Cisco last week announced its intention to acquire Splunk for about $28 billion, without revealing details on how it plans to assimilate the cybersecurity and observability vendor’s assets. While Cisco isn't talking, Gartner VP Analyst Gregg Siegfried expects Cisco to leverage Splunk’s observability advancements to improve its AppDynamics and Full-Stack Observability platform.

“Cisco struggled with AppDynamics over the years maximizing that acquisition and they've been in the process of building the new Full-Stack Observability platform that has more overlap with some of the Splunk product line,” Siegfried said. “But that's something where they may very well be able to take that set of Splunk and Cisco assets and build them into something that's better than what they had today.”

Cisco acquired AppDynamics in 2017 for $3.7 billion, while ThousandEyes came into the portfolio three years later in 2020 via a $1 billion acquisition. In 2021, the vendor integrated its AppDynamics acquisition into its application security portfolio to help developers and security teams detect vulnerabilities in production and automatically block attacks. In June, the vendor launched its Full-Stack Observability Platform, combining ThousandEyes, AppDynamics, and other existing visibility and security capabilities.

Splunk has been building out its Observability Cloud platform for a few years, mostly based on its recent acquisitions, while integrating it with its security information and event management (SIEM) tools, Siegfried noted.

How Cisco integrates Splunk’s observability capabilities

When questioned about potential product overlap, Cisco Chairman and CEO Chuck Robbins said the move with Splunk is about synergizing the observability progress.

“I don't think we have significant overlap. If you think about the data platform and the observability progress that they've made, and you couple that with our application visibility, you couple that with ThousandEyes visibility — the visibility out of the network, we'll have to make a decision on the platform, but I think that's clearly going to be the scale that Splunk has,” he said in a recent conference call with analysts.

Siegfried pointed out that Cisco hasn’t revealed its plans on how to integrate Splunk’s observability portfolio, but he forecasts the incorporation of Splunk could lead to a convergence, ultimately replacing AppDynamics.

“The traditional AppDynamics has got a kind of an obsolescence problem It's not evolved terribly well in the last few years, certainly has not been moved into the cloud era as well as maybe some of the competitors had,” he said.

Cisco recently rebranded AppDynamic Cloud to Cloud Native Application Observability as a module of its Full-Stack Observability Platform, which is a “totally different product than traditional AppDynamics,” Siegfried said.

Siegfried envisions the full-stack observability data lake could become the foundational platform moving forward. The platform would potentially integrate the front end of both Splunk’s SIEM and observability capabilities, ultimately becoming a replacement for AppDynamics.

“Using the best of Splunk and the best of Cisco there and building something that is much much better than either one of them has right now,” he said.

The shared cybersecurity-observability convergence vision

Cisco and Splunk have been making strides in converging their cybersecurity and observability capabilities. “That's an area where the messaging from both companies even before the acquisition has been very similar,” Siegfried pointed out.

Cisco recently launched the Cisco Secure Application (formerly known as Security Insights for Cloud Native Application Observability), a new module built on its Full-Stack Observability platform, which brings together capabilities from its Kenna acquisition and AppDynamics and relies on Panoptica for both API security and container and serverless runtime security.

Splunk is also integrating its observability capabilities with SIEM tools such as Splunk Enterprise.

Cisco has yet to disclose how Splunk’s team will be integrated post-acquisition, particularly regarding alignment with business units such as the security business group or the Full-Stack Observability platform team. This will affect the cybersecurity and observability convergence efforts.

“That's all gonna feed into where [Cisco] puts the [Splunk] team and depends on how far that vision goes,” he added. “That's going to be an intriguing thing to watch,”

What the deal means to Cisco and Splunk’s customers

In the short term, it likely won’t mean significant changes to customers, Siegfried said. He suggests customers of both Cisco and Splunk avoid making early conclusions about the fate of the products they are using right now.

“In the short term, I don't think it means anything. There's been no direct discussion so far about what products are necessarily going to be affected or replaced,” he said.

Siegfried noted that while there are redundancies, they are not extensive on the security side, and those on the monitoring and observability side are more complementary than overlapping to a degree.

“I would wait, I would not jump to conclusions and say: 'Oh, wait, this means that this product is going to go away or this product is going to stop being worked on',” he said.

Siegfried said it will take time for the two companies to clarify their roadmap post-merger, especially as the exchange of information may slow down until the deal gets approval. “But the stable products today are certainly still stable to be purchased and used.”