At Splunk, we are innovating with AI in our products as well as using our products to maximize your AI investments. While at Cisco Live, I had an opportunity to chat with Aqib Kazi about how Splunk Observability Cloud is using AI to take troubleshooting down from hours to minutes. We also had a quick chat about the Splunk MCP server and how using an MCP client can help aide in your workflows.
Transcript
Auto-generated captions, lightly cleaned. Speakers are not separately labeled.
Hey everybody, we’re out here at Cisco Live AMIA and I ran into AK here and we’ve been talking about Splunk observability cloud and Agentic AI and MCP servers and how all those things tie together and make your life easier. Can you give us some more information about that? >> Absolutely. I mean the Agentic AI that we have, it takes your troubleshooting basically down from hours down to minutes. As soon as you click that critical alert, you’re able to go in and quickly see the initial root cause analysis and then it’ll go through and tell you everything it traced and everything it looked at as well too. what logs are it looked at, what tags are it looked at, all the associated metadata and then based on that you can chat more with the AI assistant and you can look at the specific trace where it’s found that specific issue as well. >> Yeah. So it’s kind of doing some of that front end triage for you is finding something unusual telling you some more information without you having to go and search yourself. Is that right? >> Absolutely. I mean you’re taking that troubleshooting down from hours down to minutes. You’re really reducing that troubleshooting time and really telling you pinpointing where it is further. And a lot of times that initial root cause analysis is exactly what you’re looking for. But then if you have additional questions, you can take that context and chat with the AI assistant some more as well. >> So as an analyst, I got that front-end triage. I’m able to chat with the AI assistant and get that root cause analysis faster, respond faster, remediate faster. Is that accurate? >> Exactly. Yeah. It’s all about going faster with AI. We’re able to take the issue back down to remediation very quickly. >> Awesome. And then where are we using the MCP server and all of this? >> Yeah. So the MCP server connects over to Splunk core to our Splunk cloud instance and that’s that connection into Splunk cloud cloud to be able to pull additional information based on the logs that are available there. So we could be pulling thousand eyes logs for instance and then looking at our current alerts or current issues and then based on that I may want to see what devices are impacted. So I may look at my Moroi logs, my SDWAN logs and be able to run specific searches based on that and use Claude in this case as our LLM to be able to extract all that information for us. >> And again, we’re taking troubleshooting down from hours to minutes. Really getting to root cause much much quicker. >> That’s really great. It sounds like we’re doing a lot of innovation there. Where can I go learn some more if I want to? >> Yeah, splunk.com. You have a lot of different uh help tools there, but a lot of information available today on splunk.com. Great. Thanks so much for your time. Appreciate it, man. >> Thank you.