Cisco is bringing Splunk AI to on-premises, private cloud, and air-gapped environments through a new architecture developed with NVIDIA, expanding how Splunk Enterprise customers can deploy AI in environments where security, sovereignty, and data-location requirements limit public cloud use.
Announced at Splunk .conf in Denver, the Cisco AI POD for Splunk is part of a broader set of updates that also includes new AI observability and token-tracking capabilities, along with an expanded AWS partnership focused on agentic security operations.
Cisco and NVIDIA bring Splunk AI on-premises
Cisco and NVIDIA are bringing self-managed Splunk AI to Splunk Enterprise customers across on-premises, private cloud, and air-gapped environments through the new Cisco AI POD for Splunk.
The new offering is a configuration within the Cisco Secure AI Factory with NVIDIA, a reference architecture built around Cisco AI PODs. It combines Cisco infrastructure, NVIDIA accelerated computing, new AI runtime software, and a Kubernetes-based architecture that Cisco said has been pre-validated and optimized for Splunk AI workloads.
“Enterprises need to bring AI where their data lives, especially when security and sovereignty requirements require critical workloads to stay on-premises,” said Justin Boitano, vice president of enterprise AI at NVIDIA.
Splunk AI Assistant is available on the platform, while Agent Launchpad is expected later this year. Together, the tools support ad-hoc agentic investigations and custom agent development for use cases including agentic security operations.
Customers can also self-host a selection of open and proprietary generative AI models for Splunk Enterprise workloads. Cisco listed its Deep Time Series Model, Google Gemma 4, and OpenAI GPT-OSS 20B among the supported models, with NVIDIA Nemotron open models expected in the coming months.
Partners see services opportunity around private Splunk AI
Cisco said Accenture, bitsIO, Wipro, and World Wide Technology are among the partners available to help customers deploy the architecture on their own infrastructure.
That partner involvement provides Cisco and Splunk with a services layer for the new architecture, particularly for customers who need help designing, deploying, and operating AI infrastructure in private environments.
For solution providers, the opportunity extends beyond the initial hardware and platform implementation into integration, model hosting, security controls, and ongoing management of Splunk AI workloads.
The architecture could be especially relevant for customers in regulated or security-sensitive environments where keeping data and AI workloads on-premises is a requirement rather than a preference.
Splunk adds AI agent and token observability
Cisco is also expanding Splunk Agent Observability, which is now available through Splunk Observability Cloud and Cisco Cloud Control.
The platform evaluates agent and model behavior and monitors performance across the AI stack. According to Cisco, it can also apply runtime guardrails intended to prevent inaccurate or unsafe actions, including hallucinations and exposure of sensitive data.
A new Tokenomics solution adds real-time tracking and attribution of AI token expenditure across agents and employees using coding agents such as Claude Code, Codex, and Cursor.
Cisco said the capability will use its Deep Time Series Model to forecast consumption patterns and project spending before the end of a billing period. The company is positioning the data as a way for organizations to connect AI adoption and spending with business outcomes.
Splunk and AWS deepen agentic security partnership
Splunk and AWS have also entered a multi-year agreement to jointly develop security solutions focused on agentic security operations, expanding their long-standing relationship into joint product development.
The collaboration will bring together Splunk’s data platform and security detection capabilities with AWS cloud scale, with the companies focusing on agentic support across detection, investigation, and response.
According to Cisco, the collaboration is intended to advance agentic SOC capabilities while maintaining analyst oversight and governance.
Meanwhile, Splunk said the jointly developed approach will emphasize adjustable autonomy, allowing security teams to calibrate AI-driven automation from recommendations through execution. The companies are also focusing on analyst oversight and policy-driven, risk-based governance as part of the collaboration.
“The collaboration between AWS and Splunk is about helping customers strengthen security for their cloud-native environments at the speed of business,” said Rudra Mitra, VP of security services at AWS.
“By integrating AWS infrastructure with Splunk’s Agentic SOC, we are moving beyond simple integration to create a brand-new defensive paradigm. This powerhouse alliance offers customers the unified, intelligent architecture required to address evolving security challenges effectively.”
For channel partners supporting customers across Splunk and AWS environments, the deeper integration could eventually create additional opportunities around deploying, integrating, and managing agentic security capabilities.
Salesforce customers worldwide experienced a major outage during Dreamforce 2026 that disrupted logins, APIs, and workflows. Read more about the outage and its impact on Salesforce partners and customers.





