Webinars

Recap | Agentic Operations Start with Context: Build the Right Data Foundation

LesediK
Splunk Employee
Splunk Employee

Agentic Operations Start with Context: Build the Right Data Foundation

 

By Courtney Wright, Product Marketing Manager, Splunk Platform.

 

Every Splunk practitioner knows the moment: an investigation crosses domains, and the answer depends on someone remembering which team, runbook or overlooked data source to check.

If an AI agent joined your team tomorrow, would it know what your best engineer knows—or inherit your data foundation’s blind spots?

We created the three-part Beyond the Thread: Deconstructing the Cisco Data Fabric powered by the Splunk Platform webinar series to demystify the Cisco Data Fabric architectural framework: what it changes, why it matters and why AI raises the stakes when data and context remain fragmented. Across the series, we take a practitioner’s view of the newly generally available Splunk Platform capabilities that bring the architecture to life—and how you can begin putting them to work.

In the first conversation, Keith McClellan, Americas Platform Field CTO, and Michael Sondag, GVP of Global Platform Specialists, join me to pressure-test your readiness through three questions:

  • What context would your agent miss?
  • Can you reach distributed data without centralizing it first?
  • What data that looks routine today could become critical tomorrow?

 

1. What context would your agent miss?

 

Your team rarely investigates from one signal. You connect alerts to changes, owners, dependencies and prior incidents—often using knowledge held in people’s heads or surfaced in a war room.

Agents do not arrive with that intuition. As Keith puts it, “AI agents are great at doing tasks. They’re particularly bad at providing agency and oversight.” That distinction should feel familiar if you have ever watched automation move quickly in the wrong direction.

What changes when context becomes part of the operating foundation instead of something humans reconstruct under pressure? If an agent saw your signal, what relationships would it need to reason responsibly?

 

2. Can you reach distributed data without centralizing it first?

 

You may need evidence from security, observability, networking and business systems, but moving every byte into one place is rarely practical—or necessary.

Michael describes the desired practitioner experience simply: “Our goal is that, on a day-to-day basis, teams don’t care if the data is federated. They just know they have the data available.”

You’ll hear how Federated Search helps teams investigate across supported data stores without copying everything into Splunk, and why access, governance and context must travel together. The readiness test is whether the right evidence can be found and trusted when a human—or agent—needs it.

 

3. What data could matter tomorrow?

 

Deciding what to ingest, retain or discard has always involved tradeoffs. AI changes the calculation because data that looks low-value in isolation may become useful when an agent connects it to a new question.

Keith offers a provocative reframing: “The noisiness of data becomes a feature, not a bug.” The discussion connects that idea to Machine Data Lake and Catalog, now generally available in supported Splunk Cloud Platform regions: retain full-fidelity data economically, discover it and activate it when its value becomes clear.

You won’t leave with a one-size-fits-all architecture. You will leave better prepared to identify your own agentic entry point—and start building toward it today.

 

Watch Session 1 on demand and challenge some familiar assumptions about what “AI-ready” really means.

 

 

Then continue with Session 2: Assisted, Augmented or Agentic? Choose Your Splunk Starting Point.

In October, Session 3 will reconstruct the architecture as an end-to-end journey following the latest .conf26 announcements – registration will open soon, so stay tuned.

 

 

 

Contributors
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Analytics Workspace removal in Splunk 10.6

In Splunk Cloud Platform and Splunk Enterprise 10.6, Analytics Workspace is removed from product and no longer ...

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...