Splunk and Cisco Advance Predict-and-Prevent Operations
Predict and Prevent Operations Take Shape
Predict and prevent operations are becoming a central theme as Splunk and Cisco bring observability, security, networking and AI together. In this Techstrong TV interview from SplunkConf 2026, Alan Shimel talks with Cory Minton, Global Field CTO at Splunk, about what this shift means for digital resilience.
Minton says the industry is moving beyond a world built only around detect and react. For years, teams focused on reducing mean time to detect and mean time to repair. The next goal is more ambitious. Organizations want to predict likely failures, investigate them before they affect customers and prevent outages from happening in the first place.
Trusted Telemetry Comes First
The conversation explains why a self-healing enterprise starts with data. Teams need trusted telemetry across applications, infrastructure, networks, security tools and emerging agentic systems. Without that operating picture, AI systems lack the context required to make useful recommendations.
Splunk’s role as a system of record for operations becomes important in that model. Cisco adds network telemetry, topology context and enforcement capabilities. Together, those signals can help teams understand whether a problem is tied to security, software, infrastructure, networking or some combination of those domains.
AI Agents Help Investigate Before Impact
Minton describes a four-step model for predict and prevent operations. First, organizations collect trusted telemetry. Next, fit-for-purpose AI models predict anomalies or likely failures. Then, agents investigate the why behind those signals before an outage occurs. Finally, humans receive guided remediation and decide how to close the loop.
That human role remains critical. Minton frames the change as moving from human in the loop to human at the helm. AI agents can reduce toil and accelerate investigation, but people still need explainable and auditable recommendations before operational changes are made.
Digital Resilience Becomes the Outcome
The interview also connects the Splunk and Cisco integration to a broader digital resilience strategy. Minton says the combination gives network operators, security teams and SREs more useful signals and more ways to act on them.
For technology leaders, the takeaway is clear. Predict and prevent operations require more than dashboards or broad AI claims. They require trusted data, purpose-built models, agentic investigation and human judgment working together to keep services secure, available and resilient.
Transcript
Hey, everyone. We're back here at Splunk Conf26 in Denver, wrapping up, doing some more videos, having some great conversations. It's been a great show, it really has.
There's been so many announcements, and like you would expect with Splunk, it runs the gamut from operations and observability and security. And what's really nice is the theme I'm picking up on now is that Splunk and Cisco, One Cisco, bringing it all together, that observability is part of security, security is part of observability, and they're both part of this broader Cisco mission to use AI and agentics and everything else that goes with it to really empower people and their work. And this guy here's probably the best person we could find to talk about that.
Let me introduce you to Corey Minton. Corey is global field CTL at Splunk. Yes, sir.
And Corey, welcome to Techstrong TV. It's great to have you on, man. Thank you, brother.
I'm back. This is my third time, I think, to do this. Yeah.
You've been on our Now. I'm honored. You've been on Techstrong TV before.
Big fan. But it's funny, we were actually speaking of AI. Yeah.
So, we don't need to put this on the video, but we're moving 21,000 videos into a graph. Oh, yeah. Okay.
I love that. To make it searchable. So, if we want to just talk about Corey and his watch- Okay ...
it'll actually go through the videos. For sure. I've built my own personal knowledge graph, and honestly, I'm a super geek for AI in so many ways.
Yes, I'm excited about it for what we do in operations. Yes, I'm so excited about the innovation we're shipping. But personally, my work has been transformed by this agentic idea.
And I think that there's this brilliant opportunity for everyone in every part of work to learn these tools. Mm-hmm. Understand this beautiful system that you can create for agents to be an assistant to you.
And I say it all the time to customers, to friends, AI is not taking your job, but somebody who uses AI better than you is coming for you. A new take on the job. Yeah.
And my world has been transformed, and it is a wild time to be alive. Yeah. My time, me too.
" Yeah. " I'm having too much fun. I tell people the same thing.
I love what I'm doing, man. It stops being fun, I'm going home. But right now, it's so fun.
But right now it's fun. Yeah. Yeah.
So we're really looking forward. It's 21,000 videos. That's wild.
It's almost 100,000 written articles. So, I have 63 agents in production that run full-time. Really?
I have a knowledge graph that has now grown to... It's wild the number of nodes that are in it, but it's about, I think it said the other day, it was like 9,000 nodes in my graph of the kinds of work I do in a trusted, secure way that I've built completely on Cisco-provided tools. So, all the data's safe.
I love it. It's confidential. But it has transformed my work and productivity.
And I was actually able, this past year, or a few months ago, to recruit a team to come work for me. " And so we're teaching the company how to use these tools. We're early adopters of this.
It's so funny you're bringing this up, man, because here's my take on this. Yeah. I'm the CEO here.
Yeah. Exactly. I'm not supposed to be the person who necessarily...
But I am. Yeah. I'm sitting here waiting on you.
I'm in my different agents and stuff- Yeah ... doing 12 different things. I've written 25 special reports in the last month that average about 20 pages.
Yeah. On all kinds of topics. How do you think I prepared for this interview?
Absolutely. I literally had agents go out on Chrome and give backgrounds on everybody in this room. Really?
Well, I can imagine you're excited about me. Give me some talking points. But here's the thing.
I have this conversation with my wife. She's like, "I thought you went with this whole Futurum thing-" Yeah. "...
" Yeah. " Here's the thing about 10Xing yourself. You got to manage those 10.
You do. Absolutely, you do. You know what I mean?
So, even though my output is 10X- Yeah ... and I use AI for a lot, it helps me with a lot of the output, I still got to manage that 10. And I think that's where people need to...
We got to figure some rules out there. Yeah. And some best practices.
Agreed. Actually, I've written about this quite a bit, and one of the things I talk about from a management or leadership skill set is this idea of agency. Mm-hmm.
And you have to have the agency to look at what are the tasks that are toilsome, that are burdensome, that every week you have to do repetitively, and how could you have this really scalpel of your day, your week, automate as many of those things as possible. Try to approach everything you do with a, do I want to do this again manually, or could I build a system to do it for me? But then once you get to this production level, you have these agents working for you, you become an orchestrator.
And it's a role change. My job is fundamentally different than it was six months ago. My productivity is through the roof in terms of what's happened.
That's great. Right. But I'm able to go spend my...
Which I love this. During our keynote, Lip-Bu Tan from Intel. Mm-hmm.
" Yeah. I want to deploy that beautiful human intelligence on things that require it, and I want to automate the toilsome, burdensome things that we do as rapidly as possible. So, I call that going from human in the loop to human at the helm.
Yeah. Right? Yeah.
So, get the human out of this mundane sort of stuff. Yeah. We look for human in the loop, human on the loop, so I'm aware- Right ...
but I don't have to decide. And then human steering the ship, essentially. Absolutely.
Right? Charting the course. Couldn't agree more.
Yeah. We got ahead of ourselves. I wanted to start with you.
For sure. Give people a little bit of your background. Yeah.
So, I'm a technologist and a curious learner at the core. I would never guess. So, my job is I'm the global field CTO for Splunk, and really what my day-to-day life is, is really interacting closely with our product teams to understand what are the innovations that we're bringing to market and the why behind them.
Communicate that to our most important strategic customers and our partners to help make sure they understand why we're doing the things we are, and what's the story behind how you turn all this technology into an outcome that matters to people long term. How does it change their life as an operator? And then work between those two groups, right?
Work between our customers and our partners and our product teams and make sure that there's good conversations happening back and forth. We identify, my team really focuses on that joint innovation opportunity that, what are those customers that are pushing the limits that we could do something really interesting and cool together, and then marshal the right resources, architect the right solutions, and bring those to market, and then tell the story really well. So, I spend lots of times talking with great folks like yourself about why we're doing the things we're doing.
It's like you can read the list of the technologies, but it's like why? What does it actually unlock? What does it mean to an organization's operating model?
How does a leader think about consuming that technology, training their teams differently, orienting their organization to prepare for each of these kind of waves that are coming? And man, they're coming faster. So, my career history, I've been a technologist from every role, and I just love talking to people about how technology can transform what they do day to day.
Love it. I wanted to go serious for a second here about Splunk- Yeah ... Cisco, what took place this week here at Splunk Conf.
Yeah. I've been following Splunk probably since 2006, something like that. That's awesome.
Yeah. Early on. When the black T-shirts were the...
That was the shizzle back then, right? That's right. It was everything.
And I've been around. This is my 14th Conf, by the way, so. Is it?
Good for you, man. Yeah, been around a minute. Yeah, it's been a minute.
I'm sensing, though, and it's been what now? About three, four years since Splunk was acquired by Cisco? Yeah, not quite three, but yeah, close to.
But I really feel like at this year's Conf- Mm-hmm ... we're starting to see the partnership pay off. Absolutely.
We're starting to see it get real. Yeah. We're starting to see integration.
And at the same time, there's a third party to this, Agentic. True. Yeah.
Right? So now we're seeing the role of the agents- Yeah. On the underlying Splunk infrastructure and solution set, married to what Cisco brings to this.
Mm-hmm. And now we've got a really powerful new force- Yeah ... in the market.
I couldn't agree more. I think one of the things that we've historically been known for is we're a data platform- Mm-hmm ... first and foremost.
And I think what's happened over the last few years is that we've recognized that there's this power in having a system of record for operations to live in. And so- Mm ... if you think the big software-as-a-service players out in the market, the ones that figure out this cross-domain, cross-vertical usage really have a chance to win in this agent era.
Because at the end of the day, you need a system of record that can be trusted so that your humans and your agents have the right context to go to work. And so, we are a system of record for operations, and customers have trusted us for 20 plus years now on make it easy to get telemetry about the digital systems that drive my business into a place where I can correlate them well, right? We used to use this term monitor monitors, but correlate cross-domain, cross-systems, and answer questions rapidly on digital resilience, which is simply are my services, my revenue-generating applications, my operations, are they secure, and are they up and running as they should?
Are people experiencing this digital experience the way they should? And if not, how do I get back to a good state as rapidly as possible? And so, I think what you're sensing is we really didn't have this focus on network topologies and network telemetry in the past.
It just was kind of a blind spot for us. And when Cisco acquired us, and actually before they acquired us, when it was announced, we started in earnest this work to say, "What are the Cisco sources of data that could inform us about signals that would be interesting to understand operations in a new way? " And so, what you're seeing with a lot of the announcements this week is that work has been happening.
Yeah. We have been engineering it together, and now we have these really incredible solutions to meet network operators in a way we've never done before. And ultimately, at the end of the day, whether it's, we go back to that resilience, if an outage happens, it's really hard to determine oftentimes, is it a security breach?
Is it a failure in a software push? Did we push bad code? Is it a network challenge?
Is it an infrastructure challenge? And so, this is just, to me, it's more signal so that we can... Sometimes data can be noise.
How do you find the right signals across this operations landscape to go take action that makes your customer happier? And I will tell you, the biggest things that you've heard today, if you tie it all together, it's the world of detect and react, where we've spent, the industry's spent 20 years getting good at shrink my MTTR, shrink my MTTD. We're moving to a place now where moving to negative MTTR is real.
We can actually predict when a likely outage scenario is going to happen, when a likely challenge in our infrastructure, in our services is going to happen. Take action before it becomes a problem, and avoid the outage altogether. And so, we talk about it, it's like detect and react is the old way.
Predict and prevent is where we're going. I love that. And we've meaningfully built the technology to make that possible today.
With generally available technologies today- Yeah ... with the agents that we've deployed, with the AI capabilities we've deployed, it's real, and it's wild to see what customers are doing with it. It really is, and it is available today.
I don't know if you saw the OpenSSF- Mm-hmm ... group came out today. With their usual plea, we need more money for open source maintainers.
Yeah. But now, of course, like everyone else, they're wrapping it in the danger of AI. Yeah.
Right? And- It's got the news cycle. It certainly does have the news cycle, that's for sure.
And I read it, and as someone who does this for a living- Yeah ... I got to be honest with you, I was a little, okay, they found a new wrapper for the old story. Yeah.
And I'm not anti-open source. I'm not- No, I'm with that ... anti-giving the people who maintain these projects more money and resources because maintaining these repos that we're all using is an awesome responsibility- It is ...
that needs resources. Yep. But I feel like it just adds to this diatribe that we're hearing in the last week or two of the anti-AI stuff.
Yeah. We don't hear enough of the positive. I completely agree.
I'm a huge fan of open source. I believe the future is dependent on open source, open weight AI. Yeah.
I believe that software is better when open source is at the core. I think there's organizations that have to figure out how to monetize their business, and that's a reality we all face. But I think that collaboration between open source and closed private technologies when they're the right technology to solve the problem is a beautiful thing.
And I think we've been huge contributors to a number of open source projects, employ some of the top sort of contributors, maintainers- Yeah ... of open source projects because we firmly believe in it. But I think it creates this wonderful ecosystem where everyone can benefit if we do it right.
And so, I get the need for taking care of maintainers, taking care of those folks. We have to because it's part of our culture. Yep.
But I do think that that's that collaboration that we have to work at. And I think some of that may be based on the exciting times of valuations of companies getting exciting that we're all trying to... We're humans at the end of the day.
We want to be compensated for the things that we do. Absolutely. We want to be compensated.
It should have to be, right? People shouldn't have to toil without being rewarded or compensated. Yeah.
Cory, I want to come back to what you said. Yeah. Right?
Predict and prevent. Yeah. PAP.
I like that, PP. Right? Okay.
I know what people out here are saying. Sounds kind of slog chucky. Yeah.
Right? Sounds kind of out there. Yeah.
I'll explain it. Honest, where are we on that? Yeah.
So, it's actually a pretty simple idea. And it's we should be moving towards... When we say predict and prevent, I like this framing of a self-healing enterprise.
And a self-healing enterprise requires a couple things. And if we go from I detected something and then I have to go fix it, to I predicted something, it's a pretty simple, I call it a four-move process. You have to have trusted telemetry to where you can sense and see everything that's happening in your organization from an operations perspective.
Deep telemetry, metrics, events, log traces of everything that your team is doing, from traditional applications to cognitive applications to these agents. You have to have visibility into every bit of it. Once you have your data estate in order, you can meaningfully start to deploy machine speed prediction.
And so, in our world, you have to have a harness and an AI runtime where you can feed that telemetry into fit-for-purpose models. Not all of them have to be large language models, but fit-for-purpose models that are really good at predicting the future state of time series data and operations. " An anomaly is predicted with some level of confidence.
That's now time not to drown your SRE or your SOC analyst with new alerts and this noise that's really hard to deal with. That's when you kick off agents to go investigate. And when you have meaningful agents that can triage, can be an SRE to understand and go start to look at this full fidelity copy of data about your operations that, hey, we predicted a signal in a few things that might be an outage.
Have the agents go to work in researching the why, like, what's actually happening. Yeah. Correlate across that telemetry environment.
And then when you've figured out, when the agents have figured out, again, we're in this predictive stage. The outage still hasn't happened. I get it.
Why did it happen? And what is the right remediation step to take in order to make that outage never happen? And you hand that, an informed delivery- To a human ...
to a SOC analyst, to an SRE, right? To a human. To a human.
" Because again, it's non-deterministic software that's making a recommendation. Like I liked- Exactly ... " That's the wrong context.
No one wants to do that. And nobody wants to do that. " And give humans agentic systems that can actually go cross-domain, help them with an investigation in real time, generate the right visualizations that allows that human brain to work, and then at that point, once the human's brought the investigation to I know what to do next, close the loop, fix the problem, run a playbook, run an automation to fix the problem.
But every step in that process has to be explainable, has to be auditable, because at the end of the day, these are decisions that are being made for operations that can't get things wrong. , and then give humans the tools to work alongside agents to go drive operational outcomes. That's the world we're moving to.
And the wild thing is, literally this week, we've been talking about all these different products and capabilities. They all serve that outcome. You could literally take any one of them and go, that's where this fits in.
And the storyline is brilliant. We're making it easier for agents to use Splunk as a system of record for operations intelligence. We're putting agents to work in roles, not like these broad, like, oh, they're going to solve everything.
Agents fit for purpose, agents to solve a particular problem, to come alongside a human and advance their operations so that we know. In the SOC, the people are tired. It's a hard job to do.
Yeah. It's one of the toughest jobs in the industry. How do we make their lives better?
And I think that's everything we're doing is focused on how do we make those operators' lives better by bringing agent systems to bear for them to advance their outcomes. You like what you hear, you want it to be happy at your place, get ahold of Cory. Hey, man, we got to run.
Yeah. Thank you so much. Awesome time, John.
Yeah. Always a pleasure. Thank you for being here.
Appreciate you. Cory Vint, Global Field CTO at Splunk, here at Splunk Conf. We're going to have more coverage.
Stay tuned.