SPEAKER_00

Hello everyone and welcome again to Cisco's Inside Product series. And today I have with me Kamal Hathi, who is the Senior Vice President and General Manager of our Splunk business. Welcome, Kamal. How are you doing, man? Hey, thanks. Good to be at you too. So we are going to talk a lot about Splunk today. I know you've been here for um uh is it has it been a year in the role? Just about a year in the role, yes. Just about a year in the roll. And um there's a lot that you've done in a year. And so we we're gonna start with all the great innovation, but let's start from the macro story. Um what is it that Splunk is doing today that you are excited about and you think the customer should be excited about?

SPEAKER_01

Yeah. It's very straightforward, actually. You know, we think about where the world is today. The it used to be this notion of resilience, you'd bounce back from something bad that happened. We live in a state of perpetual disruption. Like it's it's just not ending. And worse, there are in fact disruptions or or you know uh threats that have been exploited we don't know about even. So in this world, the one thing that we need to have is visibility. You've got to know what's going on end to end. Like it cannot be in silos, it cannot be in little parts and pieces. You need to know end to end across your entire digital estate what's going on. And that is what Splunk does at scale, at speed, with trust. And once you have that, we unlock all kinds of capabilities. We allow you to go and work at data, machine data, telemetry, uh, across every aspect of your of your enterprise, infrastructure, network. Network is amazing because what the amount of signals you can collect, your applications, now emerging AI agents, we correlate and provide a cohesive view across all of these things. And then via that, uh, we enable trust, security, observability, uh, and really allow you to have a resilient enterprise.

SPEAKER_00

So so that's great. So if you think about Splunk, one of the things that um people don't always understand is the the level of scale that Splunk has in machine data. I mean, you know, you go out and handle logs, events, metrics, traces, and you're doing it at petabyte scale. There's the largest of the largest organizations that are using using Splunk. What's the in your mind, what happens with um with AI and how does this market evolve? Like what's what's what's to come in the next two, three, four years, not just for Splunk, but for the industry at all.

SPEAKER_01

Yeah, yeah, yeah. So a couple of things. One, I think we handle the largest and largest, but you're gonna go even larger. And we can talk about that, right? There is no organization, there is no problem that is too big for Splunk. In fact, there's no one else who can do it. But we're going to take that to the next level. So let's put that aside for a bit. Now we talk about AI. AI isn't is has started off with interpreting human problems. We are having a discussion now, and AI is really good understanding this. The text, the audio, the video, the language, the constructs, but they're all about solving problems that we as human beings understand. It's trained on Wikipedia, it's trained on PDFs, it's trained on all kinds of uh sources that capture the corpus of our understanding. If you think about the enterprise, think about large-scale solutions that exist across network infrastructure, if you think about applications, how they interact, the language these systems speak is not the language we speak. It's all about telemetry. It's about very messy, very messy, unstructured, hard to interpret by humans' data. And making that available for AI, unlocking the potential of understanding what's happening in what sequence. And via that, starting to take action, understanding when the threat's happening, before it even is manifested to a human being. How to understand when a network is slowing down, or what sequence of events might eventually lead to a disruption. That is interesting and it's an unsolved problem, such. So we are driving towards that, and I think you will see more and more of the industry when they start talking about, especially as you start dialing in non-human uh actors, both um you know robots as well as software, in that environment where the non-human element is going to be orders a magnitude more, the ability to understand what's going on across the wire, the telemetry, the machine data, is going to be more critical than it has been to understand and interpret human data. And that's what we're doing. And I think that's what that's what you're gonna see the evolution of uh with AI in the coming uh I would say months and years.

SPEAKER_00

In fact, one of your leaders that shared a stat with me, which was really interesting, which was uh 55% of the growth of data will be machine data. And I actually think that's conservative in nature because you're gonna have as agents get more and more proliferated within the uh the ecosystem, you'll actually have them generate probably 80% of the total data. I totally agree with you.

SPEAKER_01

Especially if you talk about non-humanoids or machines, the kind of telemetry you're talking about is just way more even. Right. So you've got software, you've got hardware, you've got net, you know, it's just going to explode.

SPEAKER_00

Okay, so break it down for our customers. Um you've you've got this kind of large voluminous data that's gonna get even more voluminous because of agents um that are gonna be generating rapid amounts of data on an ongoing basis. Um and you are gonna provide the machine data platform, so to say. What are the top two or three problems that you will solve in this kind of uh umbrella of digital resilience? Yeah.

SPEAKER_01

And you sort of hinted at them.

SPEAKER_00

Yeah.

SPEAKER_01

The first one is about being able to understand and interpret this data at machine scale. It's really important because now we're dealing with many, many different diverse sources of data. You need to understand how to manage it, how to how to be able to get this noise out as a signal booster. Signal to noise is becoming really important way more than ever before. You need to be able to make sense out of it and create structure out of this unstructured data. That whole data management is a real problem that has to be solved. It's not the most glamorous problem, but it has to be solved in order to really start taking advantage uh and have great insights into what's happening uh across your enterprise. And that's sort of supercharging what's already happening today, but but at an extent that's not been done before. And we can talk more about how we do that. The second piece is not just working at machine scale, but it's responding at machine speed. And if you think about what's happening today with uh AI and agents and how they are uh behaving, the amount of code being created by AI is just unimaginable. The surface area of software, of code is just going more and more. And it has a couple of uh implications. One is it's more attack surface. The other one is even if you don't think about malicious actors, it just creates more defects, more problems uh in in your systems. And then you've got the external threats of bad actors using AI to come in, and these things are all happening at a speed that is AI speed, machine speed. So you need to respond at machine speed. You can no longer have human beings sitting there and looking at your logs, analyzing things, and finding the needle in the haystack. That needle is already gone into your, you know, it's it's in your mind and you and it's it's it's taking out very valuable parts of your of your of your systems. So you need to be able to respond as fast as the threats or even ahead of them. And this means agentic solutions for observability, agentic solutions for security, uh, agentic solutions for network operations. And that's the second piece of responding at machine speed, and you know, we have got this these notions of an agentic SRE, an agentic SOC, um, and they are really become very important. So that's part two. Part three is everybody has to start making sure that the AI they're deploying, the agents that are deploying, are practically scalable and usable in the enterprise. Not just experiments, not just bits and pieces that some teams try out. This is the mainstream. In the mainstream, that means you need to have trust. Trust in AI is a third and really most important part here. And that has multiple parts to it. One is just understanding is the AI, is the agent doing what it's supposed to do, understanding its behavior, evaluating it, and then creating guardrails if it's not doing what it's supposed to do. Right. The second part, which I think you, for example, deal a lot with is cost. The you know, AI was an interesting thing to get started with, but it turns out because it's so prolific, the costs are prolific too. And if you don't have a clear handle on what your token spend is, what your energy spend is, understand your return on investment on these things, how much, what am I getting back, which projects actually delivering what they're supposed to? If I thought I'll get a 10-second improvement in a certain process, did I actually get it? That ROI has to be correlated very clearly. And the third part then is just fundamentally the infrastructure for AI is different, GPUs, vector databases. These things need to be observed. So this is a third part. Trust in AI built upon from GPU to agent, uh, you know, with great insight. So those are the three things that we are really focused upon. Scale.

SPEAKER_00

That's that's on the observability side, the three things.

SPEAKER_01

Um yeah, so uh and trust also goes out in terms of security as well. We have a lot of work going on across Cisco on agent security, AI security with uh work in AI defense. All of these things come together, but they all have a common uh substrate, which is visibility, which is data, which is insights, co-related and cohesive. So that's where scale becomes important, speed becomes important, but the same data unlocks the ability to move with a genetic solutions on security, on observability, and then trust as well.

SPEAKER_00

That's that's awesome. So, okay, so let's let's attack each one of these individually. So machines, machine scale and machine speed, you already talked about that. That basically is your data platform. Um, you've launched a bunch of things in the data platform, the Cisco Data Fabric, Machine Data Lake. Walk us through what those are, uh, and then we'll go into the gentic solutions, and then the third thing we'll go into is trust. So start with machine speed and scale. What are the things that you've launched? What what do customers buy? And more more specifically, what kind of outcomes should they be expecting when they actually get those things? Like what does success look like? Right.

SPEAKER_01

So ultimately it's Splunk. Uh it powers what you call the Cisco data fabric. And what this does is provide the ability to go at massive scales correlating signals across your entire infrastructure, network, applications, uh other security signals. And it enables you to work at literally, I would say, infinite scale, but with a caveat that's really important to our customers, at very finite costs and very finite uh administrative and processing overheads. And the way we do this is with a couple of things. One is making sure that we are able to work uh with not just the data, but the context of the data. So we create correlative, you know, if you will, graphs that unlock the context, the meaning, the relationship between various data. And then via that we can unlock action. So that's sort of the fundamental piece. In order to do this, to scale really to the to this infinite scale that I talked about and keeping it extremely um manageable from a cost and processing perspective, we'll flip the equation on how we work with Splunk. In the past, our promise was put all the data into Splunk and we'll unlock any kind of insight you want. We'll find the most difficult piece very, very rapidly, but it required ingestion into Splunk. Now, what we allow you to do is we don't have the data come to Splunk, we take Splunk to the data, which means we can federate over all your data where it lives without copying, without moving. And this is really critical because organizations have data all over the place. Some large data lakes, sometimes small data puddles. Uh, but every vendor tells them to put the data into my environment. And that's just not feasible, it's not scalable. So, what we allow you to do is work on your terms, and we will take care of stitching together all the correlations, all the insights without having you to copy or move the data. So we make that highly scalable and highly cost effective with that approach. The other thing we do is we leverage uh our capabilities across Cisco. So we leverage iSovalent, uh, we are we leverage the edge processing that's available across the network to really make sure that we are picking up only important signals and using them for the purposes of our processing. And this is critical because if you really want to be able to operate at enterprise scale, the data is so large and so noisy that you need to be very focused on picking out the things that matter. And that's where you know ISovalent, for example, comes in. It's an incredible technology, allows us to operate on the edge, and together we are then able to unlock uh the signal that's really, really critical. And so our customers now are able to operate at this machine scale, um, but do so with a practical way. It's cost-effective, it's uh distributed, uh, it allows them to really have a handle on the data. So that's about go ahead.

SPEAKER_00

No, no, go, go, finish.

SPEAKER_01

No, I'll see that's all about the notion of you know the Cisco Data Fabric, the fact that we correlate data across Cisco, but also non-Cisco uh uh sources. Splunk has always been an open ecosystem. So we are amazing, first class, out of the box, consuming sources of data across, you know, Miracle, Catalyst, Nexus, uh WebEx, whatever it is into one cohesive view. But you know, we we do a great job with our competitive data. We'll take data from Paolo, we'll take it from Juniper, we'll take it from whatever else. In fact, in some cases, we actually are the best data fabric on our competitors' uh data. So we are the only company who can stitch this end-to-end view across the entire enterprise and do it at scale, do it cost effectively, do it with performance, uh, and allow you to have a practical solution for data.

SPEAKER_00

Yeah. I I I like the idea that you had, which is infinite scale, lightning speed, finite costs. Because one of the things that we always hear is hey, um, customers love Splunk, but sometimes there's a theoretical maximum beyond which they don't want to pay. And that model doesn't work in an ingest everything approach because there's a there's a real cost of compute for going out and ingesting all of that. There's a real cost of storage for ingesting all that data. And so you can't go out and give it away. The marginal cost is actually non-trivial. But if you keep the data at rest wherever it is, and you take your search and analytics through the data, then you're not actually paying for the egress and you're not paying for the storage and the compute on your side. That's right.

SPEAKER_01

Yeah. And the other thing that's important is not all data in its use is equal. Some data needs to be immediate. You have a threat, you want to go find out what's happening now. Others is for governance, is to prove that you did something. It's long term. So it's hot versus cold. And that itself is work, and we just take care of it. We provide a completely turnkey solution where you just go on to the data, we take care of where it resides, how to process it, how to make sure the signal from noise is boosted, uh, we ensure that it's structured for AI processing. So we provide a completely turnkey solution that allows you to work with uh this type of data for a very large number of solutions uh that that are possible.

SPEAKER_00

That makes complete sense. So, okay, so the first one that you talked about was machine speed and scale. The second one that you were you were getting into is this notion of agenc solutions for observability, for security, and for net ops. Um and let's just zoom in a little bit on security, even. You're gonna build an agentic SOC. I actually feel like it's gonna be very hard to think of a SOC that's not agentic moving forward because you you just have way too many signals to be able to process. And right now, what's happening that's completely irrational and scary in the market, but people don't have a choice, so they have to do it, is your signal-to-noise ratio is completely lopsided. There's too much signal compared to noise. You aren't able to go out and process every single alert that comes in, so there's alert fatigue, and then you only take a selective bunch of alerts that come in, and so the other alerts go unaddressed, um, and then that can cause a huge amount of kind of over um you know, kind of exposure for the company. So what are you gonna Are we at a point in time now where every signal that comes in, every alert that comes in can be processed by um um by your data fabric and by your um um um your entire kind of apparatus?

SPEAKER_01

That's that's the idea. So that's why these things click together. Yeah. You need to have that scalable uh cost effective data fabric in order to solve the problem with the gentic SOC. You cannot, these two are not independent. And it's interesting, it's also about just the agent SOC. But think about it, by correlating across all our infrastructure from the network to identity to applications, you know, et cetera, we can actually stitch together attack paths. Attack path intelligence is a very different meaning once you're able to go and do this. And this is very different from code level analysis within LLM, right where you try to find the attack path. We know what it is. Again, this is uniquely Cisco across network, across infra, across applications. And then for the agentic SOC, this becomes really important because now you have detections that are driven by depth of visibility and makes the AI confident to act. And sometimes, you know, if you if you see, for example, uh some sort of suspicious behavior, the current mode for most sort of competitive products is you take a sledgehammer and you squash a person, and that's it. You just take them off and everything's great. Well, it turns out that it could be a process that's doing where the problem is. So session level intelligence, being able to have a clear view of the attack path allows us to be confidently in a precision isolate what's going on. And this is sort of the the uh comparison between a scalpel and a sledgehammer.

SPEAKER_00

Right.

SPEAKER_01

We can be very surgical because our intelligence is at depth. So that's part one that's really important. The second thing about your point about handling all this data, yes, we can do it, and I think not can we, but it's imperative that we do it.

SPEAKER_00

So you have been very acquisitive off late. Um you've you've bought some companies, and those companies are going to play a very strategic role within the Splunk platform. Um walk us through the acquisitions you've made and why that's so important.

SPEAKER_01

Yeah, we've made a few acquisitions, um, you know, uh, and go back um, you know, a few months ago we made an acquisition in a company called Galileo, and we can talk about that in a bit. But Galileo is all about this notion we talked about, you know, trust. It's all about agentic uh behavior, monitoring, tracking, evaluating, and applying guardrails on their agentic behavior. You know, in Cisco Live, Jito, you did in your keynote, we showed a demo uh of this hypothetical retail, online retail where somebody goes off and does a return to an agent online agent, and the agent ends up giving the guy like 10x their price, the $600 to get $6,000 back. And and um the agent is just doing his thing. And then we showed how Galileo can create an evaluation for the agent, real-time observer's behavior, uh, and then uh prevent this from happening. Now, here's the thing.

SPEAKER_00

By the way, that that team is so impressive there, you know, X DeepMind, deep AI folks. Um, and um, you know, that team is so hungry. The co-founders are amazing leaders, and I've been really, really impressed. So congratulations on that team, and I think you're gonna do some great work there.

SPEAKER_01

And the thing they did, which was very interesting, is they very early in the Gen AI cycle, right? Started looking at this problem. It's not as somebody who came in afterwards and joined the hype train. They started the hype train. Right. And so it's very different of somebody who starts that train with somebody who sort of jumps in at the end. Yeah, lots of companies in the world right now, all of them are sort of jumping on, very few who early on knew what's going on.

SPEAKER_00

They have the original insight to start it. Okay, so Galileo is one, and they're going to be our observability for AI platform. Everything from uh resilience of the infrastructure to the behavior of agents and guardrails that get applied to it, as well as the tok uh as the tokenomics that you have for the cost of managing tokens. Um what's the second acquisition you did?

SPEAKER_01

Right, G2. The other acquisition recently made is Whitefield. And that's a super interesting one. Let me tell you a little bit more about them. Uh, one of the big parts of understanding uh what's happening in the environment usually is after someone has uh maybe infiltrated or something bad's happened. So understanding the Sequence of session level activity, understanding which identity is trusted, which is not trusted, understanding the graph of how each of these actions impacts the next one is critical. And so they really are an amazing job of building a platform that weaves in identity and session level intelligence into a graph that we can now leverage in the Cisco data fabric in our agentix orc and provide solutions that previously just couldn't be done. Previously we would just be, you know, we wouldn't have enough intelligence to go and take care of a session level problem and understand exactly which actor, human, non-human, uh, was involved, what were their, what were the steps they took, which other actors did they go interact with? That entire graph is so critical in being able to have a really intelligent understanding and response to the threats that we see uh across this landscape. So there they're gonna, and by the way, the other thing about both these companies, you said, is the technology, but then it's a talent. And this and and these guys also are amazing. They're very, very sharp. Uh, I think some of them have worked at Cisco before, and you know them, uh, but very sharp, very strong. And I think this takes Splunk and Cisco to yet another level uh in terms of relevance and what we can do with with uh with our products.

SPEAKER_00

No, I'm so excited with um not just the organic team you've built internally, but how we've been able to augment that with uh folks from the outside. And um so um what questions should I have been asking you that I haven't gotten a chance to ask that you'd like to convey to customers um as it pertains to using Splunk in completely different ways in this agentic era?

SPEAKER_01

Yeah, I think the one thing about Splunk that our customers should understand is that this is a different Splunk. Splunk is, by the way, is an amazing uh product, fantastic brand. Our customers love us. If you come to the content which you have multiple times, the amount of fandom is just something that is driven out of deep organic love for the product.

SPEAKER_00

Yeah.

SPEAKER_01

And then no amount of money.

SPEAKER_00

You definitely have a very kind of committed community to the success of Splunk.

SPEAKER_01

That's right. Yeah. However, it's you know, historically, Splunk's been a toolbox, a bunch of things you put together. Uh, it requires complicated processing, and once you do, it's amazing. What we're doing is by leveraging AI, by leveraging agentic solutions, and generally making it much, much easier to just use it, is we're taking Splunk not just from that niche where it's highly effective, but we are going to broaden its capabilities, make it turnkey, one-click, uhgentic at its core, so that when you, for example, deploy Splunk, you don't have to worry about your data pipelines staying up and relevant. We will take care of it for you. You don't have to worry about whether or not uh you have enough compute. We will we have this notion of agentic twins that run in parallel and watch over your infrastructure all the time. We unlock the ability to use large language models in the context of our language, SPL, and we make it much, much simpler. We use natural language, we use Cisco Cloud Control and AI Canvas and is deeply integrated in for a much, much easier solution. So what you get is a highly, highly scalable, extremely sophisticated solution that over time will become extremely easy to use, extremely broad and highly cost-effective. This is a different um company, if you will, inside what Cisco has been able to do with us. And I think for our customers, the value they're going to get out of this is exponentially higher than they ever had in the past.

SPEAKER_00

Yeah, you still preserve all the goodness of Splunk, but you've basically added dramatic simplification to the use of the portfolio. Um, and your economics are far more seductive, and your ability to make sure that you can have not just the classical use cases with data, uh, which is you know application observability as well as you know uh the SOC, but now you have an agentic SOC, now you have an agentic SRE, and now you have a full uh stack for observability for AI that goes from resilience of the infrastructure to the behavior of agents and assessing that to the tokenomics that are required. I think this is truly remarkable what you folks have done in a very compressed amount of time. So congratulations on that. Thank you. Thank you.

SPEAKER_01

Lots more to come though. We've just got started.

SPEAKER_00

You've just got warmed up. Any kind of sneak peek that you want to give people on what they should expect?

SPEAKER_01

Um so you'll start seeing uh some interesting things coming through. Uh I'll give an example of it. You know, we've it's the agent studio that you announced at um at uh Cisco Live. Uh we're gonna have Splunk as part of it. And and the simple thing here that takeaway is you will just be able to write SPL, which is the Splunk programming language, and it'll automatically create automated, scheduled agents for you to solve the problems you want to solve. And it just takes your ability to work in Splunk and makes it into an agentic solution for arbitrary types of problems. And that really opens up like the kinds of things you can do and the autonomy you can create, yet relying upon the power of Splunk that you already invested in. That's an example, but there's a lot more coming. My my answer to that one, though, is come to .conf in September in Denver. You can see lots of interesting things, and we will talk about uh you know what's ahead. So hopefully see that many of these of your viewers end up coming there.

SPEAKER_00

You know, that is a great event. Uh I have to say that the the the most exciting thing about that event is that community of of Splunk lovers make the ability to make data their superpower is um is nothing short of extraordinary. And uh I can't wait to see what their reaction is going to be with the stuff that I know you folks are building right now that I have a sneak peek of. So, congratulations again to you and the team. Keep doing what you're doing, my friend. It's it's such a pleasure to have you on the show.

SPEAKER_01

Thank you, Judu. Always great talking to you.

SPEAKER_00

Take care.