The cost of running AI agents became the organizing theme of this two-week window. Splunk launched Tokenomics at .conf26 to track what agents spend, Datadog's CEO described a pricing model built around AI credits, and Dash0 shipped a dashboard for coding-agent costs. Around them, Coralogix earned FedRAMP Moderate certification, while Elastic, Riverbed, and Honeycomb each shipped smaller updates.
Splunk Turns .conf26 Into a Cost-of-AI Story
On September 15 at .conf26 in Denver, Cisco announced Splunk Agent Observability with a new Tokenomics capability that tracks AI spend and coding-agent usage in real time. According to SiliconANGLE's keynote coverage, agent token consumption passed human consumption in February 2026 and now runs at roughly five times the human level. A keynote demo showed frontier-model evaluators replaced by small language model guardrails, cutting evaluation cost from about $1,000 a day to a few dollars at sub-350-millisecond latency. Cisco President and Chief Product Officer Jeetu Patel named deployment difficulty as one of the biggest barriers to enterprise AI, which explains why so much of the announcement focused on packaging.
The packaging came in three parts. Cisco AI POD for Splunk bundles AI runtime software, Cisco infrastructure, NVIDIA accelerated computing, and Kubernetes as a pre-validated stack, so regulated customers can run Splunk AI models on premises. Splunk and AWS formalized a multi-year agreement for joint product development around the agentic SOC. Cisco Data Fabric, outlined as a strategy in Update #1, was shown with a Machine Data Lake and expanded Federated Search; a demo joined Splunk operational data with Snowflake business data without copying it, and SiliconANGLE reports the federation now reaches AWS CloudWatch and Databricks. Splunk's SVP of security also previewed an integration, due by year-end, that lets customers running both Splunk Observability and Enterprise Security join datasets while keeping separate budgets and teams.
Tokenomics is the clearest sign yet that AI spend is becoming a telemetry category of its own. Token counts, cost per task, and retry rates sit naturally beside latency and error rates, and vendors that already hold the observability data have a strong claim to the cost view.
Datadog Puts Numbers on the AI Shift
Datadog CEO Olivier Pomel spoke at Citi's Global TMT Conference on September 8, and the transcript coverage contains figures the quarterly release did not. Customers outside the AI-native group are growing in the high 20s percent range, up from about 18% a year ago, which addresses the question of whether the 36% quarterly growth reported in Update #4 depends on a handful of AI labs. The AI-native customer base has grown to roughly 750 from fewer than 100 about two years ago, and gross retention stays in the high 90s. Pomel put annual product development spending at about 30% of revenue, roughly $1 billion, and described security products at around $100 million in annual recurring revenue used by about a quarter of customers.
The pricing remark matters most. Datadog is moving from data-volume pricing toward an AI credits model that bundles hosts, logs, APM, security, and AI services flexibly. Splunk is metering token spend while Datadog reprices around AI credits, so two of the largest incumbents are adjusting their commercial models to the same shift within one week. The figures come from spoken conference remarks and carry the usual caveats of that format.
Coralogix Earns FedRAMP Moderate
On September 9, Coralogix announced that Coralogix U.S. GovOps is FedRAMP certified at Class C (Moderate). Federal Student Aid, an office of the U.S. Department of Education, already runs workloads on the offering under an Authorization to Operate. The release ties the certification to OMB Memorandum M-26-14, which sets federal requirements for continuous event monitoring and for threat hunting, investigation, response, and forensics, and requires retained logs to stay actively searchable for six months and retrievable for a year across every system an agency owns or runs through a provider. CEO Ariel Assaraf framed the agency problem as paying to store data that cannot be searched when it matters.
That framing connects to the cost theme above: a retention mandate turns log economics into a compliance question. It also adds a finished certification to a segment that Update #2 described as a race, where Dynatrace and New Relic had announced FedRAMP High commitments, a level that typically takes 12 to 18 months.
Shipping Notes: Dash0, Elastic, Riverbed, Honeycomb
Dash0 shipped a cluster of updates on September 14 that extends the Agent0 platform from Update #4 and the Polar Signals acquisition from Update #5. AI SDLC Insights, the renamed and expanded AI Coding Insights, shows coding-agent spend, adoption by team, cycle time, the share of AI-assisted pull requests, and where those pull requests stall across coding, review, and merge. The same-day changelog adds model selection per Agent0 investigation and a GitHub Action that keeps dashboards and check rules in sync from a repository. Custom skills for Agent0 arrived on September 9 and Service Level Objectives on September 15. Agent cost visibility is the same theme Splunk chose for its headline launch.
On September 17, Elastic made cross-project search generally available for Elastic Cloud Serverless. Teams link projects in the Cloud UI in a few clicks, with authentication handled at the organization level and no certificates or per-cluster connections. Up to 100 linked projects are supported by default across Search, Observability, Security, and Vector Database workloads, with higher limits on request. Data stays in place, which suits customers with regional or compliance boundaries.
On September 16, Riverbed launched NPM 360, building Riverbed IQ and the conversational assistant Riverbed Q into AppResponse and NetProfiler and adding NPM+ endpoint visibility. It is initially offered at no premium to current AppResponse and NetProfiler pricing, a notable choice while many vendors sell AI features as add-ons.
Honeycomb published two pieces. On September 9, Charity Majors completed the series with AI Norms & Values, Part 3, covering individual ownership of work, rising quality standards, and the company's position on energy use, intellectual property, bias, and wages. On September 14, a guide from Jodi Sloan described Canvas as the workspace for an agent development feedback loop, from OpenTelemetry instrumentation to validating fixes with production data.
Quiet Corners and What Comes Next
Grafana Labs shipped only a 13.2.2 patch release, and Observe Inc and Chronosphere produced no standalone news, which continues the integration silence after their acquisitions by Snowflake and Palo Alto Networks. Cribl published a post on managing multiple environments with Cribl as Code on September 17, ahead of CriblCon 26 in Chicago on September 29 and 30, where the next round of platform announcements is expected. Dynatrace's $915M Arize AI acquisition, announced on August 13, was expected to close, in the company's words, later this quarter or early in its third quarter, subject to regulatory review, so a closing announcement is the next item to watch. The Q3 2026 quarterly report, built on these thirteen weeks of data, follows in October.