The 2025 Splunk .conf25, the first major showcase since Splunk’s acquisition by Cisco, well post acquisition! It was a full-throttle blueprint for the AI-powered enterprise, too much AI? We’ll leave that to you to decide 😉 During conf, Splunk(uh Cisco) laid out a future where data isn’t just managed, it’s ‘weaponised’ for resilience, scale, and speed.
Here’s what mattered and why it matters now. This is a series of blogs; firstly, we’ll fly over the conference and bring you some headlines. Further blogs will bring you more detail on those themes. Hit the contact form for a detail you would like to see.
AI: Not Hype, Real Use
AI wasn’t a side act, it was the show, centre stage. Splunk and Cisco focused on AI that’s deployed, working, and solving real problems, using demos in typically the Splunk UI product with AI assistance.
We like the coined term AI – resilience with and resilience for, both topics were covered, and we’ll dig into that in future blogs.
Highlights:
- Agentic Observability and Security: AI agents now assist in detecting, triaging, troubleshooting, and remediating incidents, automatically. This isn’t future-talk; it’s either in general availability or rolling out by end-of-year.
- AI Defense: Integrated directly into the stack, it watches AI models themselves for prompt injection, hallucinations, and other failure modes.
- Foundation-sec-8B: Cisco’s first open-weight cybersecurity LLM is a domain-specific model trained on real threat intelligence, and built for enterprise control and trust.
For deeper reading:
🔗 Cisco Foundation-sec-8B Blog
📹 AI in Observability – Splunk Conf25
Data: From Lakes to Fabrics
Splunk (darn it …..Cisco) is focussed on revamping the rules of data architecture. The “Data Fabric” approach changes how machine data is ingested, processed, and monetised.
Key Concepts:
- Federated Analytics: Search the data where it lives (Snowflake, Azure, S3) without moving or duplicating it. We need more of this.
- Cisco Data Fabric: Replaces monolithic data lakes with decentralised “ponds and puddles” that use edge intelligence to filter and route only the signal, not the noise.
- Machine Data Lake (MDL): A secure, AI-ready repository designed to train LLMs and run agentic applications on your proprietary telemetry.
This architecture isn’t theoretical. It’s built on technologies like eBPF, edge processors, and open data formats like Apache Iceberg. The result? Lower cost, more control, and real-time insights at “ludicrous scale.” Again we’ll cover off some of the above topics in more detail, in further blogs.
For deeper reading:
📹 Conf25 Day 2 Keynote
📹 Conf25 Day 1 Global Broadcast
Product Evolution: A New Splunk
If you’re used to “Splunk ES,” it’s time to recalibrate. Splunk is modernising both naming and functionality:
- Splunk Enterprise Security 8.2: Split into two editions, Essentials and Premier, with built-in SOAR and UEBA. We’ll have to cover this for our clients!!!
- AI Assistant in ES: Generates case summaries, accelerates triage, and integrates with Detection Studio and SOAR.
- Detection Studio: Manage the full lifecycle of detection logic, gap analysis, and coverage mapping, all in one interface.
On the Observability front, “agentic observability” now means root cause detection, incident report drafting, and even Kubernetes-level remediation—all AI-powered and integrated with AppDynamics.
For deeper reading:
📹 SOC Future – Conf25
📹 Day 2 Product Keynote
Cost & Value: It’s Not Just About Tech
Splunk and Cisco made it clear: They’re not just building cool tech—they’re targeting cost control and ROI.
Cost Efficiency Moves:
- Free Firewall Log Ingest: No more burning licence just to get basic telemetry.
- Edge Filtering: With Splunk’s Edge Processor, 74% of low-value data can be filtered out before ingest.
- Federation Over Ingestion: Why pay to ingest when you can query in place?
These aren’t just architectural niceties… they’re bottom-line decisions. Every move here is designed to reduce waste and boost insights per dollar.
So What’s Next?
This was just the beginning. Over the next few blogs, we’ll break down each major theme: AI, Data, Product, and Cost to explore what they mean for SecOps, ITOps, and your bottom line.
Splunk isn’t trying to be your log storage anymore. It wants to be your AI-driven operating layer. Trusted, federated, and embedded across your digital business.
Up Next: AI in the Real World – How Splunk + Cisco Are Building Agentic Infrastructure
Further Reading + Resources:
-
1 July 2026
Building a Foundation for Risk
-
22 June 2026
The Convergence Imperative
-
4 June 2026
From Reactive to Resilient: Managed Splunk Operations for a Leading UK Financial Business
See how we can build your digital capability,
call us on +44(0)845 226 3351 or send us an email…


