5 Key Takeaways From Splunk .Conf26

Splunk this week debuted a slew of new products and capabilities, many around AI agentic security and observability, with the goal of positioning itself as the data platform for building trustworthy AI systems. Here’s a look at some of the major announcements and the key insights that came out of the event.


“Powering the rise of the agentic enterprise” has been the theme of this week’s Splunk .conf26 in Denver where Splunk executives positioned the company’s platform as a critical component of an organization’s AI strategy while at the same time introducing new AI-enabled security and observability capabilities for Splunk software.

“We have reimagined Splunk so you can trust AI,” said Kamal Hathi, senior vice president and Splunk general manager, during a product keynote session Tuesday. “This is Splunk moving at an incredible pace of innovation.”

Splunk also continues to more tightly integrate its products with those from Cisco Systems, which acquired Splunk in March 2024 in a blockbuster $28 billion deal.

The Splunk platform, for example, is the data management foundation for the Cisco Data Fabric architecture, which debuted last year at the Splunk .conf25 event. Splunk is also the data and intelligence engine powering Cisco Cloud Control, the company’s unified, cross-domain operations platform.

While AI observability and security are key applications for Splunk’s technology, Jeetu Patel, Cisco president and chief product officer, made it clear in a presentation during the Splunk .conf26 opening keynote session that Splunk is more than that.

“This is not just about keeping everything up and running,” Patel said. “What we also want to do is make sure that we build on the core fabric of trust that’s going to be required in this agentic era.” Those requirements, he said, are optimizing AI at scale, defending at machine speed, and turning machine data into agentic action.

“Delivering digital resilience starts with Splunk,” said Patel, calling the Splunk purchase “one of the most strategic acquisitions we’ve ever made.”

Splunk’s moves this week are creating significant opportunities for the company’s channel partners, including AI-related strategy consulting and implementation services, around networking, security, data analytics and tokenomics, said Mangesh Pimpalkhare, Splunk senior vice president and general manager, Splunk platform, in a pre-Splunk .conf26 interview.

“There’s a great opportunity for partners anytime there’s a big transformation going on in the industry. When there’s this kind of a change, enterprises are looking for answers,” Pimpalkhare said, calling partners “the critical bridge” between the technology offered by IT vendors like Splunk and customer needs.

Pimpalkhare touted the use cases around Cisco Cloud Control, which leverages the Splunk platform’s telemetry collection capabilities, as “a great conversation starter for partners.”

Here’s a look at the key announcements and takeaways at this week’s Splunk .conf26 event.

Splunk Agent Observability

“You have to understand what AI is actually doing, not what you intended it to do,” Hathi said, emphasizing during the Splunk .conf26 product keynote the importance of having visibility into AI infrastructure operations and AI agent behavior.

Splunk Agent Observability, initially unveiled last month as an on-premises product, is now available in Splunk Observability Cloud and in Cisco Cloud Control, extending visibility across the Cisco portfolio.

The product evaluates agent and model behavior, observes performance across the AI stack, and applies runtime guardrails that block inaccurate or unsafe actions such as generating hallucinations or leaking sensitive data, according to Splunk.

Splunk Agent Observability’s capabilities include full-stack visibility and tracing, live evaluation and real-time guardrails.

The observability software, which operates within the broader Cisco Data Fabric unified architecture, incorporates AI evaluation technology from Cisco’s Galileo acquisition in May.

Splunk has also added a new Tokenomics capability to Splunk Agent Observability that extends the platform’s visibility to AI spending, tracking and attributing token expenditure across AI agents and employee use of coding agents such as Claude Code, Codex and Cursor. The Tokenomics tool, now generally available, also leverages the Cisco Deep Time Series Model to forecast consumption patterns and forecast spending, helping organizations better tie AI spending to business outcomes.

Also new is Observability Studio, a tool that enables development teams to ensure that new applications are designed from the start to be observable, measurable and production ready. And the new Network Intelligence App brings Cisco network topology, device health data and event alerts into Splunk.

Splunk Observability Cloud now offers AI SRE, an agentic AI feature that takes on site reliability engineering tasks, process telemetry signals and accelerate incident investigation and root cause analysis.

At Splunk .conf26, the company also announced that it now offers Essentials and Premier editions of Observability Cloud. The new Essentials package is tailored for DevOps and IT teams that are in the early stages of monitoring, managing and securing generative AI applications and AI agents.

“It gives everybody a simple way to get started with the ability to observe every aspect of AI,” Hathi said. “It really democratizes what is required in this age of agentic AI.”

Cisco AI POD for Splunk

One of the key applications for Splunk in the AI space is collecting machine data and making it available for model training and for AI agents to work with as they perform their tasks.

Through an expanded relationship with Nvidia, Cisco and Splunk are bringing Splunk AI capabilities to on-premises data centers with the Cisco AI POD for Splunk, a configuration addition to the Cisco Secure AI Factory with Nvidia AI reference infrastructure.

The extended Cisco-Nvidia relationship brings self-managed AI directly to Splunk Enterprise customers across their own on-premises, private cloud and air-gapped environments, according to Splunk.

Cisco AI POD for Splunk provides new AI runtime software, Cisco infrastructure, Nvidia accelerated computing and Kubernetes-based infrastructure that is pre-validated and optimized for Splunk AI workloads.

Splunk said that Cisco AI POD for Splunk is now available and that infrastructure partners such as bitsIO, Wipro and World Wide Technology are ready to help implement the product.

Splunk customers can also self-host a number of open and proprietary generative AI models for Splunk Enterprise workloads including Cisco Deep Time Series, Google Gemma 4 and OpenAI GPT-OSS-20B. Nvidia Nemotron open models will be supported in coming months.

Splunk AI Assistant and Agent launchpad (the latter coming later this year) run on Cisco AI POD for Splunk.

Splunk Agentic SOC

“Defending at machine speed” was one of the central themes at Splunk .conf26.

“In this world, we have to reimagine where AI is the threat and AI is the response,” Hathi said during the product keynote, citing recent cybersecurity incidents where AI agents hacked into other companies and organizations.

At the RSAC 2026 conference in March and Cisco Live in June, Splunk rolled out Splunk Agentic SOC (security operations center), combining enterprise telemetry with specialized cybersecurity agents. At the time the company debuted six specialized AI agents, built into Splunk Enterprise Security, to handle such tasks as building detections, triaging alerts, analyzing malware and automating responses.

At Splunk .conf26 this week the company expanded Splunk Agentic SOC by adding purpose-built agent capabilities to Splunk Agentic SOC Workforce that carry out the same tasks as elite security teams across detection engineering, proactive threat hunting, autonomous investigation, coordinated response and policy governance.

Splunk Agentic SOC also now offers expanded exposure analytics, providing complete exposure visibility with broader asset coverage, historical change tracking, and business-specific risk insights.

“There is no future at this point, in this day and age, where the SOC is not agentic,” said John Morgan, Splunk senior vice president and general manager, security, during the product keynote.

New Capabilities For The Splunk Platform

“The Splunk platform that you already have is going to evolve,” said Mangesh Pimpalkhare, Splunk senior vice president and general manager, Splunk platform, during the product keynote.

Pimpalkhare provided a look at some of the capabilities Splunk has developed for its core platform including:

Splunk And AWS Expand Alliance

Splunk and Amazon Web Services announced an expansion of their strategic partnership to continue what the two called “building a significant foundation of customer adoption, commercial scale and technical collaboration” around agentic AI.

The latest chapter of the alliance emphasizes improving cooperation between the two companies around security for cloud-native environments, including tighter integration of AWS infrastructure and AWS Security Suite with the Splunk Agentic SOC.

“By integrating AWS infrastructure with Splunk’s Agentic SOC, we are moving beyond simple integration to create a brand-new defensive paradigm,” said Rudra Mitra, AWS vice president of security services, who made an appearance during the Splunk .conf26 opening keynote session.

“This powerhouse alliance offers customers the unified, intelligent architecture required to address evolving security challenges effectively.”

The two companies said that through the alliance they look to help customers maintain deep analyst oversight and context, adjust autonomy levels from recommendation to execution, and enforce policy-driven, risk-based governance around AI.