Product1 publisher3 min readPublished
Splunk federates search into Snowflake and Databricks to cut costs of data duplication
Cisco's Splunk unit is repositioning around telemetry it expects agents to generate faster than people can read, with a new fabric that queries Snowflake, Databricks and object stores in place. Pricing was not disclosed.
The Product Desk · Product desk

What happened
- Cisco's Splunk unit unveiled a set of platform, security and observability changes on September 15, positioning itself as the data and governance foundation for what it calls the agentic enterprise.
- Splunk says the design targets a longstanding complaint about the cost of ingesting and indexing data, which it expects to sharpen as hundreds or thousands of agents emit telemetry continuously.
- Splunk AI Assistant runs on the Cisco and Nvidia configuration now, and Agent Launchpad, due later this year, will let customers build agents in-house with templates, MCP connections and human controls.
- A multiyear agreement with AWS commits the two companies to jointly developing agent-specific security products, with Splunk contributing its data platform.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision The renewal conversation stops being about how much daily volume to license and becomes a per-source decision about what leaves the index.
- constraint Cost relief depends on the customer actually ending the copy, and the compute a federated query burns lands on the bill of whoever owns the lake, so the observability budget spreads across other teams' invoices.
- capability Regulated and air-gapped operators can run the assistant, and later self-hosted agents, without shipping operational data to an outside AI service.
- exposure Once agent traces sit outside the index, the length of an incident review is set by retention rules in CloudWatch or Databricks that the security team does not control.
Teams tell themselves they will tune the noisy sourcetypes properly next quarter. What they actually do, when ingest volume runs over plan, is switch off the low-status ones and hope nobody needed them during the next incident. Cisco Data Fabric is aimed at that habit. Splunk says it analyzes information where it resides instead of requiring customers to copy everything into Splunk [6], federating across Splunk, cloud object stores, data lakes and platforms including Snowflake and Databricks [7]. Expanded federated search covers Amazon Web Services CloudWatch data lakes and Databricks [11].
Splunk frames all of this as a response to volume it expects agents, not people, to produce [3], and it puts the count in the hundreds or thousands, each emitting logs, events and traces continuously [8]. "Cost is directly addressed by this federated approach," said Mangesh Pimpalkhare, senior vice president and general manager of Splunk Platform at Cisco. "If you start duplicating data movement and all the processing needed, that is what drives up costs" [9].
A federated query still runs on compute somewhere, and when it runs in Snowflake or in a CloudWatch data lake, that compute is supplied by the host system and not by a Splunk index [23]. The saving shows up only if the customer stops the copy, which means somebody sits down with the source list and takes things out of the index. The SiliconANGLE report does not state pricing or licensing terms for the fabric or for the new hardware configuration [22].
The platform also adds a universal collector for metrics, events, logs and traces, real-time ingest processing, and smaller models trained on operational data, with examples in time-series forecasting, log analysis and graph reasoning [12][13]. "We are not reinventing frontier models," Pimpalkhare said. "Our goal is to complement those frontier models and develop the next level of domain-specific models" [14].
For shops that cannot send operational data outside, the Cisco AI POD for Splunk combines Cisco infrastructure, Nvidia accelerated computing, Splunk AI runtime software and a Kubernetes architecture validated for Splunk workloads [15], and supports on-premises, private-cloud and air-gapped deployment [16]. Of the four self-hosted models Splunk named, three come from outside Cisco: Google's Gemma 4, OpenAI's GPT-OSS 20B and Nvidia's Nemotron, which arrives later [18][21]. Pimpalkhare said customers do not have to choose between on-premises AI and cloud services: "They can absolutely combine the two" [19].
A workable sort for Monday uses two questions per telemetry stream: who reads it, a human or an agent, and how fast it has to answer during an incident. Streams a human opens in the first ten minutes of a page stay indexed. Streams an agent pulls on demand, where a few seconds of latency costs nothing, are the federation candidates. Streams nobody has queried in a quarter should stop being collected. The awkward box is agent traces that nobody reads until an audit or a post-incident review: cheap to leave in an object store, useful only if the retention on that store is longer than the review cycle.
What to watch
- Whether Agent Launchpad ships this year with the promised MCP connectors and human approval controls intact.
- Whether Splunk publishes a price for federated queries against external stores, and how it compares with indexed-volume licensing.
- What the joint AWS work actually produces, and whether the agent-security products cover agents Splunk does not collect from.