Partner POV | From Vision to Value: New Splunk Platform Innovations Supporting Cisco Data Fabric Are Generally Available
In this article
This article was written by Mangesh Pimpalkhare, SVP and GM, Splunk Platform.
Today, that vision has become reality.
Key Splunk Platform innovations including Machine Data Lake, Catalog, and Agent Launchpad, together with expanded Federated Search and Data Management capabilities, are now generally available. You can begin using these Splunk Platform innovations today to federate data, correlate at scale and unlock machine data for AI.
This milestone reflects a journey from intent to value—Cisco Data Fabric powered by the Splunk Platform is the system of record and intelligence for the agentic enterprise. It represents the architecture for connecting and activating distributed operational data, while the Splunk Platform is the data platform that brings the architecture to life through capabilities for managing, accessing, understanding, and acting on that data.
Together, these innovations move the architecture from vision to an operational foundation you can put to work today—turning distributed machine data into the trusted context that humans and AI need to act.
The AI Challenge Amplifies the Age-Old Data Challenge
Security, IT, engineering, observability, and network teams are already managing unprecedented volumes of operational data across cloud platforms, on-premises systems, applications, networks, SaaS services, and data lakes.
AI compounds this challenge in two directions. AI applications and agents generate additional telemetry, while also requiring timely access to more of an organization's existing data. They need to find and reason across information that spans different systems, formats, owners, retention policies, and governance requirements.
As organizations scale AI, these demands expose the limits of architectures built around moving all data to one place. They also expose operational processes that still depend on manual onboarding, normalization, and maintenance.
The result is a difficult cycle: more data creates more cost and complexity, while fragmented, inaccessible, or poorly understood data limits the value organizations can realize from AI.
The answer is not simply to collect more. Organizations need the flexibility to place data according to its value, find and search it across environments, maintain its quality, and activate it with the appropriate context and controls.
Today, Cisco Data Fabric powered by the Splunk Platform helps them to do that —at machine speed, at scale—delivering a unified data journey into a cohesive source of truth.
From Security Signals to Autonomous Response
Consider a security team investigating suspicious activity involving a privileged account. The initial signal is visible in Splunk, but the full story may span identity events, endpoint telemetry, network activity, cloud logs, and historical data retained elsewhere.
To connect activity across these sources, the team first needs the data onboarded, normalized, and kept Common Information Model (CIM) compliant. Our latest Data Management enhancements help compress work that can take weeks into minutes. Guided Onboarding acts as an in-product expert, leading administrators through best-practice setup, while Auto Schematization recommends CIM mappings and generates the configuration artifacts needed to correlate events sooner.
As data sources evolve, Self-Healing Pipelines detect CIM compliance drift and surface AI-generated remediation recommendations for administrators to review, helping keep the data accurate and useful throughout the investigation.
The team also needs access to historical and distributed evidence. The new Machine Data Lake provides a Splunk-managed environment for landing and retaining full-fidelity machine data at scale, making the data available for promotion across higher-performance tiers when premium costs warrant. Catalog helps the investigator identify relevant datasets and understand their metadata. Expanded Federated Search capabilities extend the investigation across supported external data environments without requiring every dataset to be moved or duplicated.
With the evidence assembled, Agent Launchpad then helps the analyst move from investigation to action. Analysts can build an agent, choose the LLM, connect to tools, select agent skills, without coding or data science expertise. If a suspicious activity was detected in the privileged account login pattern, the alert can launch the agent - with relevant context already attached - to investigate related activities, summarize evidence, and recommend or take approved next steps. Administrators retain control through role-based access control, governing who can access agents, data, and approved tools. Every agent run remains traceable, so the team can review the evidence, inspect tool usage, and ask follow-up questions before responding.
To further accelerate agentic operations in the enterprise, we just launched Splunk agent skills, available in Github to the open source community. Splunk agent skills give agents reusable, task-specific instructions that help them perform common security and operations workflows more consistently and accurately. This initial release introduces the first three Splunk-built skills as a curated starting point, making it easier for customers to add proven expertise to their agents.
Instead of spending valuable time locating data and moving between disconnected systems, practitioners can focus their expertise on understanding risk and determining the appropriate response.