By Courtney Wright, Product Marketing Manager, Splunk Platform.
You do not need another reminder that AI is changing operations. The practical question is: where should it enter your Splunk workflow first? The challenge is choosing an option that solves a real problem without outrunning your data, controls or team.
We created the three-part Beyond the Thread: Deconstructing the Cisco Data Fabric powered by the Splunk Platform webinar series to demystify the Cisco Data Fabric architectural framework: what it changes, why it matters and why AI raises the stakes when data and context remain fragmented. Across the series, we take a practitioner’s view of the newly generally available Splunk Platform capabilities that bring the architecture to life—and how you can begin putting them to work.
In the second conversation, Greg Ainslie-Malik, Director of Global AI Architects, and Sonal Pardeshi, Senior Director of Product Management, join me to pressure-test your starting point through three questions:
Greg captures the practitioner’s dilemma: “Organizations aren’t saying, ‘We don’t know where to get started.’ They’re saying, ‘We don’t know what the best place to start is.’”
Your first move might be assisted—helping someone find, summarize or interpret information. It might be augmented—supporting a multistep decision. Or it might be an engineered agentic workflow with defined actions and boundaries.
You’ll hear how to distinguish among those paths based on the work, not the hype—and where a deterministic workflow may be more reliable. As Greg reminds us, “Not everything needs to be a language model.”
If the workflow begins with a Splunk alert, detection or investigation, should practitioners remain inside Splunk? If it begins in another system—or your developers are composing a broader workflow—should Splunk provide context and capabilities to an external agent?
Sonal offers a useful starting principle: “If your workflow starts with a Splunk signal—whether it’s an alert fired or a detection—then you would build inside.” From there, she and Greg compare native entry points such as AI Assistant and Agent Launchpad with external patterns enabled by Splunk MCP Server.
The point is to recognize how workflow origin, user experience, team skills and governance should shape your path.
Moving from recommendation to action raises the stakes. A technically impressive agent is not necessarily one you should trust with production changes.
“Autonomy is not a switch that you can flip,” Sonal explains. “It’s a permission that you extend when the evidence has justified it.” You’ll hear what that evidence can look like: scoped permissions, traceable reasoning, shadow mode, human review and measurable performance.
You do not have to automate everything on day one. You need a well-chosen entry point, a clear definition of success and a credible path to greater autonomy.
Watch Session 2 on demand to hear Greg and Sonal unpack each decision then decide what you are ready to try first.
If you want to begin with the data foundation, watch Session 1: Agentic Operations Start with Context. In October, Session 3 will reconnect the architecture as an end-to-end journey following the latest .conf26 announcements – registration will open soon, so stay tuned.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.