Cisco expands Splunk Agent Observability with token tracking
Cisco announced expanded Splunk Agent Observability on September 15, 2026, at its .conf26 conference, adding monitoring for AI stack components including GPUs, vector databases, memory systems, and orchestration frameworks Cisco.
The expansion introduces Tokenomics, a new capability within Splunk Agent Observability that tracks AI token spending and coding agent usage in real time and forecasts consumption before billing periods end NetworkWorld. Cisco's official materials describe the feature as enabling organizations to "trace AI spending and coding agent usage in real time" and "project where spend is headed before a billing period ends" Splunk Blog.
Deployment and availability
The Tokenomics feature is available in Splunk Observability Cloud and Cisco Cloud Control. Cisco also expanded Splunk Agent Observability as an on-premises offering, extending the platform beyond cloud-only deployments to serve enterprises requiring local infrastructure control Cisco.
Monitoring scope and use case
The expanded observability platform monitors the full AI stack, moving beyond traditional application performance monitoring to capture components critical to agentic systems. Tracking GPU utilization, vector database performance, memory consumption, and orchestration framework behavior addresses a specific gap: enterprises deploying coding agents and autonomous AI workflows need visibility into infrastructure costs before unexpected bills arrive.
Tokenomics forecasting is built directly into the observability pipeline, allowing operations teams to model consumption trajectories and adjust resource allocation or agent workloads preemptively. This positions cost management as a core observability function rather than an after-the-fact billing surprise.
Market context
The announcement reflects growing demand for AI agent governance across enterprise deployments. As organizations scale coding agents and autonomous workflows, token consumption—measured in input and output tokens processed by large language models—has become a significant operational expense. Organizations running multiple agents across teams face compounding costs without real-time visibility.
Cisco's move to add on-premises deployment options for Splunk Agent Observability signals enterprise preference for hybrid or fully local AI infrastructure, particularly for cost-sensitive or security-regulated workloads. The timing at .conf26, Splunk's annual observability conference, positioned the announcement at a venue focused on operational governance at scale.