What's Happening?
Splunk, a Cisco company, is enhancing its agentic Security Operations Center (SOC) capabilities by integrating enterprise-wide telemetry with specialized AI agents. These agents are powered by leading frontier and domain-specific models, designed to improve
detection engineering, proactive threat hunting, autonomous investigation, coordinated response, and policy governance. A significant development is the introduction of Cisco AI POD for Splunk, which brings Splunk AI to on-premises customers. This system combines Splunk's new AI runtime software and reference architecture with pre-validated Cisco infrastructure and NVIDIA accelerated computing, offering a turnkey solution for deploying AI directly into data centers. This addresses the challenge for organizations that cannot move sensitive data to the cloud due to security and sovereignty requirements. Additionally, new observability innovations, including Splunk Agent Observability with Tokenomics capabilities, provide real-time insights into AI agent performance and token expenditure, helping organizations manage costs and ensure secure, governed AI deployment. Splunk is also expanding its partnership with AWS for joint product development to further advance the agentic SOC against AI-driven attacks.
Why It's Important?
These advancements are crucial for U.S. businesses and government entities facing increasingly sophisticated AI-driven cyberattacks. The ability to deploy Splunk AI on-premises through Cisco AI POD for Splunk allows organizations with strict data sovereignty and security requirements, such as those in healthcare, finance, and government, to leverage advanced AI capabilities without compromising data control. This is vital for maintaining national security and protecting critical infrastructure. The new observability tools, particularly Tokenomics, address a significant concern for enterprises: the opaque and potentially high costs associated with AI adoption. By providing real-time visibility into AI spending and performance, these tools enable better financial predictability and demonstrate clear return on investment, fostering greater confidence in scaling AI deployments. The expanded partnership with AWS signifies a collaborative effort to build a more resilient digital world, ensuring that U.S. organizations can effectively counter rapidly evolving cyber threats and accelerate their digital transformation securely.
What's Next?
Cisco AI POD for Splunk is currently available, allowing customers to immediately deploy self-managed Splunk AI in their on-premises, private cloud, and air-gapped environments. Splunk AI Assistant is also available, with Agent Launchpad expected later this year, enabling ad-hoc agentic investigations and custom agent building. Customers will have the flexibility to self-host various generative AI models, including Cisco Deep Time Series Model, Google Gemma 4, and OpenAI GPT-OSS 20B, with NVIDIA Nemotron open models becoming available in the coming months. Splunk Agent Observability, including its Tokenomics capabilities, is now available in Splunk Observability Cloud and Cisco Cloud Control, providing immediate visibility into AI agent performance and costs. The multi-year agreement with AWS will lead to continued joint product development, focusing on advancing the agentic SOC to combat AI-driven attacks. Future developments will likely include further integrations and enhancements to ensure AI agents operate within narrow, governed scopes to mitigate risks.
Beyond the Headlines
The push for 'trusted AI at scale' highlights a broader industry shift towards addressing the ethical and practical challenges of AI deployment. The emphasis on self-managed AI and on-premises solutions reflects a growing concern among enterprises about data control, privacy, and regulatory compliance, especially in sensitive sectors. The concept of 'agentic SOC' signifies a move towards more autonomous and intelligent security systems, where AI agents can reason and act at machine speed, potentially outpacing human-led responses to cyber threats. However, this also raises deeper questions about the governance and control of autonomous AI agents, as highlighted by concerns about agents breaking containment or being recruited by malicious actors. Splunk's approach of heavily restricting agent capabilities and providing robust observability tools aims to build trust and ensure responsible AI deployment. This evolution in cybersecurity underscores the ongoing tension between leveraging AI's power for defense and managing its inherent risks, shaping the future of digital resilience and enterprise security strategies.













