By Courtney Wright, Product Marketing Manager, Splunk Platform.
Every Splunk practitioner knows the moment: an investigation crosses domains, and the answer depends on someone remembering which team, runbook or overlooked data source to check.
If an AI agent joined your team tomorrow, would it know what your best engineer knows—or inherit your data foundation’s blind spots?
We created the three-part Beyond the Thread: Deconstructing the Cisco Data Fabric powered by the Splunk Platform webinar series to demystify the Cisco Data Fabric architectural framework: what it changes, why it matters and why AI raises the stakes when data and context remain fragmented. Across the series, we take a practitioner’s view of the newly generally available Splunk Platform capabilities that bring the architecture to life—and how you can begin putting them to work.
In the first conversation, Keith McClellan, Americas Platform Field CTO, and Michael Sondag, GVP of Global Platform Specialists, join me to pressure-test your readiness through three questions:
Your team rarely investigates from one signal. You connect alerts to changes, owners, dependencies and prior incidents—often using knowledge held in people’s heads or surfaced in a war room.
Agents do not arrive with that intuition. As Keith puts it, “AI agents are great at doing tasks. They’re particularly bad at providing agency and oversight.” That distinction should feel familiar if you have ever watched automation move quickly in the wrong direction.
What changes when context becomes part of the operating foundation instead of something humans reconstruct under pressure? If an agent saw your signal, what relationships would it need to reason responsibly?
You may need evidence from security, observability, networking and business systems, but moving every byte into one place is rarely practical—or necessary.
Michael describes the desired practitioner experience simply: “Our goal is that, on a day-to-day basis, teams don’t care if the data is federated. They just know they have the data available.”
You’ll hear how Federated Search helps teams investigate across supported data stores without copying everything into Splunk, and why access, governance and context must travel together. The readiness test is whether the right evidence can be found and trusted when a human—or agent—needs it.
Deciding what to ingest, retain or discard has always involved tradeoffs. AI changes the calculation because data that looks low-value in isolation may become useful when an agent connects it to a new question.
Keith offers a provocative reframing: “The noisiness of data becomes a feature, not a bug.” The discussion connects that idea to Machine Data Lake and Catalog, now generally available in supported Splunk Cloud Platform regions: retain full-fidelity data economically, discover it and activate it when its value becomes clear.
You won’t leave with a one-size-fits-all architecture. You will leave better prepared to identify your own agentic entry point—and start building toward it today.
Watch Session 1 on demand and challenge some familiar assumptions about what “AI-ready” really means.
Then continue with Session 2: Assisted, Augmented or Agentic? Choose Your Splunk Starting Point.
In October, Session 3 will reconstruct the architecture as an end-to-end journey following the latest .conf26 announcements – registration will open soon, so stay tuned.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.