Trusted Agentic SOC: The AI in Security and the Security in AI
Security Rod SotoKey takeaways
- AI agents gather evidence, suggest next steps, and generate search queries, giving analysts a head start instead of starting each investigation from scratch.
- Investigations stay connected from alert to evidence to detection improvement, so lessons learned help build stronger future security detections.
- Human analysts still review evidence, validate AI-generated queries, and approve high-impact actions, ensuring AI supports decisions rather than replacing judgment.
During .conf26, I had the opportunity to see the Splunk Agentic Security Operations Center (SOC) in action. The strongest part of the demonstration was the way AI agents supported security analysts during alert triage and investigation. The experience made the idea of an Agentic SOC feel practical because it connects triage, evidence, investigation, response, and detection improvement in one workflow. The agent can gather context, organize evidence, and suggest next steps while the analyst remains responsible for judgment and high-impact decisions.
The screenshots in this article show the workflow from several angles. They should be read as examples of the interface and the activity it records, not as independent proof that every investigation will produce the same result. The important question is how the pieces fit together and whether they help an analyst reach a defensible decision faster.
Why Alert Triage Needs Assistance
Security operations teams must work through large volumes of alerts while also investigating the small number of events that may represent real threats. Triage requires more than a severity label. Analysts need context about the entities involved, related activity, available threat intelligence, and the quality of the underlying data. Gathering that context manually can delay the investigation and can make it difficult to apply the same level of attention to every alert.
The agentic approach presented at .conf focuses on this early stage. The agent can enrich findings, prioritize them, and explain why an alert deserves attention. That does not eliminate the analyst’s role. It changes the analyst’s starting point from an isolated alert to an investigation that already contains relevant context and suggested lines of inquiry.
The triage dashboard records agent activity, including generated queries, evidence considered, hypotheses considered, and threat intelligence lookups.
From Alert to Investigation
The Analyst Queue and Mission Control provide the operational center of the workflow. An analyst can review alerts, inspect their status, and follow up on a finding without losing the connection to the original detection. The interface also provides a path to start an investigation with agentic assistance when the initial alert does not contain enough information to make a decision or simply as a way to verify the path that led to the alert.
The Analyst Queue organizes findings so the analyst can review status, priority, and related investigation details in one place.
The value of this workflow is not a single screen. It is the sequence between screens. An alert can be reviewed, enriched, investigated, and either resolved or escalated while the evidence remains attached to the case. That continuity can reduce context switching and make it easier for another analyst to understand what has already been checked. For ‘SE Clear Text Password Detection’ Findings, those were opened, had a response action, and Closed by ‘The Agent’, with no human analyst interaction, as the response action was tested to confirm no impact to the network or the conference.
The queue can be paired with investigation details, so the analyst can move from a finding to the evidence and suggested follow-up work.
Evidence and Explainability
An agent recommendation is useful only when the analyst can examine the basis for it. The investigation view presents entities, context, results, and supporting evidence rather than only a final disposition. This matters because analysts must be able to challenge an incorrect conclusion, identify missing data, and explain the decision later to a teammate or incident reviewer.
The inclusion of agent-generated SPL queries is also important. The query gives the analyst a concrete way to inspect the data behind the hypothesis. It makes the investigation more transparent than a summary that cannot be reproduced. Analysts should still validate the query and its assumptions, particularly when the query is used to support containment, escalation, or another high-impact action.
The investigation view surfaces entities, context, evidence, and generated SPL that can be reviewed as part of the analyst’s decision.
Analyzing Files Without Losing Context
The Analyst Queue also provides a path to upload files for analysis with Splunk Attack Analyzer. That capability extends the investigation beyond the original alert. When a suspicious file is relevant to the case, the analyst can submit it for behavioral analysis and use the result to determine whether the original finding should be strengthened, narrowed, or revisited.
Keeping file analysis connected to the investigation is useful because it preserves the reasoning around the submission. The analyst can see why the file was uploaded, compare the analysis with other evidence, and decide what action is justified. The interface is most valuable when it helps the analyst maintain that chain of evidence instead of treating file analysis as an unrelated lookup.
Attack Analyzer provides behavioral details for an uploaded file that can be considered alongside the original detection and investigation of evidence.
From Investigation to Detection Engineering
An investigation should improve the SOC’s future coverage whenever it reveals a behavior that existing detections do not capture well. Security Content provides access to existing Enterprise Security Content Updates (ESCU) content and helps analysts identify detections that may be relevant to the current environment. This makes the transition from investigating one event to improving future detection coverage more direct.
Security Content presents detection coverage and health information that can help analysts identify relevant content and potential gaps.
Detection editor continues that process. An analyst can clone, modify, improve, or create a detection and test it against available data before deploying it. That testing step is important because it gives the analyst a chance to inspect the results, tune the detection, and understand how it will behave in the environment. The result is a feedback loop: investigations inform detections, and better detections improve future triage.
Detection Studio supports the development and testing of detection logic before it is added to the operational workflow.
Detection results can be reviewed for coverage, health, and other attributes before the content is used in triage.
Human Judgment Remains Part of the System
The most important design constraint is that the agentic SOC should enhance analysts rather than remove accountability from the process. The agent can help gather information, generate queries, summarize evidence, and propose a disposition. The analyst still needs to validate the evidence, understand uncertainty, and approve actions that could affect users, systems, or business operations.
Human-in-the-loop control should be specific rather than habitual. Organizations should define which actions require approval, how low-confidence results are handled, how generated queries are reviewed, and how agent activity is recorded aiming to improve this process. Telemetry of false positives, false negatives, investigation time, and analyst acceptance must be tracked instead of relying only on the amount of activity displayed by a dashboard.
This distinction is important because automation can make a weak conclusion easier to repeat or trigger a cascade of errors. A fast workflow is valuable only when it preserves the ability to inspect the evidence and correct the agent. The goal is not to make every decision automatic. The goal is to make good decisions easier to reach and bad decisions easier to prevent.
The Security in AI
The second half of this topic is the security of the agents themselves. As organizations deploy more AI systems, their SOCs will need to monitor not only traditional infrastructure and identities, but also the agents that can read data, call tools, generate queries, and recommend actions. An agent with too many permissions or insufficient oversight could create a new path for abuse even if the underlying detection workflow is well designed.
That means an agentic SOC should be evaluated as both a security capability and a security-sensitive system. Access should be limited to the tools and data the agent needs. Agent actions should be auditable. Generated content should be treated as untrusted input to review rather than an unquestionable authority. Organizations should also consider how prompt injection, manipulated data, unsafe tool calls, and compromised agent identities could affect an investigation.
This is where the future of security operations becomes more complicated. Defenders will use agents to manage the volume and speed of activity created by other automated systems, while adversaries will look for ways to influence the data and decisions on which those agents depend. The SOC will need operational discipline and security controls around its AI systems, not only enthusiasm for their productivity benefits.
Conclusion
The Agentic SOC shown at .conf26 is promising as an analyst enhancement. Its strongest contribution is the connection between triage, investigation, evidence, file analysis, and detection engineering. That connection can help analysts spend less time collecting information manually and more time evaluating what the information means.
The technology still needs human judgment to be effective. Analysts must be able to inspect the evidence, validate generated queries, challenge weak conclusions, and approve high-impact actions. Organizations also need to secure the agents that support the SOC and measure their performance with operational outcomes.
As AI adoption increases, the amount of data and automation facing security teams will continue to grow. Agents that help analysts find meaningful alerts, correlate activity, investigate evidence, and improve detections will become increasingly important. The challenge is to build that assistance with enough transparency, control, and security that strengthens the SOC instead of creating another source of risk.
Check out the other blogs by the humans in the .conf26 Agentic SOC.
Related Articles

Staff Picks for Splunk Security Reading March 2023

Staff Picks for Splunk Security Reading July 2022
