Product1 publisher3 min readPublished
Splunk's year-end join of observability and security data requires customers to own both products
Cisco and Splunk spent the .conf26 keynotes on trust and on who is authorized to act. The two items named as shipping are a token-cost meter available now and a dataset join gated on holding two licenses.
The Product Desk · Product desk

What happened
- Splunk security chief John Morgan previewed an integration shipping at year-end that lets any customer holding both Splunk Observability and Enterprise Security join those two datasets.
- Cisco's Jeetu Patel told the keynote that agent token consumption passed human token consumption for the first time in February and stood at five times human consumption seven months later.
- SiliconANGLE reported that the .conf 2026 keynotes in Denver centered on trust and on who or what is authorized to act, with Patel calling agents the new workforce and saying trust is what adoption depends on.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Morgan said the observability and security teams often have different budgets, so the cheapest route to one shared evidence trail runs through a second product line item in someone else's plan.
- decision When an agent failure and an intrusion look the same in the telemetry, somebody has to be named on call for agent incidents before a joined dataset does anything but give two teams more to argue about.
- cost With most AI compute going to inference, agent token spend is a monthly run rate, and the buyer who turns on forecasting is the one who has to defend the number to finance.
- capability Correlating agent traces and evaluator scores with security signals makes an agent's actions provable after the fact. That record is what an incident review or an auditor asks for.
Splunk put an AI engineer and a security operations analyst on stage, working the same incident from two consoles [9]. In a real shop at four on a Tuesday afternoon, that same incident is a question about who gets paged first, and Cisco president and chief product officer Jeetu Patel gave the reason it is hard to answer: "It is actually very hard to distinguish between whether there's a breach, or some agent was poisoned because of an external prompt, or the agent just exercised poor judgment because it was very literally following your instructions," he said [10].
Splunk's answer is a single correlated set of data: agent traces, evaluator scores, application telemetry, network data and security signals, with one evidence trail serving both teams [11]. Patel said agents "are like teenagers" [8].
The join has a gate on it. John Morgan, Splunk's senior vice president and general manager of security, previewed it for customers who have both Splunk Observability and Enterprise Security [12]. He was direct about the org chart: "We want to respect that the observability and the security teams are different. We know they often have different budgets, but at the same time they have the same business goal," he said [13]. Shared evidence therefore sits behind two purchase orders.
What is generally available now is a meter. Splunk Agent Observability ships in the cloud, on premises and as a native Cisco Cloud Control application, and its Tokenomics capability tracks and forecasts token spend across agents and coding tools [14]. SiliconANGLE's write-up does not include a price [19].
The demand case came from Patel. He said agents passed humans in token consumption for the first time in February and were consuming five times as many seven months later, calling the crossover "wild" [6]. February plus seven months is September, the month SiliconANGLE published its account [16]. The agent-to-human token ratio therefore moved from 1:1 to 5:1 in seven months, about 26 percent compounding a month (5^(1/7) = 1.26) [17]. Patel also cited projections putting roughly 60 percent of this year's global AI compute on inference [7]. That leaves 40 percent for training [18].
When the pager goes off, people file the incident where their license and their budget already are. Two questions settle whether the year-end join is worth buying in January. Do you already pay for both Observability and Enterprise Security? Is one named person on call when an agent misbehaves? Yes to both, and the join cuts triage time on incidents nobody can classify. Yes to the license and no to the owner, and you have bought a shared dataset and kept the argument. No to the license and yes to the owner, and the join costs you a second product. No to both, and Tokenomics is the only part of this you can use this year, and it is a finance tool.
What to watch
- Whether the year-end integration ships as a free join or a separate SKU for customers who hold only one of the two licenses.
- Whether finance teams accept Tokenomics forecasts as a basis for chargeback rather than after-the-fact reporting.
- Whether Cisco puts named identity and permission controls for agents behind the workforce framing at its next event.