Skip to content

Image: blogs.cisco.com · rights & removal

Executive Summary

A live Security Operations Center was operated at the Splunk .conf26 event in Denver, protecting over 5,145 attendees from 70 countries. The SOC utilized an agentic pipeline involving live telemetry feeds to Splunk Enterprise Security, autonomous triage agents for Tier 1 analysis, Cisco Cloud Control for confidence gates, and human analysts for response. The firewall functioned as the initial signal engine, providing wire-speed Snort 3 detection and other telemetry without impacting production traffic. Network Operations Center (NOC) managed the venue network, supplying dedicated SPAN feeds to SOC firewalls. Cisco Cloud Control unified on-premises and cloud firewall management. Within this architecture, Unified Events correlated firewall telemetry, connection events, security events, and intrusion data with file events and malware verdicts. This provided rich context that allowed Splunk AI Triage Agents to move from atomic alerts to unified incident narratives. Furthermore, AgenticOps utilized AI to optimize firewall health by analyzing rule hit counts, reducing log volume before ingestion into the SIEM.

Facts Only

* The live SOC protected over 5,145 attendees from 70 countries at Splunk .conf26 in Denver.
* The SOC operated on a multi-stage agentic pipeline: Live telemetry feeds Splunk Enterprise Security; autonomous triage agents accelerate Tier 1 analysis; Cisco Cloud Control enforces confidence gates; human analysts make response calls.
* Firewalls delivered wire-speed Snort 3 detection and Encrypted Visibility Engine telemetry with zero impact on production traffic.
* Network Operations Center managed the venue network, providing SPAN feeds to SOC firewalls.
* Cisco Cloud Control unified on-premises and Cloud-Delivered Firewall Management Center (FMC) deployments.
* Unified Events in Cisco Cloud Control unified firewall telemetry, connection events, domain filtering data, TLS policies, Intrusion events from Snort 3, file events, and malware verdicts directly to the flow.
* Structured telemetry was streamed directly into Splunk Enterprise Security in JSON format using Advanced Logging.
* Splunk ES combined firewall signals with endpoint, identity, and cloud telemetry to assemble incident narratives for autonomous agents.
* AgenticOps applied AI intelligence to firewall management by analyzing rule hit counts and optimizing policy evaluation order.
* AI Canvas is a shared workspace for human operators and AI agents to collaborate on incident resolution and situational best practices.

Full Take

The narrative centers on shifting security operations from reactive alert chasing to proactive, context-driven orchestration facilitated by a unified agentic architecture rooted in the network layer. The innovation described moves beyond simply collecting data; it details an operational paradigm where the network infrastructure itself acts as a structured signal engine, feeding contextualized information into AI-driven workflows. The mechanism of transforming raw firewall logs into meaningful security context via Unified Events and EVE inspection, and then structuring that data for Splunk's consumption, establishes a crucial link between deep infrastructure visibility and high-level threat analysis. This creates an operational velocity where automation handles low-level correlation and optimization (AgenticOps), allowing human capacity to focus on complex decision-making within AI Canvas. The underlying assumption is that performance overhead associated with security inspection can be eliminated by shifting computation upstream, directly onto the network devices themselves. The implication for human agency rests on whether this architecture democratizes sophisticated analysis or concentrates control in the AI layers. The process of building an operational loop where engineering design dictates security posture, and data is automatically formatted for consumption, suggests a path toward systems where security intelligence is inherent to the platform rather than an overlaid afterthought. How does reliance on unified context via agents change the traditional skill set required for effective incident response when the system itself handles complex correlation? What are the hidden costs associated with delegating real-time decision-making to AI in these high-stakes, live environments?

From the original · Cisco Security Blog

At Splunk .conf26 in Denver, our team operated the live Security Operations Center (SOC) protecting more than 5,145 attendees representing 70 countries, including all attending Splunkers. We monitored multi-gigabit traffic while defending live capture the flag attack simulations and dynamic demo environments running throughout the venue.
Read the full story at blogs.cisco.com

Sentinel — Human

Confidence

This text reads like a highly technical, internally focused blog post or conference summary where deep operational experience informs an architectural argument about unifying network security and AI orchestration.

Signals Detected
low severity: Moderate sentence length variance; uses complex technical vocabulary but maintains a clear narrative flow.
low severity: Strong internal coherence, flowing logically from operational setup (SOC) to architectural philosophy (agentic pipeline) and finally to platform vision (Cisco Cloud Control).
low severity: The structure aligns with typical B2B/tech thought leadership articles: problem -> solution architecture -> implementation detail -> future vision. Attribution is internal ('our team') rather than external claims.
low severity: Uses highly specific, current industry terminology (Splunk ES, Snort 3, EVE, AgenticOps) in a way that suggests deep operational knowledge, but the flow is very smooth, common in technical white papers or blogs.
Human Indicators
The text successfully weaves highly specific, interconnected product names and architectural concepts (Splunk, Cisco, Snort 3) into a coherent narrative about an operational system, suggesting direct involvement or deep immersion in the subject matter.
The shift between describing operational execution ('live capture the flag attack simulations') and high-level conceptual architecture ('AgenticOps model') demonstrates a rhetorical arc typical of human-crafted explanatory writing.
Admin in the Loop: Firewalls and the Agentic SOC | Huntaegis