Image: blogs.cisco.com · rights & removal
Admin in the Loop: Firewalls and the Agentic SOC
Reporting by Cisco Security BlogRead the original at blogs.cisco.com
Executive Summary
Facts Only
* The live SOC protected over 5,145 attendees from 70 countries at Splunk .conf26 in Denver.
* The SOC operated on a multi-stage agentic pipeline: Live telemetry feeds Splunk Enterprise Security; autonomous triage agents accelerate Tier 1 analysis; Cisco Cloud Control enforces confidence gates; human analysts make response calls.
* Firewalls delivered wire-speed Snort 3 detection and Encrypted Visibility Engine telemetry with zero impact on production traffic.
* Network Operations Center managed the venue network, providing SPAN feeds to SOC firewalls.
* Cisco Cloud Control unified on-premises and Cloud-Delivered Firewall Management Center (FMC) deployments.
* Unified Events in Cisco Cloud Control unified firewall telemetry, connection events, domain filtering data, TLS policies, Intrusion events from Snort 3, file events, and malware verdicts directly to the flow.
* Structured telemetry was streamed directly into Splunk Enterprise Security in JSON format using Advanced Logging.
* Splunk ES combined firewall signals with endpoint, identity, and cloud telemetry to assemble incident narratives for autonomous agents.
* AgenticOps applied AI intelligence to firewall management by analyzing rule hit counts and optimizing policy evaluation order.
* AI Canvas is a shared workspace for human operators and AI agents to collaborate on incident resolution and situational best practices.
Full Take
From the original · Cisco Security Blog
At Splunk .conf26 in Denver, our team operated the live Security Operations Center (SOC) protecting more than 5,145 attendees representing 70 countries, including all attending Splunkers. We monitored multi-gigabit traffic while defending live capture the flag attack simulations and dynamic demo environments running throughout the venue.Read the full story at blogs.cisco.com
Sentinel — Human
This text reads like a highly technical, internally focused blog post or conference summary where deep operational experience informs an architectural argument about unifying network security and AI orchestration.
