Analyst(s): Fernando Montenegro
Publication Date: September 22, 2026
What Is Covered in This Article:
- What Splunk highlighted: Cisco Data Fabric, an expanded agentic SOC, tokenomics, and on-premises AI with NVIDIA.
- Why trust only counts when the platform enforces it, not when a human rubber-stamps it.
- Whether the cost reset lowers the bill or just moves it.
- The Cisco dividend: culture, ecosystem reach, and a contested layer.
- The “buy, build, or outsource” decision regarding agentic SOC.
The Event—Major Themes & Vendor Moves: Splunk held .conf26, its flagship user conference, in Denver from September 14 to 16, 2026, with the Cisco integration now roughly two and a half years in and increasingly visible across the product line.
The week had one throughline: trust is the gate on scaling AI, and the layer beneath the agents is where that trust is won or lost. Packaged as “Splunk reimagined” and “trusted AI at scale,” it ran through the welcome keynote by Cisco President and Chief Product Officer Jeetu Patel and Splunk SVP and GM Kamal Hathi, and announced more than 200 product launches over the past year.
The tension is real for buyers. In Futurum’s 1H2026 Cybersecurity Decision-Makers Survey, 44.3% of respondents agreed they are intentionally delaying deployment of internal AI copilots or agents until they have better security guarantees (N=929, unweighted). Splunk grouped its news around three pillars: optimize AI at scale, defend at machine speed, and turn machine data into agentic action.
The data foundation: Cisco Data Fabric
The centerpiece is the Cisco Data Fabric, powered by the Splunk platform, which the company positions as a way to analyze data where it lives rather than copying everything into Splunk. Splunk proposes that it:
- Federates and correlates across Splunk, cloud object stores, data lakes, and platforms, including Snowflake and Databricks, with federated search now reaching AWS CloudWatch.
- Combines a machine data lake, catalog, universal collector, and real-time ingest processing.
- Adds domain-specific models (time-series forecasting, log analysis, graph reasoning) that complement, not replace, frontier models.
Splunk pitched this as its answer to its oldest criticism, ingest and indexing cost. Hathi framed the goal as roughly 10 times the capacity at a flat bill, so customers can “stop agonizing over what data you can afford.”
Running AI where your data lives
Cisco and NVIDIA expanded their partnership to bring self-managed Splunk AI on-premises:
- Cisco AI POD for Splunk, the newest Cisco Secure AI Factory with NVIDIA configuration, is available now; partners, including Accenture, Wipro, World Wide Technology, and others, can stand it up.
- Splunk AI Assistant runs on it today; Agent Launchpad (custom agents, MCP connections, human controls) is slated for later this year.
- Customers can self-host models, including the Cisco Deep Time Series Model, Google Gemma 4, and OpenAI GPT-OSS 20B, with NVIDIA Nemotron coming.
Separately, Splunk and AWS formalized a multi-year agreement to jointly develop agent-focused security offerings.
Observability and tokenomics
Splunk announced general availability of Splunk Agent Observability across Observability Cloud and as a native Cisco Cloud Control application. The company says it evaluates every event without sampling and applies runtime guardrails that block unsafe actions such as hallucinations or data leakage. Added alongside it:
- Tokenomics, which tracks and attributes token spend across agents and coding tools (Claude Code, Codex, Cursor, and others) and forecasts consumption before a billing period ends.
- Observability Studio, guided OpenTelemetry so apps are “born observable,” plus a Network Intelligence App and new Essentials and Premier editions.
The agentic SOC
Splunk expanded its Agentic SOC Workforce with purpose-built agents across detection engineering, threat hunting, investigation, response, and governance. Per the company, they share context, correlate full-stack machine data, and deliver explainable verdicts, with customers setting how much autonomy each agent gets (for example, automating triage while keeping account or infrastructure actions subject to approval). Packaging splits into:
- Enterprise Security Essentials, for teams that want analysts to make the final call.
- Enterprise Security Premier, for customers ready for more autonomous defense.
Exposure Analytics enhancements add broader asset discovery, historical change tracking, and business context to risk scoring, spanning Splunk, Cisco, and third-party sources.
Splunk .conf26: Trust is Key for the Agentic Era
Analyst Take: Splunk used its keynote time to address an unglamorous question: what a customer must believe before it will let agents run a security operations center. We think that this was the right call.
In terms of technology, capability is largely settled. According to what we see in industry, what holds agentic adoption back is confidence and cost, both of which lie beneath the agents, in the data and controls that wrap around them.
Splunk, now inside Cisco, is betting on that layer. If agents are the new workforce, the data, observability, and control plane they run on is the system of record for machine behavior, and that record may matter more than any single agent running on it.
Two questions stayed with us. Is the trust on the label enforced by the platform, or does it still come down to a human clicking approve? And does owning this layer mean the customer pays less, or just pays differently?
Trust as a Control
Splunk’s position seems to be that trust is something you enforce, not assert. The autonomy ladder showed, with automated triage but keeping account lockouts and infrastructure isolation behind a person, that it is the right shape and matches how practitioners describe it: an agent earns scope like a new hire. That said, we feel that the metaphor travels only so far: a colleague carries boundaries and accountability in ways an agent does not, whatever we call it.
A human in front of every action is not the safeguard it appears to be, because anyone who has watched an analyst clear a queue knows that cognitive factors such as habituation mean they end up approving almost everything. What holds the line sits below the person: guardrails that block unsafe actions, and evaluators that assess an agent’s confidence and downgrade a shaky verdict before it reaches anyone.
We are positive on the updated packaging. Splitting Enterprise Security into an Essentials tier that keeps analysts in charge and a Premier tier that runs more autonomously gives organizations a path to grow without undue costs.
The Economics Reset
Cost has trailed Splunk its whole life, and the company went straight at it during .conf: the Cisco Data Fabric shifts the pitch from “send us your data to analyze it where it sits,” with Hathi promising ten times the capacity at a flat bill. Futurum’s ETR data says the appetite is there, one in five surveyed Splunk customers already using the AI Assistant and another quarter piloting it (July 2026, n=143).
The saving is real but partial. Federating across object stores, Snowflake, and others avoids copying and re-indexing everything, yet data elsewhere still has to be read, moved, and paid for. Whether the total falls or just shifts to another line is the part that the pitch does not answer fully, and much of the fabric is yet to be made available in large numbers.
Tokenomics carries the same limit. Splunk can now watch token spend in real time and forecast it before the invoice lands, down to which team’s use of coding agents like Claude Code or Codex is driving it. That is real and overdue. But attributing a cost is not the same as containing it, and closing that gap still falls to a human with a budget and a policy.
The Cisco Dividend
Thinking about the Splunk acquisition itself, it’s expected that deals of this size usually flatten what they absorb, and culture is the tell. Two and a half years in, .conf26 still felt like Splunk’s show, fezzes, Boss of the SOC, and Buttercup intact. For a platform whose stickiness rests on its community, keeping that through an integration this large counts for something.
It’s interesting to see how the deal elevates the conversation. A previously standalone Splunk might not have had what it took to put NVIDIA, Intel, and a roster of frontier and open models on one stage, or walk into the CIO’s room when strategic vendors plan for AI. Cisco does, and Splunk rides in with it, backed by integrators standing up the AI POD, some 1,300 security integrations, and Cisco Cloud Control as the plug-in point. That is the gravity that a pure-play cannot easily manufacture.
None of this means the work is done. A company this size is not folded into Cisco in thirty months, and buyers still feel the seams in how they are sold to and supported. Splunk is not alone in reaching for this layer, either: CrowdStrike, Microsoft, Palo Alto Networks, Fortinet, and others make the same claim, each with a security stack and SIEM. Cisco’s breadth is a differentiator, but the layer is contested from several directions, including agile startups.
Security and Observability, and the Harder Part Underneath
Cisco’s proposed long-term merging of security and observability capabilities is sound, in part because security problems come first. When an agent misbehaves, security signals alone often cannot tell you whether it was breached, fed a poisoned prompt, or just followed a bad instruction to an expensive conclusion. Those three look alike in the telemetry, and only a shared trail across application, network, and security data separates them. The old “bug or attack” question loses its clean answer once the system is nondeterministic.
Security and observability sit in different teams, with different budgets, and Splunk’s year-end move to join those datasets admits the architecture has outrun the org chart. It also drops Splunk into a second contest, against observability specialists like Datadog, Dynatrace, and others, at the same time as the security field.
The harder problem sits underneath. Watching an agent is not the same as knowing what it did: latency, traces, and token counts describe the mechanism, while the outcome, whether it booked the right trip or approved the wrong claim, is what a business answers for. An agent that honors an expired discount at a rate pegged near half a million dollars an hour throws no error while every signal reads healthy. Agent Observability is reaching toward business-level data with evaluators and guardrails; the test is whether it can judge outcomes and name who owns a bad one.
The Agentic SOC and the Decision it Forces
The agentic SOC was the center of gravity in security news this week, and Splunk’s expanded agent workforce across detection engineering, threat hunting, investigation, response, and governance is a serious undertaking. For a buyer, the question is less whether it works than whether to buy it here, build it, or outsource the problem.
Who is asking decides the answer. A large, sophisticated team can build much of this in-house, preferring to own the logic rather than rent it. A four-person SOC faces the opposite arithmetic: once agentic operations are table stakes, the real choice is between buy and outsource, the way people move from doing their own taxes to hiring an accountant. Essentials and Premier speak to the first group; the second may skip the product for a managed service, which Cisco can sell to them, too.
Defensive AI carries an asymmetry that does not currently favor the defender, and it deserves the same honesty as the wins. Confirming that an offensive technique worked is cheap; proving a defense holds means proving a negative, so offensive capability tends to compound faster. Splunk’s target of high recall with low noise is the right one, and the part worth pressure-testing is the failure nobody sees, the missed detection that leaves no alert behind to audit.
Proof and caution came from the same stage. A US energy utility cut detection-and-response time for a cloud identity incident from roughly 20 minutes to under a minute once it trusted automation to act, then described the reverse: turning AI on before its data foundation was ready and drowning analysts in false positives. Agentic tooling amplifies whatever it sits on, which puts the unglamorous data work ahead of the agents.
What to Watch:
- Does the cost math actually change? The Data Fabric and tokenomics answer the ingest-cost complaint on paper, but with FedRAMP and on-premises federation dated to 2027, the real question is whether total cost falls or just moves to egress and compute.
- Is trust enforced or only labeled? As Premier pushes further into autonomous defense, the test is whether guardrails and evaluators hold the line, or whether governance slides back to a human approving whatever the queue serves up.
- Can observability judge outcomes, not just telemetry? Agent Observability reaches toward business-level data. Can it tell a correct business result from an expensive mistake, and can anyone be held to the answer?
- Does the system-of-record claim hold? CrowdStrike, Microsoft, Palo Alto Networks, Fortinet, Datadog, and others are reaching for the same layer, so where large buyers actually consolidate, as the agentic SOC matures, is what to watch.
- Build, buy, or outsource? For smaller teams, agentic operations may accelerate a move to managed services over in-house adoption, and whether Cisco ends up selling the platform, the service, or both will tell you how it lands.
For more information, read the full announcement from Cisco.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Other Insights From Futurum:
Cisco and NVIDIA Bring Splunk AI to Enterprises
Can Cisco Widen Splunk’s Agentic SOC Capabilities With WideField?
A Loud Floor and a Quiet Gap: Security Summer Camp 2026
Cisco Live 2026: Platform, Silicon, and Security for the Agentic Era
Author Information
Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.
Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.
Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

