Visibility gaps in automated networks
The integration between ThousandEyes and Splunk RUM attempts to make ThousandEyes network metrics visible on Splunk Observability Cloud. Teams use this to determine if problems relate to the application or the network. It helps to pinpoint the root cause of high end-user response times by correlating them with ThousandEyes network metrics. However, the 2026 network outage data shows that failures increasingly stem from how autonomous systems interact. ThousandEyes tracked up to 386 global network outage events per week in the first quarter of 2026. During the last week of February, outages hit 386, a 62% jump from the 239 incidents seen the week before. The Cloudflare BYOIP incident on February 20 shows how automation can create failures when a bug in an internal maintenance task causes a system to withdraw IP address advertisements. I see these interaction failures as a primary risk for companies relying on automated observability. When a user reaches an ingestion limit, Splunk Observability Cloud stops ingesting ThousandEyes data. This makes the "Sync tests" option unavailable. Users can view correlated browser or mobile RUM application performance and network metrics directly within the Splunk RUM UI.
| Metric | ThousandEyes test |
|---|---|
| network.loss | Agent-to-server, HTTP server, page load, and transaction |
| network.latency | Agent-to-server, HTTP server, page load, and transaction |
| network.jitter | Agent-to-server, HTTP server, page load, and transaction |
| dns.lookup.duration | DNS server, DNS trace |
Pricing and roadmap uncertainty
The $28 billion Cisco acquisition of Splunk causes many teams to re-evaluate their long-term strategy. Procurement groups face ambiguity regarding the product roadmap as Cisco aligns Splunk with its broader portfolio. Many users report that the licensing model becomes expensive as data volumes increase. At 500GB per day, annual costs exceed $788,000. Small deployments of 1 to 10GB per day cost between $1,800 and $18,000 per year. Splunk also requires a separate license for SOAR on top of the base SIEM contract. I observe that the platform presents a steep learning curve. Teams often require training or experienced personnel to manage the environment effectively. Dashboard customization requires significant time. Users report that the platform requires too much expertise to be useful. Cisco now offers Enterprise Security Essentials for teams that want analysts to make the final call, and Enterprise Security Premier for customers ready for more autonomous defense. The centerpiece is the Cisco Data Fabric, which combines a machine data lake, catalog, universal collector, and real-time ingest processing. Users federate and correlate across Splunk, cloud object stores, and data lakes like Snowflake or Databricks using this fabric. I wonder if the move to a unified platform under Cisco will truly lower costs or simply change the billing line.
Misidentifying system interaction failures
The convergence of security and observability creates a major diagnostic problem. A security signal often mimics an application performance issue when an agent follows a bad instruction or responds to a poisoned prompt. These three scenarios look alike. When an agent honors an expired discount at a rate pegged near half a million dollars an hour, it throws no error while every signal reads healthy. This makes it hard for analysts to distinguish between a breach and a system misbehavior. The 2026 outage data from ThousandEyes shows that interaction failures between autonomous systems cause more disruptions than individual component breakdowns because autonomous agents make decisions in milliseconds without human intervention. I note that the proliferation of agents creates specific technical risks like optimization conflicts. A performance agent, a cost-reduction agent, and a reliability agent may work against each other simultaneously. The aggregate cost of unplanned downtime for Global 2000 companies reached $600 billion annually in 2026, a 50% increase in just two years. Human error contributes to 66% to 80% of all downtime incidents, often stemming from staff not following established procedures or using flawed processes. The average cost of downtime for organizations has reached $15,000 per minute.
