Cisco has announced a set of product updates and partnerships aimed at bringing Splunk AI capabilities to more deployment environments, including on-premises systems, and adding tools to track AI agent performance and spending.
The updates include Cisco AI POD for Splunk, described as a new addition to Cisco Secure AI Factory with NVIDIA, intended to make Splunk AI features available to self-managed and on-premises Splunk customers. The company said the offering supports deployment across on-premises, private cloud and air-gapped environments.
In parallel, Cisco and Splunk said they are expanding work with AWS under a multi-year agreement to co-develop security solutions designed to keep pace with AI-driven attacks.
According to Jeetu Patel, President and Chief Product Officer at Cisco, “One of the biggest roadblocks to enterprise AI today is that it’s too hard to deploy. Customers want to know: Can I trust it to do the job? Can I afford it? And, most importantly, can I secure it? By running Splunk AI on the infrastructure customers already trust, they can move faster to put AI to work in their business with confidence and control.”
Another focus of the announcement was observability and cost management for AI agents. Cisco said Splunk Agent Observability, including new “Tokenomics” capabilities, provides real-time visibility into AI spending and agent usage, including coding assistants, with forecasting intended to help organisations anticipate consumption trends before billing periods end.
On security operations, Splunk outlined updates aimed at supporting what it calls an “agentic” security operations centre, with enhancements to exposure analytics designed to broaden asset coverage, add historical change tracking and provide business-specific risk insights across Splunk, Cisco and third-party tools.
The announcement was made in conjunction with Splunk .conf in Sydney on September 16, 2026.

