The volume of data flowing across modern infrastructure is overwhelming (some at Splunk .Conf might even call it… ludicrous). At the same time, the threat landscape is evolving faster than ever. Security teams are expected to keep up with both, making sense of mountains of logs while defending against increasingly sophisticated attacks. At .conf25, the flagship conference for all things security observability centered around Splunk, Dan Wendlandt (Co-founder & VP of Isovalent @ Cisco) outlined how Isovalent and Splunk bring out the best in each other to help SecOps teams fight evolving threats and the ludicrous amounts of data being generated. Isovalent Runtime Security brings deep visibility and real-time enforcement by instrumenting infrastructure at the kernel level. Splunk steps in as the brain, providing the intelligence to analyze, correlate, and act on what matters most. Together, Splunk and Isovalent deliver the leading unified solution for integrated security and observability, which was front and center at this year’s Splunk .conf. Isovalent software is magical and transformative. Tom Gillis, SVP and General Manager, Infrastructure & Security, Cisco This isn’t quite as magical as discovering alchemy, but it does feel that way compared to legacy security. Isovalent surfaces only what matters from the kernel, stripping away noise and surfacing the critical context for Splunk to analyze. The result: less noise, faster response, and actionable insight at a scale that simply wasn’t possible before. What does distributed, granular security look like in practice? Imagine if you could break security into a million pieces, a million tiny... well, I won’t call them firewalls, but distributed controls that you can put everywhere. Every application, every service, every web server, every Kubernetes cluster gets its own little perimeter. Applications aren’t just in the data center anymore, they’re everywhere: the robot bartender, the hospital blood analyzer, more very sophisticated applications. The network is the perfect place to observe and enforce controls. Tom Gillis, SVP and General Manager, Infrastructure & Security, Cisco As Tom explains, security is no longer a monolithic boundary. Instead, controls are embedded everywhere, at every process, container, and service. Security teams can set precise policies that move with workloads, no matter where they are scheduled or what network they traverse. Every application gets its own ‘perimeter’. Every connection is visible and auditable. With Isovalent, our platform provides SecOps teams the tooling to observe every process, every network packet, and every event as it happens. The expertise from building Cilium and Tetragon abstracts out the value of eBPF, and brings granular insight into what is actually running, what files are being touched, and what connections are being made. Isovalent makes it possible to enforce security policies in real time, right down to the process or container level. It’s 2025, we’re no longer managing individual Linux boxes or desktops manually. We are managing fleets of servers, Kubernetes clusters, containers, AI workloads getting scheduled everywhere. But the technology we have to connect, secure, and observe those workloads are still those legacy Linux technology. eBPF lets us change all that and drive a lot of innovation in the Linux kernel. Dan Wendlandt, Co-founder & VP of Isovalent @ Cisco At the heart of modern security is eBPF. This revolutionary technology allows for deep, programmable visibility and control right inside the Linux kernel, without performance trade-offs or risk to system stability. As Brendan Gregg (Intel Fellow and leading kernel expert) puts it, eBPF gives us superpowers for Linux security, networking, and observability. It lets us teach an old dog (the Linux kernel) new tricks without crashing or slowing down the kernel. eBPF programs run safely inside the kernel, letting us observe every process, syscall, network packet, and policy event on the host. This means Isovalent can enforce security right where it matters; at the point of execution, not a hop away in a SIEM or a network tap. The result: teams get precise, actionable data, and attacks are intercepted at the source, not after the fact. Our customers think of Isovalent’s runtime security as the “eyes and hands” that see and enforce runtime policies, working in conjunction with Splunk’s analysis muscle. Security and ops teams finally share a single source of truth, closing the gap between “it’s the network” and “it’s the app.” That same telemetry, information about what processes are executing, whether there have been drops, and so on, also helps us monitor the health and connectivity of an application. We can look at L2, L3, L4 and even L7 tracing to monitor application health and assist with troubleshooting. Dan Wendlandt, Co-founder & VP of Isovalent @ Cisco How do Isovalent and Splunk streamline threat detection and response? Even our first customers were naturally using Isovalent and Splunk together. This isn't because we’re now part of Cisco, it’s just a natural "better together." Dan Wendlandt, Co-founder & VP of Isovalent @ Cisco Isovalent provides the granular data and enforcement. Splunk makes sense of it all at scale. Instead of flooding teams with log data, Splunk’s analytics engine highlights what’s actionable to minimize alert fatigue and accelerate investigations. The network is the perfect place to observe and initiate those controls, so with this distributed system, we have extremely precise fine-grained resolution. Tom Gillis, SVP and General Manager, Infrastructure & Security, Cisco Splunk's strength lies in the ability to sift through enormous data volumes, surface real threats, and provide actionable intelligence to security and operations teams. This is an important feedback loop and workflow for building new policies or responding to threats. When something security significant is surfaced, Splunk can trigger an automated response to close the loop between detection to enforcement. If you take this eyes-hands-brain analogy further, you can imagine all kinds of things. If the brain sees something suspicious, what does your body do? It focuses on that. Splunk might collect a lot more telemetry just in case it needs it for an investigation, or maybe Splunk has learned of a vulnerability. We might then push out an eBPF control. That combination, all working together as one system, is incredibly powerful. Dan Wendlandt, Co-founder & VP of Isovalent @ Cisco What happens when a critical threat is detected? See the demo Over the years of helping teams better understand and defend their environments, Isovalent and Splunk have naturally come together. See a demo from Katie Brown, Director of Platform Security at Splunk, showcasing coming together to protect critical AI infrastructure from zero-day vulnerability. Splunk acts as the system’s intelligence layer, ingesting high-value telemetry from Isovalent, correlating events across infrastructure, and applying advanced detection logic to surface real threats. Fortunately, we’d just set up Isovalent with smart data onboarding. The templates we have equipped with Isovalent Runtime Security means we only are gathering the logs that we care about. Katie Brown, Director of Platform Security, Splunk Why do SecOps and Infrastructure teams choose Isovalent + Splunk? SecOps and Infrastructure teams choose Isovalent for advanced cloud-native networking, security, and observability in Kubernetes and Linux workloads, and Splunk for its comprehensive data ingestion, analysis, and security operations capabilities. Together, they provide deep visibility and control over dynamic cloud-native applications and infrastructure, enhancing both security posture and operational efficiency. The deep control and visibility through eBPF represents a fundamental leap forward for security use cases. By distributing security logic to workloads, eBPF enables fleet-wide granular policy enforcement and real-time threat detection based on process behavior and network flows. I think what’s exciting is that this isn’t just an incremental improvement, it’s a whole new architecture, not just for security, but for how we manage and use data overall. Tom Gillis, SVP and General Manager, Infrastructure & Security, Cisco This combined approach is a fundamental leap forward. Real-time enforcement at the kernel level. High-fidelity data for detection and investigation. Automated, closed-loop responses. This model means faster detection and response cycles. Security teams no longer wait for manual intervention or chase after endless false positives. The operational overhead drops, removing constant “needle in a haystack” log searches. Kernel-level enforcement and edge intelligence provide true scalability, without the need for massive data ingestion or performance penalties. The end result is a stronger security posture, better compliance, and peace of mind for organizations managing complex, distributed environments. Notably, a core part of eBPF is the safety mechanisms in place to guarantee the workload will never crash or hang. Ready to try Isovalent Runtime Security with Splunk? The combination of Isovalent and Splunk delivers end-to-end, intelligent, and actionable security and observability. Shift your team from reactive to proactive, bringing the insights and control needed to face today's highly scaled challenges. Explore the new hands-on Splunk <> Isovalent lab or demo video, or reach out and we are happy to walk through any question or use cases.