Every generation of enterprise infrastructure eventually reaches an architectural inflection point. AI appears to be creating that moment for Security Information and Event Management, known as SIEM.

The question now is: With its ownership of Splunk—a leader in SIEM—will Cisco now take advantage of this opportunity or bumble it?

There’s a tidal wave of data analytics startups as well as established vendors going after the so-called “next-gen SIEM” market, which is rapidly evolving and growing—even though nobody knows exactly what it is. Indeed, this market is actually several markets at once, with nuances behind the scenes.

Splunk is still the huge incumbent in the market. Acquired by Cisco in 2024, Splunk has plenty of time to defend its incumbency, as a large roster of both public and private competitors look to feast on the explosion of demand for data storage, telemetry, and analytics.

With Splunk’s annual conference coming up later this month (Denver, September 14), it’s a good time to watch how Cisco shifts its strategy. Industry insiders tell us that Chief Product Officer Jeetu Patel, who has made large strides in reinventing Cisco’s portfolio—including networking, AI infrastructure, and even communications with a reinvigorated Webex—is now focused on transforming Splunk.

Let’s dive in to see how this could pan out.

Splunk was Cisco’s largest acquisition ever , at $28 billion in cash in 2024. Under Cisco, Splunk now faces an architectural transition as AI increases the strategic value of historical security telemetry and data analytics. AI’s also shifting priorities for customers, as they determine how AI models and agents can better access security data to build autonomous workflows.

Splunk rose to prominence by becoming the de facto data analytics platform for several use cases, with cybersecurity being one of the most important. But Splunk is coming under increasing pressure from customers and competitors alike. Customers frequently complain that the cost of data ingestion is high and that Splunk’s volume-based licensing is unpalatable for high-volume applications, which of course include AI. Splunk was most recently contributing about $4 billion in annual revenue for Cisco, but its growth has slowed and has been complicated by a shift from on-premises to a cloud business model.

Splunk’s challenges are reflective of a big architectural shift happening in the SIEM space. Traditional SIEMs couple storage and compute as organizations retain only months of logs. AI transforms historical telemetry into context for autonomous investigation, reasoning, and threat hunting—making long-term retention strategically valuable rather than merely a compliance requirement. Security areas such as extended detection and response (XDR) as well as the emerging agentic security operations center (SOC) markets need this data, whether via their own tools or from partnerships.

Cisco’s public direction around AI—the Cisco Data Fabric/Splunk Machine Data Lake and federated access—suggests it recognizes this transition. There is an opportunity to evolve Splunk into an AI-era platform while preserving the ecosystem that made it the industry’s leading SIEM.

There are also new hints that Cisco CEO Chuck Robbins and his product chief, Patel, have a Splunk overhaul in the works. Just this week, Cisco named Sunil Potti the new SVP of Cisco’s combined security, observability, and data platform organization . Potti was previously a partner at Wing Venture Capital. (Prior to this announcement, I asked for a briefing from Cisco. The company said it was holding off on comments until the Splunk event, .conf26, which will be held in Denver Sept. 14-17.

Competitors Come to the Fore

Cisco will have to move fast to defend its turf. The data analytics and SIEM markets include a who’s who of tough competitors, including Elastic, Datadog, and Sumo Logic. Cloud giants such as Microsoft and Google offer SIEM alternatives with Microsoft’s Sentinel and Google’s SecOps. Cybersecurity vendors such as Palo Alto Networks and Crowdstrike are getting in on the action with their own integrated SIEM and SecOps platforms.

“Across several of our largest enterprise customers, we are witnessing security leaders actively rethink the architecture of the SOC, and the future of SIEM is becoming a central part of that planning,” said Rikin Shah, CEO and co-founder of Slower, an AI-native technology integration firm. “Increasingly, they’re looking beyond simply optimizing ingestion toward architectures that decouple how security data is stored, computed on and accessed, allowing them to economically retain far more full-fidelity telemetry while preserving the workflows their security teams already depend on—because as AI transforms threat hunting, investigation, and incident response, having years of historical context immediately available becomes an increasingly valuable strategic asset.”

Meanwhile, the agentic SecOps category is brimming with venture-backed startups that will either partner with SIEM providers or bring their own to drive more automation into cybersecurity services. Some private SecOps companies to watch include 7AI, Exaforce, Imply, TENEX.ai, Stellar Cyber, and Torq.

All of this points to lots of movement in the combined markets of SIEM, XDR, and agentic SOC.

“The traditional SIEM players are trying to find a niche while the market moves to agentic technology,” said Steve Garrison, a longtime technology executive and SVP of Marketing for Stellar Cyber . “There is still SIEM budget, but more people are thinking of a holistic platform. SIEM, XDR, and SOAR [Security Orchestration, Automation, and Response] are merging to become an agentic SecOps platform. We are all chasing that dream. We think we’re ahead.”

Many of these technologies can be mixed and matched to build the most effective and cost-efficient solution. To Shah’s point, customers will be examining new architectures to optimize the collection, storage, and use of data.

This brings us to BTG Pactual. In June, the Brazilian bank made a splash by publicly stating it was using technology from startup Imply to modernize its data architecture. BTG Pactual said it was using Imply’s Lumi to query historical telemetry stored in a low-cost data lake, while also improving efficiencies with Splunk.

Contrary to some reports, BTG Pactual did not replace Splunk, according to my sources. Instead, it modernized the architecture beneath existing workflows by using Imply Lumi to access historical telemetry stored in low-cost object storage.

The result was expanded retention, improved scalability, lower software costs, and preservation of analyst workflows, say these sources. The significance lies less in cost savings than in demonstrating that investigation and detection in the AI age have become distinct workloads requiring different infrastructure.

This was a huge win for Imply, which demonstrates a modern architecture optimized for AI-scale security analytics. Rather than replacing analyst workflows, Imply decouples storage and compute to enable faster investigations, greater retention, and improved economics.

I highlight Imply here primarily to show how the SIEM market is rich for upheaval. This is a different competitive threat to Splunk than simply “Elastic is better” or “Sentinel is cheaper.” BTG said they want to keep using Splunk, but they want more effective workflows that can store data in other places.

Of course, there are many other vendors looking to tap into this vein of data-store capabilities. In addition to the Splunk competitors mentioned above, there are other startups, such as Observe and Hydrolix, that are focused on high-volume data analytics with storage for logs, metrics, and objects.

Cisco Execs Eye Splunk’s Upside

What does this mean for Splunk? Splunk still holds the advantage of its installed base, even though customers are looking to offload data storage costs. Cisco has an opportunity to further integrate the product set with its vast resources and huge installed based in cybersecurity and networking.

Splunk may well represent the next upside for Robbins and Patel in their quest to reinvent and expand the company. Cisco has recently been on a roll, with significant gains in networking and AI infrastructure revenue. If Cisco’s product maestro Patel can guide Splunk to its AI era, Cisco will have a considerable competitive position in a gigantic market in transition.

Disclosure: Futuriom provides paid research and marketing services to technology companies, with the goal of providing accurate and objective insight into how cloud and AI infrastructure markets are evolving. These services include subscription research, custom research, and report sponsorships. In the past twelve months, some of the companies mentioned in this article have purchased research services from Futuriom, including Cisco and Stellar Cyber. As a policy, the author holds no positions in individual technology stocks covered in articles.