Cisco combines Secure Network Analytics with Splunk's security portfolio to detect network threats and automate investigation and response, positioning AI-assisted analytics as a core part of its network defense stack.
Cisco Secure Network Analytics, formerly Stealthwatch, is a network detection and response product that uses telemetry from network infrastructure and behavioral analytics to identify threats such as insider misuse, malware, and policy violations. Cisco acquired Splunk in 2024 for approximately 28 billion dollars, adding Splunk's security information and event management, observability, and data platform capabilities to its security and networking portfolio. Cisco has stated it is integrating Splunk's analytics with its own security products, including Secure Network Analytics and its XDR offerings, to broaden detection and automated response across network and log data.
Cisco is a publicly traded multinational technology company headquartered in San Jose, California, with fiscal year 2024 revenue of approximately 53.8 billion dollars across networking, security, collaboration, and observability segments. Splunk operates as a Cisco business unit following the 2024 close of the acquisition, continuing to sell its data platform, Splunk Enterprise Security, and Splunk SOAR alongside Cisco's own security portfolio, including Cisco XDR, which draws on Secure Network Analytics telemetry and Splunk data sources.
Documented from public materials · these are the products the AMS scores
Cisco Secure Network Analytics
Shipping since 2015
Formerly Cisco Stealthwatch, Secure Network Analytics ingests NetFlow and other telemetry from switches, routers, and firewalls to build behavioral baselines and detect anomalies such as lateral movement, data exfiltration, and encrypted traffic threats without requiring dedicated sensors on every segment. It integrates with Cisco Identity Services Engine and other Cisco security products for automated policy enforcement.
Cisco XDR
Shipping since 2023
Cisco XDR correlates telemetry across endpoints, network, cloud, and email, including data from Secure Network Analytics and Splunk, to prioritize incidents and automate response actions. Cisco has continued to add AI-based alert triage and guided investigation capabilities to XDR following the Splunk acquisition.
Splunk Enterprise Security and SOAR
Splunk Enterprise Security and SOAR
Splunk Enterprise Security provides security information and event management with correlation searches and risk-based alerting, while Splunk SOAR automates playbook-driven response. Cisco has stated it is connecting these products with its own network telemetry sources as part of a unified security analytics strategy following the 2024 acquisition close.
2024 - 2026 ·gold = a monetization move· grey = product or capital
Cisco completed its acquisition of Splunk for approximately 28 billion dollars, adding Splunk's SIEM, SOAR, and observability products to Cisco's security and networking business. Source: https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2024/m03/cisco-completes-acquisition-of-splunk.html
Cisco outlined plans to integrate Splunk data and analytics with Cisco XDR and its broader security portfolio, aiming to unify network, endpoint, and log-based detection under a single response workflow. Source: https://blogs.cisco.com/security/cisco-and-splunk-a-story-of-visibility-and-security
Cisco does not publish list pricing for Secure Network Analytics; the product is sold through Cisco's channel and direct sales teams, typically licensed by network flow volume or number of monitored devices as part of broader Cisco Secure or networking bundles. Pricing not public.
Splunk products, including Enterprise Security and SOAR, have historically been licensed by data ingest volume per day, with Splunk having introduced workload-based and consumption-based pricing tiers prior to the Cisco acquisition. Cisco has indicated it intends to maintain Splunk's existing licensing models in the near term while exploring longer-term integration with Cisco's own enterprise agreement structures. Public sources do not confirm a unified pricing meter across Secure Network Analytics and Splunk as of the cutoff date.
There is no publicly documented separate price meter specifically for AI or automation features within Secure Network Analytics or Splunk's AI Assistant; these capabilities appear to be bundled into existing product tiers rather than billed as a discrete add-on based on available public documentation.
Analyst layer · placement follows the documented capability above
Independence. Secure Network Analytics and Splunk's security products surface prioritized alerts and recommended actions, but security teams retain control over rule tuning, investigation, and response execution. Automated playbooks in Splunk SOAR can execute predefined actions, but human analysts typically approve high-impact responses, placing documented independence in the moderate range.
Job width. These products span an end-to-end security operations workflow within the security function, covering detection, alert correlation, investigation support, and in some cases automated response through SOAR playbooks. This work remains scoped to the security operations function rather than spanning multiple business functions, consistent with a moderate job width classification.
Output versus cost. Behavioral analytics and AI-assisted alert triage allow security teams to process larger volumes of network telemetry and log data than manual review would support, representing a meaningful efficiency gain. Public documentation does not support claims of order-of-magnitude cost reduction beyond typical SIEM and NDR efficiency gains, placing this in the inflecting range rather than exponential.
Monetization pattern. Cisco's documented pattern combines hardware and software bundling for Secure Network Analytics with Splunk's historical consumption-based data ingest licensing, sold through enterprise agreements and channel partners rather than public self-service pricing. Public sources as of the cutoff date do not show a distinct usage-based or outcome-based meter tied specifically to AI or automation features across either product line.
| Edition | AMS score | Metric on record | Change |
|---|---|---|---|
| Aug 2026 | M · M · Infl | Provisional AMS score calculated from public documentation, Aug 2026 | Baseline, first edition |
Future editions add a row whenever the score or the metric moves, with the evidence that moved it.
About this data
Everything on this page is a synthesis of public information: published reporting, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.