Cisco Data Fabric, powered by Splunk, was a hot topic at Cisco Live. While at the conference, I had a chance to chat with Chris Crocco about what Cisco Data Fabric is, what it isn’t, and how it is fundamentally shifting the way Splunk accesses and uses data. Chris explains the platform, Machine Data Lake, and Federated Search. Cisco Data Fabric is being utilized across the Cisco portfolio, and the Native Splunk integration in Cisco Nexus One is a great example. Cisco Data Fabric opens up so man
Transcript
Auto-generated captions, lightly cleaned. Speakers are not separately labeled.
Hey everybody, we’re out here at Cisco Live and I ran into Chris here and Cisco Data Fabric. It’s a hot topic at the conference. >> It is. >> What is it and what does it do? >> So, I’m going to first answer that with what it isn’t. So, Cisco Data Fabric is not a product. It is not the new name for Splunk. It’s an architecture. And really what that means is we’re bringing the capability set of Splunk to the rest of the Cisco portfolio and expanding that capability set to leverage more value from where customers are and what they need to do with their modern environments. So it’s going to be three key components. So the first one is obviously the core platform. Uh but you’re also going to have the machine data lake which is going to be a highly compressed cost-effective data store for that nebulously valued to low value data. You may not necessarily need to search or operate against that every day, but you do need to keep it for compliance reasons or maybe something that you need to pull for threat hunting later. Um, and you need it quickly referenceable and and retrievable in that Splunk environment. The other component is going to be federated search. So, we’ve had federated search in Splunk for a while, and this is us really expanding that into the larger Cisco portfolio so that you’re going to be able to federate not only across your Splunk environments um and across your long-term data stores, uh but across other parts of the Cisco portfolio as well. So, a great example is there’s now Splunk native in Nexus dashboard. Well, if we need to pull that Nexus information into your Splunk environment, but not necessarily reindex it, the new federated search capabilities of the data fabric architecture are going to give us the capability to do that. So, a lot more malleability, a lot more capability uh to meet you where you are for your data needs and extract value and outcomes. >> Sounds like there’s a a lot of options now for the Splunk user on how do I get data to the right place? >> Where does it make sense to land? And we’re giving you all those options and tools and levers. Is that right? >> It is. Yeah. So, we’re going to give you a lot of options from the ingest layer. So determine what needs to go where, what you may need to extract, um, enrich, route, uh, based on that operational relevance that we talked about before. So high operational relevance, low operational relevance or nebulous. Um, we’re going to help you make that deterministic routing. We’re also going to give you those store locations in a much uh, better and cost-effective way than Splunk has ever done before. Uh and then we’re also going to give you that opportunity to reach outside of the Splunk and Cisco ecosystem and ex extract that value uh in a way that again we have never done as a company both either Cisco or Splunk. >> So this is like kind of a fundamental shift of how Splunk has worked in the past to how we’re getting access to data today. Is that right? >> Absolutely. Yeah. You’re going to see Splunk be a very different animal than it has been in the past. Uh we’re meeting our customers where they are. we’re meeting the modern data needs of you know not only human beings but the agentic uh demand that is coming whether we wanted to or not. Um so we’re going to meet the market where it is and help plan for the future where we know uh data and insights need to come from. >> Now if I want to go educate myself some more about all of these capabilities and such data fabric what would you suggest? >> So a couple of different places. So obviously cisco.com is going to have a great data fabric uh component to it. Um all of the sessions from here at cisco live should be available for replay soon. Uh and then voc.splunk.com is a great place to sign up to get your hands dirty with some of the private previews of the newest, latest, greatest features. >> That sounds really incredible. Really appreciate your time. Yeah, thank you.