What We Learned Building Agentic SOCs at the Toughest Live Events

Security Jessica Oppenheimer , Paul Pelletier

Earlier this year, we published our Lessons Learned from securing some of the world’s largest and most complex events. That first guide focused on how to rapidly deploy a cloud-first Event SOC in temporary, high-noise environments where thousands of unmanaged devices, short baselining windows, active security research, and real business operations all collide. Live events prove the future SOC needs speed, evidence and governed AI.

Since Then, the Operating Model Has Evolved

The revised report was released at Splunk .conf26, introducing the reference architecture from our experiences inside the Cisco Event Agentic SOCs. It is practical model for using AI agents with Splunk Enterprise Security (ES), Cisco Cloud Control, packet evidence, malware analysis, and human validation to accelerate security operations without losing accountability.

toughest-1.png

Agentic security operations should not mean removing people from the SOC. It should mean removing the repetitive Tier 1 collection work that slows analysts down: stitching together alerts, copying observables between tools, searching for supporting evidence, documenting basic context, and trying to decide whether something is worth deeper review. In the Event Agentic SOC, agents prepare the evidence. Humans validate the decision. Splunk ES preserves the investigation record.

toughest-2.png

The Event Agentic SOC

At security industry events, the SOC does not have the luxury of long baselines, full endpoint control, or a simple “block everything suspicious” response model. The team must protect the event network while preserving attendee experience, training environments, demos, media operations, and critical services. The answer is not blind automation. The answer is faster, better-contextualized decisions with strong evidence and clear human approval gates.

In the updated architecture, Splunk ES is the center of the analyst workflow. Detections, risk events, Findings, Investigations, dashboards, SPL searches, SOAR context, entity data, and evidence summaries come together in one place. The Splunk Triage Agent can help assess evidence, summarize likely scope, recommend next steps, and identify gaps. Analysts then validate the findings, determine impact, and decide whether to close, escalate, hunt, or respond.

The revised guide also reflects how the Event Agentic SOC uses Cisco and partner technologies as the evidence layer that helps analysts make decisions.

toughest-3.png

Since Then, the Operating Model Has Evolved

Every event gives us real telemetry, real analyst workflows, real integration pressure, and real customer-facing proof. When a detection works, it can become reusable content. When a workflow breaks, it becomes product feedback. When an analyst needs context that is missing, it becomes an integration requirement. When a tour resonates with a customer, it becomes field enablement.

That is the value of the Event Agentic SOC: it connects operations, product design, engineering, sales, and customer education in one live environment.

The updated resources hub includes new video resources showing the Event Agentic SOC in action.

The lesson from the past year is that the future SOC is not just more automated. It is more evidence-driven, more governed, more transparent, and more teachable. Agents accelerate triage. Splunk ES unifies the investigation. Cisco and partner telemetry provide the evidence. Human analysts still make the critical decisions, and feed that back into the Agentic SOC operating model.

That is the operating model we built and are sharing with you: agents prepare, humans validate, evidence proves, and operations improve.

Event Agentic SOC: Reference Architecture & Operations Guide

Related Articles

Picture Paints a Thousand Codes: Dissecting Image-Based Steganography in a .NET (Quasar) RAT Loader
Security
13 Minute Read

Picture Paints a Thousand Codes: Dissecting Image-Based Steganography in a .NET (Quasar) RAT Loader

Uncover how to identify malicious executable loaders that use steganography to deliver payloads such as Quasar RAT.
Add to Chrome? - Part 2: How We Did Our Research
Security
5 Minute Read

Add to Chrome? - Part 2: How We Did Our Research

SURGe explores the analysis pipeline in more detail and digs into the two main phases of this research – how the team collected the data and how they analyzed it.
DORA will accelerate cloud migration in Financial Services
Security
2 Minute Read

DORA will accelerate cloud migration in Financial Services

The much-anticipated Digital Operational Resilience Act (DORA) is finally here. This Regulation, applicable across the 27 EU Member States, provides a set of guidelines via which financial services organisations will need to prove that they are operationally resilient, i.e, they are able to withstand any unforeseen shocks.