AI Canvas Shines New Light on the SOC

Platform Lizzy Li

Key takeaways

  1. AI can help security teams investigate alerts faster by turning questions into searches, visualizing data, and bringing key information together in one place.
  2. A shared workspace helps security teams collaborate in real time, making investigations easier to follow, hand off, and complete.
  3. Bringing data, context, and teamwork together can help teams find threats faster, reduce confusion, and improve security operations.

In the modern SOC, one of the most dangerous enemies is the sheer volume of noise that creates confusion, obscures threats, and wreaks havoc on visibility. Security analysts are continuously bombarded with alerts, while struggling to navigate disparate data sources, complex query languages, and unrelenting pressure to maintain a low MTTR. All of these factors make their job harder.

For the Splunk Global Security (SGS) team, weeding through complexity is an ongoing challenge. The desire to consider and experience possible new approaches to this challenge was a driving force to join the alpha program testing Cisco AI Canvas as “customer zero.”

As part of the Cisco AI Canvas Alpha program, SGS Threat Response, focused on first-hand experiences and provided critical feedback on how the tool could reshape analysts’ workstreams and impact future development. Although still in alpha, team members said the tool has the power to transform daily operations.

Here are some of the core use cases for Cisco AI Canvas that will help teams move from fragmented, disjointed workflows to a unified strategy.

Accelerating the “First Mile” of Investigation

At its core, Cisco AI Canvas is an AI-powered investigative workspace, with a mission to accelerate the security investigation lifecycle by transforming how analysts interact with data.

For a SOC analyst, the start of an investigation is often the most difficult phase. When an alert fires, analysts must quickly determine if a behavior is malicious or benign, triaging and prioritizing it amid a fog of incidents. “

One use case helps to address this challenge. Cisco AI Canvas uses natural language to generate complex SPL queries, removing the technical barrier for analysts who may not be experts in query syntax. By automating the “first mile" of the investigation, analysts can retrieve data and create visualizations in seconds, turning the most tedious parts of the job into a streamlined workflow.

"With Cisco AI Canvas, I can get that high level overview and understand the lay of the land quicker without having to run eight or ten different searches to look at various data sources. I can just get the answer that I need and have it visually. That speeds up my investigation process and helps me close tickets faster." - Ryan Cunningham, Splunk Incident Response Analyst.

Instant Pattern Visualization

Beyond query generation, Cisco AI Canvas turns raw data into actionable intelligence. Instead of manually writing queries to graph data, analysts can use the tool to instantly visualize patterns, spikes, or anomalies. This capability allows them to quickly identify outliers and focus on the most relevant details of an investigation. In complex environments, this visual approach allows SOC analysts to spot trends that might be buried in a wall of raw text, enabling them to make faster, better-informed decisions.

“You want to see where there’s a spike in traffic or just where there’s a lack of traffic,” said Austin Pham, Splunk incident response analyst. “There’s a visualization for that without having to create a dashboard or using time chart. That’s where Cisco AI Canvas really excels.”

Clear Data Correlations

In the SOC, Cisco AI Canvas is vital for data correlation and contextual clarity, offering the ability to act as a lighthouse that clears away incident “fog.” In complex environments, Cisco AI Canvas reduces the time spent searching for the right data and analyzing alerts by providing context that flags concerning behaviors. It also offers a cohesive view of an attacker’s path through infrastructure, allowing analysts to easily identify breaches, vulnerabilities, stealth malware, lateral movement, and other threats.

The tool consolidates disparate data sources across security, IT, observability, and engineering environments, into a single, visual workspace. By acting as a central hub, the tool helps analysts navigate and correlate complex log data sources across all data in Splunk and Cisco products.

The resulting high-level picture eliminates the need for analysts to manage dozens of browser tabs during investigations. It also creates greater consistency across investigations, connecting fragmented data trapped in organizational silos.

“Cisco AI Canvas has the potential to be a lighthouse that beacons out into the dark, murky waters of the data and the various sources we’re trying to navigate,” said Pham. “It maps the direction or starting point that leads us to a quicker response.”

Efficient Collaboration in a Virtual War Room

Perhaps one of the most exciting features Cisco AI Canvas offers is its ability to facilitate cross-team collaboration. The tool streamlines cross-functional communication, serving as a virtual war room that enables multiple analysts to work within the same workspace. It also allows members to work on the same investigation in real time, rather than relying on shared individual queries or static screenshots.

This collaborative environment has revolutionized the way team members hand over information between their shifts. Currently, shift handovers often require analysts to read through fragmented notes. Alternatively, Cisco AI Canvas provides an interactive visual record of an investigation, allowing incoming analysts to quickly grasp an incident’s current state and history. The result is seamless communication between analysts, incident response, and other security teams, reducing time, friction, confusion, and information loss associated with complex, high-pressure events.

“It allows us to engage people on an incident-by-incident basis and focus on the same work quicker than what we are doing now."

Beyond collaboration is Cisco AI Canvas’ ability to share institutional knowledge and uplevel teams. Entry-level analysts can hone their skills and share information as they use the tool to learn about new investigation types or specific misconfigurations directly within the interface. Because Cisco AI Canvas can standardize in-house knowledge across the team with a consistent framework, junior analysts can perform at a higher level by leveraging the visual workflows established by more senior members. This means that the SOC team can engage in high-level, comprehensive investigations, regardless of individual tenure.

From Alpha to Beta

Above all else, SOC tools aim to improve the security posture of the organization. That’s where Cisco AI Canvas shines. By enabling faster, more accurate diagnoses, the tool allows teams to move through the ticket queue more effectively, ensuring that malicious threats are caught before they can escalate into major breaches.

“It’s not only helping us get to the next issue faster, it’s helping us reach a correct diagnosis, reducing attack surface and the impact from those attacks,” said Brandon Parks, Splunk director of Threat Response.

The SGS team is currently in the early stages of discovery with Cisco AI Canvas. However, the tool’s potential is undeniable, representing a more visual, collaborative, and efficient way of working. And as the tool transitioned to the beta phase, and now the controlled availability phase, the team continues to refine use cases highlighting how these capabilities can further reduce detection time, drive efficiency, and create more clarity for the future of the agentic SOC.

Cisco AI Canvas is currently available for eligible customers. To learn more about how it can bring clarity to chaos and transform your SOC operations, please visit the Cisco AI Canvas page or contact your Cisco representative.

Related Articles

Monitoring Pulse Connect Secure With Splunk (CISA Emergency Directive 21-03)
Security
11 Minute Read

Monitoring Pulse Connect Secure With Splunk (CISA Emergency Directive 21-03)

Our Splunk security experts share a closer look at the Pulse Connect Secure attack, including a breakdown of what happened, how to detect it, and MITRE ATT&CK mappings.
Hunting M365 Invaders: Navigating the Shadows of Midnight Blizzard
Security
11 Minute Read

Hunting M365 Invaders: Navigating the Shadows of Midnight Blizzard

The Splunk Threat Research Team outlines the attack chain detailed in the Microsoft blog, offering practical detection and hunting tips for cybersecurity defenders.
Hunting M365 Invaders: Blue Team's Guide to Initial Access Vectors
Security
17 Minute Read

Hunting M365 Invaders: Blue Team's Guide to Initial Access Vectors

Discover insights from the Splunk Threat Research Team on Microsoft 365 threat detection, focusing on data source analysis and effective methods for hunting initial access threats.