Webinars

Recap | Assisted, Augmented or Agentic? Choose Your Splunk Starting Point

LesediK
Splunk Employee
Splunk Employee

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point

 

By Courtney Wright, Product Marketing Manager, Splunk Platform.

 

You do not need another reminder that AI is changing operations. The practical question is: where should it enter your Splunk workflow first? The challenge is choosing an option that solves a real problem without outrunning your data, controls or team.

 

We created the three-part Beyond the Thread: Deconstructing the Cisco Data Fabric powered by the Splunk Platform webinar series to demystify the Cisco Data Fabric architectural framework: what it changes, why it matters and why AI raises the stakes when data and context remain fragmented. Across the series, we take a practitioner’s view of the newly generally available Splunk Platform capabilities that bring the architecture to life—and how you can begin putting them to work.

In the second conversation, Greg Ainslie-Malik, Director of Global AI Architects, and Sonal Pardeshi, Senior Director of Product Management, join me to pressure-test your starting point through three questions:

  • What should AI do first in your environment?
  • Where should the agentic experience live?
  • What evidence would earn an agent its next permission?

 

1. What should AI do first in your environment?

 

Greg captures the practitioner’s dilemma: “Organizations aren’t saying, ‘We don’t know where to get started.’ They’re saying, ‘We don’t know what the best place to start is.’”

Your first move might be assisted—helping someone find, summarize or interpret information. It might be augmented—supporting a multistep decision. Or it might be an engineered agentic workflow with defined actions and boundaries.

You’ll hear how to distinguish among those paths based on the work, not the hype—and where a deterministic workflow may be more reliable. As Greg reminds us, “Not everything needs to be a language model.”

2. Where should the agentic experience live?

 

If the workflow begins with a Splunk alert, detection or investigation, should practitioners remain inside Splunk? If it begins in another system—or your developers are composing a broader workflow—should Splunk provide context and capabilities to an external agent?

Sonal offers a useful starting principle: “If your workflow starts with a Splunk signal—whether it’s an alert fired or a detection—then you would build inside.” From there, she and Greg compare native entry points such as AI Assistant and Agent Launchpad with external patterns enabled by Splunk MCP Server.

The point is to recognize how workflow origin, user experience, team skills and governance should shape your path.

 

3. What evidence would earn an agent its next permission?

 

Moving from recommendation to action raises the stakes. A technically impressive agent is not necessarily one you should trust with production changes.

“Autonomy is not a switch that you can flip,” Sonal explains. “It’s a permission that you extend when the evidence has justified it.” You’ll hear what that evidence can look like: scoped permissions, traceable reasoning, shadow mode, human review and measurable performance.

You do not have to automate everything on day one. You need a well-chosen entry point, a clear definition of success and a credible path to greater autonomy.

 

Watch Session 2 on demand to hear Greg and Sonal unpack each decision then decide what you are ready to try first.

 

 If you want to begin with the data foundation, watch Session 1: Agentic Operations Start with Context. In October, Session 3 will reconnect the architecture as an end-to-end journey following the latest .conf26 announcements – registration will open soon, so stay tuned.

Contributors
Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...