Splunk partners with AWS and Nvidia: going deeper and higher in the stack

Splunk partners with AWS and Nvidia: going deeper and higher in the stack

Splunk has taken a close look at how its current parent company, Cisco, operates within its own stack. Today, it is announcing (updates to) partnerships with Nvidia and AWS that make it clear that Splunk, in a way, wants to go full-stack too. With Nvidia, the focus is on a specific Cisco on-premises AI POD. Meanwhile, with AWS, the partnership marks what Kamal Hathi, SVP and GM of Splunk, calls “the beginning of a very important relationship.”

Naturally, a great deal has been done in recent years to integrate Splunk into Cisco’s stack. As far as we’re concerned, it all really came together last year when Splunk announced the Cisco Data Fabric. Although this data fabric bears Cisco’s name, it is largely built on Splunk technology.

Cisco Cloud Control, which Cisco announced earlier this year, can be viewed as the UI that Cisco has built on top of the Data Fabric. In this way, Splunk is an important part of what we’ve called “one of the biggest innovations in 40 years of Cisco,” namely, Cisco Cloud Control.

Cisco AI POD for Splunk brings Splunk AI to Nvidia compute

The integration of Splunk into the full stack continues even after the announcement of the Cisco Data Fabric. Today, Splunk is getting its own AI POD: the Cisco AI POD for Splunk. The AI POD concept has been in place at Cisco for just under two years. The idea behind the AI POD concept is that it enables Cisco to deliver full-stack AI infrastructure for specific use cases and industries. Cisco builds the AI POD according to its own Cisco Validated Design. Of course, this is done in accordance with Nvidia’s reference architectures.

This brings us to the importance of the ongoing collaboration between Cisco/Splunk and the world’s most valuable company. After all, AI PODs are part of the so-called Cisco Secure AI Factory with Nvidia. Until now, however, there was no place for Splunk in this lineup. That changes today. With the announcement of the AI POD for Splunk, Cisco is bringing the capabilities offered by Splunk very close to Nvidia’s compute resources.

Why is this important or interesting?

One of the main reasons Cisco introduced the AI POD was to be able to offer and sell a great deal of AI computing power to customers, even on-premises. Many customers subject to laws and regulations regarding sovereignty, security, and compliance are not allowed to send their data anywhere at all. To still get the most out of that data, sufficient computing power must therefore be made available on-premises. The idea is that an AI POD is one of the options for doing so.

What’s new about the Cisco AI POD for Splunk is that it runs on new AI runtime software used by Splunk AI. Splunk AI is designed to ensure that the agent-based workloads running on the AI POD do so securely. Furthermore, it ensures that these workloads continue to run smoothly.

What does Splunk AI add?

The Splunk AI Assistant, which is already available, enables ad-hoc investigations. More interesting, however, is what’s coming later this year: Agent Launchpad. This is an environment where organizations can build their own custom AI agents and then deploy them on the AI POD. Splunk promises that this won’t require any actual programming. In other words, it’s a no-code environment.

Of course, an assistant alone, or even the yet-to-be-released Agent Launchpad, isn’t enough. Models must also be made available for the assistant and agents to use. Cisco and Splunk have chosen to provide access to multiple models.

Model selection is important because not every model handles all types of data equally well. This often depends on where the data is generated. Machines frequently generate time-series data, which standard LLMs struggle to process. That’s why customers have the option to use Cisco’s Time Series Model. Additionally, users can choose between Google Gemma 4 and OpenAI GPT-OSS 20B. Part of today’s Nvidia-related news from Splunk is that the open Nvidia Nemotron models will also be available for selection soon.

Greater control, security, and sovereignty

With the Cisco AI POD for Splunk, organizations should be able to run more than just on-premises AI workloads. Thanks to the integration of Splunk (AI) into the AI POD, organizations also retain control over the workloads themselves. At least, that’s the promise from Splunk. Thanks to the capabilities Splunk brings to the AI POD, teams should be able to gain faster insight into any issues. In addition, Splunk AI is expected to eliminate many manual tasks within SecOps, ITOps, and NetOps. Finally, Splunk is designed to ensure that AI agents can do their jobs without performing unauthorized actions.

We also think it’s worth noting that customers don’t necessarily have to purchase an AI POD to run Splunk this close to their AI workloads. Splunk has made its new runtime software and the reference architecture for the AI POD for Splunk available. This allows you to effectively layer this Kubernetes layer over any hardware stack that uses Nvidia compute. That said, one strict requirement remains: there must be NVIDIA hardware underneath the Splunk layer. That is, so to speak, the foundation for the Splunk Platform built on top of it.

“AWS is our hyperscaler”

The quote above is from the previously mentioned Kamal Hathi, who is responsible for Splunk at Cisco. You could see it as a kind of declaration of love. Splunk has made a decision and is entering into a long-term strategic partnership with AWS. In and of itself, this is actually quite striking, because just a few years ago, Cisco was on stage at Cisco Live alongside a Microsoft representative to announce a deeper collaboration with Microsoft. The focus then was also on cybersecurity.

Exactly what this partnership entails is not yet clear. The two parties have already worked relatively closely together in the past. For example, Splunk is part of AWS Security Hub Extended (announced earlier this year). You could view this as a full-stack security solution that combines the capabilities of AWS with those of a select group of partners.

If we are to believe Hathi, the partnership between AWS and Splunk will now go much deeper than just co-selling and integrating solutions. Specifically, it involves building agent-based security solutions, he tells us. The two companies are even launching a co-design partnership. This means they will jointly develop a solution that both companies will then actively market.

Conceptually, the partnership aims to combine AWS’s scale and infrastructure with Splunk’s Agentic SOC framework. This should make it easier for customers to adopt a security architecture that functions as a unified whole. Of course, it is equipped with the necessary additional intelligence thanks to AI. Exactly what this will look like remains to be seen. It also remains to be seen whether organizations are actually eager for such a convergence of major players into a single offering.