Cisco has introduced Cisco AI POD for Splunk, a pre-validated configuration intended to let Splunk Enterprise customers run the vendor’s AI capabilities in their own data centers, private-cloud environments or air-gapped deployments. The company puts a self-managed option alongside the cloud-based services that have been central to many enterprise AI rollouts.
Cisco says the offering is part of its Secure AI Factory with NVIDIA reference architecture. The configuration combines new AI runtime software, Cisco infrastructure, NVIDIA accelerated computing and a Kubernetes-based architecture optimized for Splunk AI workloads. It is available now, according to Cisco, and is designed for organizations that cannot move sensitive machine data to an external cloud service.
That placement decision matters for enterprises whose security, sovereignty or regulatory requirements constrain where operational data can be processed. Cisco says customers can self-host a selection of open and proprietary generative-AI models for Splunk Enterprise workloads, rather than sending that data outside their own environment. The release does not specify the deployment prerequisites, licensing terms or operating costs for individual customer configurations, so teams will need to assess those factors against their existing infrastructure.
The company says Splunk AI Assistant is available on the new layer, while an Agent Launchpad planned for later this year will support custom agent building and agentic investigations. Those capabilities could give security and operations teams a way to apply AI to their existing Splunk data while retaining responsibility for model selection, access controls and system administration. A self-managed architecture can change where a workload runs, but it does not remove the need to evaluate authorization, data handling and the reliability of agent outputs.
Cisco also announced additions to Splunk Agent Observability. The service, initially announced as an on-premises offering, is now available in Splunk Observability Cloud and Cisco Cloud Control, Cisco said. It evaluates agent and model behavior across the AI stack and includes runtime guardrails that the company says can block inaccurate or unsafe actions, including hallucinations and sensitive-data leakage.
A new Tokenomics capability is intended to make AI consumption more visible to technology and finance teams. Cisco says it tracks and attributes token spending across AI agents and employees’ use of coding agents, then forecasts consumption before a billing period ends. For enterprises trying to connect AI experimentation to budgets, that could provide a more granular view than a monthly model-provider invoice. The usefulness of those projections will depend on the underlying workload data and how an organization allocates shared AI services.
The company also emphasizes security operations. Cisco says new agent capabilities in its Splunk portfolio are meant to support detection engineering, threat hunting, investigation, coordinated response and policy governance, using telemetry from network, cloud, application and identity environments. Separately, Cisco and AWS said they have expanded their relationship through a multiyear agreement to co-develop security solutions.
For enterprise buyers, the most substantive part of the announcement is the option to bring Splunk AI to controlled infrastructure without making a wholesale move to a vendor-operated AI service. Organizations considering the platform will still need to test whether its model options, operational controls, capacity requirements and observability features fit their own data estate. Cisco’s announcement establishes the architecture and availability; a practical business case will depend on the workloads and governance constraints each team brings to it.

