Splunk .conf26: Trust is Key for the Agentic Era

Splunk .conf26 Trust is Key for the Agentic Era

Analyst(s): Fernando Montenegro
Publication Date: September 22, 2026

What Is Covered in This Article:

  • What Splunk highlighted: Cisco Data Fabric, an expanded agentic SOC, tokenomics, and on-premises AI with NVIDIA.
  • Why trust only counts when the platform enforces it, not when a human rubber-stamps it.
  • Whether the cost reset lowers the bill or just moves it.
  • The Cisco dividend: culture, ecosystem reach, and a contested layer.
  • The “buy, build, or outsource” decision regarding agentic SOC.

The Event—Major Themes & Vendor Moves: Splunk held .conf26, its flagship user conference, in Denver from September 14 to 16, 2026, with the Cisco integration now roughly two and a half years in and increasingly visible across the product line.

The week had one throughline: trust is the gate on scaling AI, and the layer beneath the agents is where that trust is won or lost. Packaged as “Splunk reimagined” and “trusted AI at scale,” it ran through the welcome keynote by Cisco President and Chief Product Officer Jeetu Patel and Splunk SVP and GM Kamal Hathi, and announced more than 200 product launches over the past year.

The tension is real for buyers. In Futurum’s 1H2026 Cybersecurity Decision-Makers Survey, 44.3% of respondents agreed they are intentionally delaying deployment of internal AI copilots or agents until they have better security guarantees (N=929, unweighted). Splunk grouped its news around three pillars: optimize AI at scale, defend at machine speed, and turn machine data into agentic action.

The data foundation: Cisco Data Fabric

The centerpiece is the Cisco Data Fabric, powered by the Splunk platform, which the company positions as a way to analyze data where it lives rather than copying everything into Splunk. Splunk proposes that it:

  • Federates and correlates across Splunk, cloud object stores, data lakes, and platforms, including Snowflake and Databricks, with federated search now reaching AWS CloudWatch.
  • Combines a machine data lake, catalog, universal collector, and real-time ingest processing.
  • Adds domain-specific models (time-series forecasting, log analysis, graph reasoning) that complement, not replace, frontier models.

Splunk pitched this as its answer to its oldest criticism, ingest and indexing cost. Hathi framed the goal as roughly 10 times the capacity at a flat bill, so customers can “stop agonizing over what data you can afford.”

Running AI where your data lives

Cisco and NVIDIA expanded their partnership to bring self-managed Splunk AI on-premises:

  • Cisco AI POD for Splunk, the newest Cisco Secure AI Factory with NVIDIA configuration, is available now; partners, including Accenture, Wipro, World Wide Technology, and others, can stand it up.
  • Splunk AI Assistant runs on it today; Agent Launchpad (custom agents, MCP connections, human controls) is slated for later this year.
  • Customers can self-host models, including the Cisco Deep Time Series Model, Google Gemma 4, and OpenAI GPT-OSS 20B, with NVIDIA Nemotron coming.

Separately, Splunk and AWS formalized a multi-year agreement to jointly develop agent-focused security offerings.

Observability and tokenomics

Splunk announced general availability of Splunk Agent Observability across Observability Cloud and as a native Cisco Cloud Control application. The company says it evaluates every event without sampling and applies runtime guardrails that block unsafe actions such as hallucinations or data leakage. Added alongside it:

  • Tokenomics, which tracks and attributes token spend across agents and coding tools (Claude Code, Codex, Cursor, and others) and forecasts consumption before a billing period ends.
  • Observability Studio, guided OpenTelemetry so apps are “born observable,” plus a Network Intelligence App and new Essentials and Premier editions.

The agentic SOC

Splunk expanded its Agentic SOC Workforce with purpose-built agents across detection engineering, threat hunting, investigation, response, and governance. Per the company, they share context, correlate full-stack machine data, and deliver explainable verdicts, with customers setting how much autonomy each agent gets (for example, automating triage while keeping account or infrastructure actions subject to approval). Packaging splits into:

  • Enterprise Security Essentials, for teams that want analysts to make the final call.
  • Enterprise Security Premier, for customers ready for more autonomous defense.

Exposure Analytics enhancements add broader asset discovery, historical change tracking, and business context to risk scoring, spanning Splunk, Cisco, and third-party sources.

Splunk .conf26: Trust is Key for the Agentic Era

Analyst Take: Splunk used its keynote time to address an unglamorous question: what a customer must believe before it will let agents run a security operations center. We think that this was the right call.

In terms of technology, capability is largely settled. According to what we see in industry, what holds agentic adoption back is confidence and cost, both of which lie beneath the agents, in the data and controls that wrap around them.

Splunk, now inside Cisco, is betting on that layer. If agents are the new workforce, the data, observability, and control plane they run on is the system of record for machine behavior, and that record may matter more than any single agent running on it.

Two questions stayed with us. Is the trust on the label enforced by the platform, or does it still come down to a human clicking approve? And does owning this layer mean the customer pays less, or just pays differently?

Trust as a Control

Splunk’s position seems to be that trust is something you enforce, not assert. The autonomy ladder showed, with automated triage but keeping account lockouts and infrastructure isolation behind a person, that it is the right shape and matches how practitioners describe it: an agent earns scope like a new hire. That said, we feel that the metaphor travels only so far: a colleague carries boundaries and accountability in ways an agent does not, whatever we call it.

A human in front of every action is not the safeguard it appears to be, because anyone who has watched an analyst clear a queue knows that cognitive factors such as habituation mean they end up approving almost everything. What holds the line sits below the person: guardrails that block unsafe actions, and evaluators that assess an agent’s confidence and downgrade a shaky verdict before it reaches anyone.

We are positive on the updated packaging. Splitting Enterprise Security into an Essentials tier that keeps analysts in charge and a Premier tier that runs more autonomously gives organizations a path to grow without undue costs.

The Economics Reset

Cost has trailed Splunk its whole life, and the company went straight at it during .conf: the Cisco Data Fabric shifts the pitch from “send us your data to analyze it where it sits,” with Hathi promising ten times the capacity at a flat bill. Futurum’s ETR data says the appetite is there, one in five surveyed Splunk customers already using the AI Assistant and another quarter piloting it (July 2026, n=143).

The saving is real but partial. Federating across object stores, Snowflake, and others avoids copying and re-indexing everything, yet data elsewhere still has to be read, moved, and paid for. Whether the total falls or just shifts to another line is the part that the pitch does not answer fully, and much of the fabric is yet to be made available in large numbers.

Tokenomics carries the same limit. Splunk can now watch token spend in real time and forecast it before the invoice lands, down to which team’s use of coding agents like Claude Code or Codex is driving it. That is real and overdue. But attributing a cost is not the same as containing it, and closing that gap still falls to a human with a budget and a policy.

The Cisco Dividend

Thinking about the Splunk acquisition itself, it’s expected that deals of this size usually flatten what they absorb, and culture is the tell. Two and a half years in, .conf26 still felt like Splunk’s show, fezzes, Boss of the SOC, and Buttercup intact. For a platform whose stickiness rests on its community, keeping that through an integration this large counts for something.

It’s interesting to see how the deal elevates the conversation. A previously standalone Splunk might not have had what it took to put NVIDIA, Intel, and a roster of frontier and open models on one stage, or walk into the CIO’s room when strategic vendors plan for AI. Cisco does, and Splunk rides in with it, backed by integrators standing up the AI POD, some 1,300 security integrations, and Cisco Cloud Control as the plug-in point. That is the gravity that a pure-play cannot easily manufacture.

None of this means the work is done. A company this size is not folded into Cisco in thirty months, and buyers still feel the seams in how they are sold to and supported. Splunk is not alone in reaching for this layer, either: CrowdStrike, Microsoft, Palo Alto Networks, Fortinet, and others make the same claim, each with a security stack and SIEM. Cisco’s breadth is a differentiator, but the layer is contested from several directions, including agile startups.

Security and Observability, and the Harder Part Underneath

Cisco’s proposed long-term merging of security and observability capabilities is sound, in part because security problems come first. When an agent misbehaves, security signals alone often cannot tell you whether it was breached, fed a poisoned prompt, or just followed a bad instruction to an expensive conclusion. Those three look alike in the telemetry, and only a shared trail across application, network, and security data separates them. The old “bug or attack” question loses its clean answer once the system is nondeterministic.

Security and observability sit in different teams, with different budgets, and Splunk’s year-end move to join those datasets admits the architecture has outrun the org chart. It also drops Splunk into a second contest, against observability specialists like Datadog, Dynatrace, and others, at the same time as the security field.

The harder problem sits underneath. Watching an agent is not the same as knowing what it did: latency, traces, and token counts describe the mechanism, while the outcome, whether it booked the right trip or approved the wrong claim, is what a business answers for. An agent that honors an expired discount at a rate pegged near half a million dollars an hour throws no error while every signal reads healthy. Agent Observability is reaching toward business-level data with evaluators and guardrails; the test is whether it can judge outcomes and name who owns a bad one.

The Agentic SOC and the Decision it Forces

The agentic SOC was the center of gravity in security news this week, and Splunk’s expanded agent workforce across detection engineering, threat hunting, investigation, response, and governance is a serious undertaking. For a buyer, the question is less whether it works than whether to buy it here, build it, or outsource the problem.

Who is asking decides the answer. A large, sophisticated team can build much of this in-house, preferring to own the logic rather than rent it. A four-person SOC faces the opposite arithmetic: once agentic operations are table stakes, the real choice is between buy and outsource, the way people move from doing their own taxes to hiring an accountant. Essentials and Premier speak to the first group; the second may skip the product for a managed service, which Cisco can sell to them, too.

Defensive AI carries an asymmetry that does not currently favor the defender, and it deserves the same honesty as the wins. Confirming that an offensive technique worked is cheap; proving a defense holds means proving a negative, so offensive capability tends to compound faster. Splunk’s target of high recall with low noise is the right one, and the part worth pressure-testing is the failure nobody sees, the missed detection that leaves no alert behind to audit.

Proof and caution came from the same stage. A US energy utility cut detection-and-response time for a cloud identity incident from roughly 20 minutes to under a minute once it trusted automation to act, then described the reverse: turning AI on before its data foundation was ready and drowning analysts in false positives. Agentic tooling amplifies whatever it sits on, which puts the unglamorous data work ahead of the agents.

What to Watch:

  • Does the cost math actually change? The Data Fabric and tokenomics answer the ingest-cost complaint on paper, but with FedRAMP and on-premises federation dated to 2027, the real question is whether total cost falls or just moves to egress and compute.
  • Is trust enforced or only labeled? As Premier pushes further into autonomous defense, the test is whether guardrails and evaluators hold the line, or whether governance slides back to a human approving whatever the queue serves up.
  • Can observability judge outcomes, not just telemetry? Agent Observability reaches toward business-level data. Can it tell a correct business result from an expensive mistake, and can anyone be held to the answer?
  • Does the system-of-record claim hold? CrowdStrike, Microsoft, Palo Alto Networks, Fortinet, Datadog, and others are reaching for the same layer, so where large buyers actually consolidate, as the agentic SOC matures, is what to watch.
  • Build, buy, or outsource? For smaller teams, agentic operations may accelerate a move to managed services over in-house adoption, and whether Cisco ends up selling the platform, the service, or both will tell you how it lands.

For more information, read the full announcement from Cisco.


Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.

Other Insights From Futurum:

Cisco and NVIDIA Bring Splunk AI to Enterprises

Can Cisco Widen Splunk’s Agentic SOC Capabilities With WideField?

A Loud Floor and a Quiet Gap: Security Summer Camp 2026

Cisco Live 2026: Platform, Silicon, and Security for the Agentic Era

Author Information

Fernando Montenegro

Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.

Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.

Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

Related Insights
AI Fuels Record Cyberattacks in Italy, and a Channel Opportunity
September 22, 2026

AI Fuels Record Cyberattacks in Italy, and a Channel Opportunity

Exprivia's Q2 2026 threat report reveals record AI-driven cyberattacks on Italian organizations, as cybersecurity becomes a top revenue driver for global channel partners....
Wiz Bets on MCP to Make WIN the AI Security Integration Layer
September 22, 2026

Wiz Bets on MCP to Make WIN the AI Security Integration Layer

Wiz's MCP-powered agent integrations let partner AI agents access live security context during investigations, positioning the company at the forefront of AI-driven security innovation in a market forecast to reach...
Fastly Bets the Edge on AI Governance as Machine Traffic Tops 50%
September 22, 2026

Fastly Bets the Edge on AI Governance as Machine Traffic Tops 50%

Fastly's new AI Runtime Control, AI Firewall, and API Security capabilities address enterprise security urgency as machine-generated traffic crosses 50% on its network, with AI traffic growing 6.5x faster than...
Lattice Mach-N2 Turns the Post-Quantum Procurement Gate Into an FPGA Moat
September 21, 2026

Lattice Mach-N2 Turns the Post-Quantum Procurement Gate Into an FPGA Moat

Brendan Burke, Research Director at Futurum, shares his insights on why Lattice Mach-N2's full CNSA 2.0 compliance and integrated flash extend the secure control FPGA lead as the post-quantum procurement...
Cisco and NVIDIA Bring Splunk AI to Enterprises
September 18, 2026

Cisco and NVIDIA Bring Splunk AI to Enterprises

Fernando Montenegro, VP at The Futurum Group, shares insights on Splunk AI, the Cisco–NVIDIA partnership, and enterprise requirements for hybrid deployment....
Zscaler Launches Agentic SOC, Betting on Telemetry Over Model Horsepower
September 18, 2026

Zscaler Launches Agentic SOC, Betting on Telemetry Over Model Horsepower

Fernando Montenegro, VP at Futurum, analyzes Zscaler's launch of Agentic SOC and why its inline telemetry, decoy mesh, and Red Canary detection matter more than the AI agents themselves....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.