Cisco has unveiled a slew of AI-centric releases leveraging its $28 billion Splunk mega-deal.
As announced at Splunk’s annual Conf. event, the pair unveiled AI-driven updates to Splunk Enterprise Security (ES), with updates to the threat detection, investigation, and response (TDIR) platform focused around agentic AI.
Among the new offerings is Splunk Enterprise Security Premier, marketed as a bundling of ES’s latest 8.2 iteration with offerings in user and entity behavior analytics (UEBA), detection capabilities, security orchestration, automation, and response (SOAR) alongside the Splunk AI Assistant.
Also released is Splunk Enterprise Security Essentials, an entry-level version of the mainline platform with AI Assistant and Splunk Detection Studio only.
With its new version of ES, Cisco is offering AI-centric security operations (SecOps) to network teams. Integrated AI agents are promised to triage and prioritize alerts to reduce analyst workload, while also reverse-engineering malware, extracting indicators of compromise, and identifying malicious behaviors.
Other functions include automating the creation of SOAR playbooks from natural language, importing standard operating procedures into response plans using multi-modal large language models (LLMs), and continuously enhancing a detection library to accelerate the move from hypothesis to production.
The platform also features a personalized generator to adapt detections for unique security operations center (SOC) environments, which integrates with Webex to automate the creation of war rooms for security response efforts.
Other key enhancements include integrating Isovalent Runtime Security (eBPF) into Splunk to provide immediate, granular visibility into workloads for pinpointing security breaches and anomalies, and federating Cisco Firewall Data, which enables Splunk Cloud users to perform security analytics on firewall logs stored in the Security Analytics and Logging (SAL) function directly, without requiring data ingestion, potentially accelerating response times.
Outside of ES, Splunk Observability Cloud and Splunk AppDynamics will see troubleshooting agents designed to analyze incidents and surface root causes for prompt resolution.
An agent in Splunk IT Service Intelligence (ITSI), meanwhile, is claimed to enable automated alert correlation and context, while ITSI Episode Summarization generates overviews for users of grouped alerts with trends, impact, and root causes.
Splunk also introduced an AI Agent Monitoring service that evaluates model quality and cost against business goals, alongside an infrastructure monitoring tool for detecting bottlenecks and spikes across network services.
Cisco advances agentic AI authority
As recently explored by SDxCentral, various vendors are releasing AI agents to automate various actions across network security.
Cisco already offers one AI assistant which has been integrated into various of its subsidiaries, including ThousandEyes, Meraki, and Webex.
The Splunk AI Assistant for Security (AIA), first released last year, seems to stand on its own terms, judging by its branding.
In addition, Cisco Secure AI Factory with Nvidia was integrated this month with AI operating system (OS) vendor Vast Data, specifically with Cisco’s AI points of delivery (PODs). With the infrastructure offering, Cisco customers can potentially accelerate data extraction and retrieval for agentic AI models, with agents having data at their disposal at moment of need.
Cisco has an established pedigree with the tech, having established the Agntcy project to be a de facto listing of AI agents. The framework was donated to the Linux Foundation this year, with Cisco staying on as a formative member for its development.
Elsewhere at Splunk Conf.25
The new Splunk ES solutions come alongside this week’s release of Cisco Data Fabric. Where Cisco’s Secure AI Factory with Nvidia hones in on building, training, and deploying AI models, the new Data Fabric platform focuses on collecting and preparing machine data for AI at scale.
The tool integrates with Splunk’s model training offering, Machine Data Lake, its AI Toolkit, and a model context protocol (MCP) server based on an open standard to standardize the way AI systems integrate and communicate with external data sources, tools, and systems.
Such integration potentially lowers both cost and complexity for enterprises as the AI tide drives a data deluge. Recent IDC research, for example, predicts that 80% of the top 500 industrial enterprises will have an operations data fabric capability to handle AI-driven use cases by 2026.
Cisco Data Fabric also provides a federated search capability, powered by Splunk, that queries multiple distributed machine data sources in real-time across the likes of Amazon S3, Apache Iceberg, and Microsoft Azure.
Cisco also announced a Splunk Federated Search tool specifically for Snowflake, designed to connect, query, and combine business and operational data across Splunk and Snowflake environments.
With these latest Splunk updates, Cisco has signalled its software ambitions, leveraging its $28 billion acquisition of the data platform last spring. CEO Chuck Robbins claimed the acquisition would bolster Cisco's ability to help organizations harness the power of AI while strengthening security and observability capabilities.
Comments