Splunk’s agentic observability push raises a bigger security question

Splunk’s March Observability Cloud release is no longer new, but it is still a useful signal of where observability is heading. The important story is not that Splunk added another feature. It is that production telemetry is being opened up to AI assistants, IDEs, chatbots and internal LLMs, and that raises a governance question that enterprises can’t ignore.

Splunk’s MCP server lets engineers interact with observability data from tools such as VS Code, Cursor, Windsurf, IntelliJ, Claude, ChatGPT and homegrown LLMs. According to Splunk, it supports natural-language queries, automated workflows, secure JWT-based authentication, role-based access control and agentic workflows.

That is powerful because observability has traditionally required engineers to know where to look, which dashboard to open and how to interpret metrics, traces, logs and alerts. With MCP, Splunk is moving telemetry closer to the places where developers and SREs already investigate problems.

But the same shift also changes the risk model. 

Observability data can expose infrastructure patterns, service dependencies, error traces, customer-impact signals and operational weaknesses. When that data becomes accessible through more interfaces, the security conversation has to move beyond productivity.

Agentic observability needs agentic governance

Splunk’s Real User Monitoring (RUM) AI Assistant shows the upside. 

Engineers can use natural-language prompts to investigate application performance, isolate crashes and monitor user sessions, including questions about cold-start times, top crashes, stack traces, affected devices and page latency metrics.

The operational value is clear: faster investigation, less context switching and a shorter path from symptom to root cause. But enterprises need to decide who can ask which questions, what data an assistant can retrieve, how prompts and responses are logged, and whether AI-generated recommendations should trigger automated actions.

Cisco’s wider agentic AI security pitch reinforces that point. In March, Cisco said 85% of major enterprise customers were experimenting with AI agents, but only 5% had moved them into production. It also argued that agentic systems need trusted identities, Zero Trust access controls, MCP policy enforcement and machine-speed detection.

Splunk’s own CISO research shows why the market is interested but cautious. Its survey found that 40% of CISOs use generative AI in security functions and 39% are exploring agentic AI, while 83% cited hallucination impacts as their top concern for agentic AI.

Source: The CISO Report 2026

That makes platform trust central. As we recently noted in our coverage of Splunk’s high-severity RCE patches, Splunk environments are sensitive operational assets. Agentic observability may help teams move faster, but only if access, identity, auditability and human oversight move just as quickly.

You might also be interested

Kihara Kimachia
Kihara Kimachia

Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.