In this briefing
- 01Delivery objects diverge from model endpoints into systems, services and operational components
- 02Available systems and future functions still need separate status labels
- 03Portable scope in isolated networks has explicit boundaries
- 04Cost, performance and auditability still lack a common basis
- →What to watch next
- ↗Sources and verification
- Cisco AI POD for Splunk is available for Splunk AI workloads. Splunk AI Assistant is currently available; Agent Launchpad and NVIDIA Nemotron support remain future plans.
- On 15 September, Cirrascale announced that Inference Platform had entered production release and was available in its US and international regions. Multi-accelerator routing, throughput and cost advantages remain vendor claims without an independent benchmark under matched conditions.
- Corelight has released Agent Builder Library and Natural Language Query. Corelight explicitly says the Library’s documented investigation logic can be imported into private LLM and SOAR environments, including air-gapped networks without cloud connectivity. That does not establish that the complete query or Agent products can run offline.
Delivery objects diverge from model endpoints into systems, services and operational components
On 15 September, Cisco announced that Cisco AI POD for Splunk was available that day for self-managed Splunk Enterprise AI workloads in on-premises datacentres, private clouds and air-gapped environments. Splunk’s product page describes it as a pre-configured, pre-validated dedicated system combining AI Tier, Cisco UCS, NVIDIA RTX PRO 6000, Cisco networking, OpenShift and Splunk Operator for Kubernetes. It also offers a software route for installing AI Tier on qualified customer hardware. The system is not a general-purpose GPU appliance.
On the same day, Cirrascale announced that Inference Platform had entered production release and said it was now available in US and international regions. The vendor puts open models, private models, connections to private knowledge bases, model routing, team usage controls and Agent constraints into a managed inference service. Corelight’s Agent Builder Library is a different form of delivery: documented network-investigation playbooks, field explanations and decision trees that can be exported into a customer’s own Agent, SOAR or private LLM environment, including air-gapped networks without cloud connectivity.
These three releases show that what an enterprise receives is not always a model API. A pre-validated system, managed service and portable logic carry different responsibilities for deployment, updates, support and audit; the verifiable scope also changes with conditions such as existing hardware, network isolation or proprietary knowledge sources. The three companies’ materials provide no common interface, interoperability test or unified delivery standard, so they cannot be described as one combined solution.
Available systems and future functions still need separate status labels
Cisco’s availability statement applies to AI POD for Splunk and the released Splunk AI Assistant. Agent Launchpad is marked for later this year, while NVIDIA Nemotron model support is planned for the coming months. Splunk’s product page says AI Tier software has no incremental fee, but that does not make the complete hardware, integration and ongoing service free. Customers remain responsible for datacentre location, connectivity, security controls and routine operations; final system specifications must be determined against the workload.
Cirrascale’s 15 September announcement says the platform has reached production release, but another official product page still said “currently released for preview” when checked for this article. That page also lists monthly cloud-server instance prices, expressly billed by server; they cannot be treated as the new inference platform’s token prices. Corelight said on the same day that Agent Builder Library and Natural Language Query had both been released, but its announcement gives no licence price for the exportable Library or offline-deployment inventory for the complete product.
“Platform production release”, “a particular function currently available”, “future model support” and “an older page still showing preview” are distinct status records. The public material establishes what each vendor announced and when, while exposing documentation that is not yet aligned. Delivery scope, pricing and specific deployment conditions still depend on formal contracts, versioned technical documents and validation in a customer environment. A single availability label cannot cover every function on the same page.
Portable scope in isolated networks has explicit boundaries
Cisco describes on-premises, private-cloud and air-gapped use for AI POD. Splunk’s product page also says AI POD is dedicated to Splunk AI workloads and that the customer retains responsibility for datacentre and security operations. This defines a local delivery route; it does not prove that all Splunk cloud observability functions, third-party models or the future Agent Launchpad are available in the same way while completely disconnected from the network.
Corelight’s descriptions “deterministic” and “exportable” apply only to the documented investigation logic in Agent Builder Library. LLM generated outputs are not covered by those descriptions. For Natural Language Query, sub-Agents separately construct, validate and execute an editable LogScale query; the official announcement does not say that the whole query chain or Agentic Triage can be deployed offline in an isolated network. Cirrascale says that private data does not leave the customer environment during fine-tuning, while also describing the new platform as a managed service across regions. The two statements do not automatically amount to operation without external network connectivity.
Private operation can mean a complete system in a customer datacentre, a regional service connected to customer data, or only a portable operational component. Offline operation or data control has a complete meaning only when paths for model weights, the control plane, logs, updates, external calls and support access are all specified. The current announcements do not provide end-to-end tests of the three forms under the same isolation conditions.
Cost, performance and auditability still lack a common basis
On the same day, Cisco announced Tokenomics for Splunk Agent Observability, saying it can attribute Agent token spending and employees’ consumption of coding tools including Claude Code, Codex and Cursor; predicted consumption is listed as a future capability. A SiliconANGLE interview independently confirmed the scope of Splunk’s local-system and observability releases but provided no test of cost-attribution accuracy or system performance. Splunk’s product page also gives no public price for the complete AI POD or fixed model throughput, instead requiring sizing against the workload.
Cirrascale says the platform can choose where models run among NVIDIA, AMD, Qualcomm and Tenstorrent accelerators and improve token output per unit of GPU cost. Its announcement does not disclose quantisation format, context, batch size, first-token latency, throughput, concurrency or a price table under matched conditions. Corelight links investigation verdicts to specific playbooks, behavioural signals and network evidence, but the same page gives no independent error rate, offline-import test or licence basis. Cost attribution, an inference service and investigation evidence are different results; they cannot be merged into a performance ranking.
These products place cost observation, model execution and investigation logic into different deliverable forms, showing that acceptance in private environments extends beyond whether an endpoint answers. Vendor demonstrations and product descriptions can define functions and conditions that remain to be tested, but cannot prove cost savings, accuracy or compliance in a real business setting. In particular, workloads and suppliers lack common test conditions, so the current evidence does not support a cross-supplier efficiency conclusion.
What to watch next
- Whether Cisco publishes AI POD for Splunk configurations, complete-system pricing and performance conditions for matched workloads, as well as actual availability dates for Agent Launchpad and Nemotron support.
- When Cirrascale aligns the product page that still says preview with its production-release announcement and publishes platform pricing, routing test conditions, latency, throughput and formal compliance status.
- Whether Corelight specifies the Library’s licensing and offline-import scope and independently validates the precise dependencies of Natural Language Query and Agentic Triage in disconnected environments.
Sources and verification
Golden Data has edited this briefing from the public materials listed above. The original sources govern facts and figures. The enterprise relevance sections are Golden Data editorial analysis and do not constitute an endorsement of any third-party product.
← Back to AI Daily Briefing