shares insights on AWS and Salesforce’s expanded integrations and the tests that matter for enterprise adoption....
Can Samsung and Verizon Make Network Sensing Useful for Venues
September 17, 2026

Can Samsung and Verizon Make Network Sensing Useful for Venues?

Tom Hollingsworth, Networking Technology Advisor and Event Lead at Futurum, shares insights on Samsung and Verizon’s network sensing trial and its implications for venue operations....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.