Cisco on September 15, 2026, introduced Cisco AI POD for Splunk, bringing self-managed Splunk AI to customers operating on-premises, in private clouds and in air-gapped environments. The configuration is available now, while Splunk Agent Launchpad is scheduled to arrive later in 2026.
The offering is the newest configuration within Cisco Secure AI Factory with NVIDIA, a reference architecture built from Cisco AI PODs. Cisco said the Splunk configuration combines new AI runtime software, Cisco infrastructure, NVIDIA accelerated computing and a Kubernetes-based architecture that has been pre-validated and optimized for Splunk AI workloads. Accenture, bitsIO, Wipro and World Wide Technology are prepared to help customers deploy it on their own infrastructure.
Splunk AI Assistant is available on the platform, and Agent Launchpad is intended to support custom agent development and ad hoc agentic investigations, including for security operations centers. Customers can self-host selected open and proprietary generative AI models for Splunk Enterprise workloads, including the Cisco Deep Time Series Model, Google Gemma 4 and OpenAI GPT-OSS 20B. NVIDIA Nemotron open models are expected in the coming months. Cisco said this approach allows customers to select models without sending data outside their environment.
Cisco also announced Tokenomics capabilities for Splunk Agent Observability, designed to track and attribute token expenditure across AI agents and employees’ use of coding agents such as Claude Code, Codex and Cursor. The company said the solution provides a real-time view of agent performance and token spending and will use the Cisco Deep Time Series Model to forecast consumption before a billing period ends. Splunk Agent Observability is now available through Splunk Observability Cloud and Cisco Cloud Control, where Cisco says it can evaluate agent and model behavior, monitor the AI stack and apply runtime guardrails against inaccurate or unsafe actions.
Other observability additions include Observability Studio, intended to make new applications measurable and production-ready from the outset, and the Network Intelligence App, which brings Cisco network topology, device health and events into Splunk. Cisco also introduced Essentials and Premier editions for Observability Cloud, with log analytics for diagnosing application and infrastructure problems.
For security operations, Cisco described new specialized agents spanning detection engineering, threat hunting, investigation, response and policy governance, as well as Exposure Analytics enhancements covering more assets, historical changes and business-specific risk information. Splunk Enterprise Security Essentials adds agentic security functions, while the Premier edition provides deeper autonomy. Separately, Splunk and AWS formalized a multi-year agreement to jointly develop security products for detection, investigation and response, combining Splunk’s data platform and detection capabilities with AWS cloud infrastructure while retaining analyst oversight and governance.

