Splunk .conf26: Proving the Agentic SOC in the Center of the Community

Security Jessica Oppenheimer

Key takeaways

  1. AI agents helped analysts quickly gather evidence and investigate threats, but humans made all final decisions on what was true and how to respond.
  2. Splunk Enterprise Security 8.7 served as one unified workspace where analysts investigated threats without switching between multiple separate tools.
  3. A junior analyst using an AI Triage Agent uncovered a real credential-theft attack, leading to fast detection and containment of an infected laptop on-site.

Splunk .conf26 gave us the opportunity to build a real Agentic Security Operations Center (SOC) in the middle of the Splunk community, with live data, human analysts, Black Hat refined detections, and customer conversations happening around it. With our Cisco, Splunk, Endace and Jamf team, we created the SOC from our experiences at Cisco Live, Black Hat, RSAC, the NFL Super Bowl, and protecting other large-scale events.

Check out the recap video below.

Event SOCs are noisy, temporary, highly dynamic, and full of devices and behaviors we do not completely control, except for the conference devices themselves. That is what makes these SOCs such powerful proving grounds. They force the SOC team to make fast, evidence-based, risk-aware decisions under conditions that look a lot like the hardest parts of enterprise security operations.

At .conf26, our goal was to operate a live Agentic SOC that protected the event, educated customers and the field, and validated the future of security operations with Splunk Enterprise Security (ES) 8.7 at the center. We appreciate David Bombal stopping by to talk about how to spot a real Agentic SOC.

ops-1.jpg

Protect First, Then Innovate

The first mission of any event SOC is always to protect the network and the people depending on it. The network must work. The customer experience must be preserved. The SOC must investigate quickly, but it also must respond carefully.

That balance was especially important at .conf26. Activity that would be alarming on a corporate network may be normal in Splunk University, Boss of the SOC capture the flag, a demo environment, or a security research setting. At the same time, real threats can appear in the same telemetry. The challenge was not just detecting activity. The challenge was determining which activity was truly malicious in context.

This is where the Agentic SOC model had direct impact. Agents helped gather context, summarize evidence, identify gaps, and recommend next steps. Humans still decided what was true, what mattered, and whether response was appropriate. When we could trust the autonomy of the agents, after extensive testing, we then handed off those tasks to be completed (with an audit trail) without further human gatekeeping.

A common discussion topic for customers who toured the SOC was, “Is AI replacing analysts?” For our Agentic SOC, the architecture was agent-assisted, evidence-backed, human-validated security operations.

ops-2.png

Splunk ES as the Unified TDIR Center

At .conf26, Splunk ES served as the primary analyst workspace, evidence system, and Unified Threat Detection, Investigation, and Response (TDIR) platform for the SOC. Splunk ES centralized detections, risk events, Findings, investigations, dashboards, searches, response plans, and analyst workflows.

Instead of analysts jumping across many tools to build a story from scratch, Splunk ES became the place where the evidence came together, with the new Agentic SOC Workforce. Role-based access made that operating model practical: SOC leaders, analysts, threat hunters, detection engineers, and response owners could work from the same investigation record while seeing and doing only what their role allowed.

Operating Splunk ES as a unified TDIR workspace proved that consolidating detection through documentation eliminated unnecessary pivots, preserved a shared investigation record across all tiers, and empowered teams to make faster, evidence-backed decisions with governed response controls.

What Fed the SOC

Below you can see a graphic of the telemetry that was ingested into Splunk ES. This data was not valuable simply because it existed. It became valuable when it was normalized, correlated, searched, enriched, and turned into evidence that an analyst could trust. Our thanks to Josh Wilson, who led the architect team.

The operating flow was designed around that principle: telemetry entered Splunk Cloud, ES detections and risk-based alerting identified activity of interest, Findings were reviewed by the Agentic SOC Workforce Triage skill, humans validated the evidence, and deeper investigation pivoted into SPL, Endace packet capture, Splunk Attack Analyzer, Secure Malware Analytics, endpoint context, DNS, firewall, and identity data as needed.

ops-3.png

Agents Prepared. Humans Decided. Evidence Proved.

One of the most important lessons from Cisco Live Americas 2026 was that agentic workflows can raise the starting point for analysts. New analysts do not need to begin with a raw alert queue and a dozen product consoles. They can begin with an evidence package: what happened, what is known, what is uncertain, what the agent recommends, and what a human needs to validate.

At .conf26, the Agentic SOC Workforce is made of several AI skills, as natural extensions of their human counterparts: AI Assistant in Security, Triage Agent, Guided Response, Malware Threat Reversing, and response-plan driven automation. The practical question was not whether one agent could replace an analyst. The question was which parts of triage, evidence gathering, and response preparation could be accelerated while keeping permissioned actions governed. Humans remained accountable for decisions that affected event availability, attendee experience, or customer operations.

For example, in her very first hour on her first day in the Agentic SOC, Oxana Sannikova, a Tier 1 analyst leveraging the Triage Agent investigated an assessed likely true positive outbound connection to a suspicious domain (moonlighthathel[.]org), which the AI agent rapidly enriched and correlated against a malicious fake-Corepack credential-theft and proxyware campaign. What began as an automated alert triage was immediately escalated into a high-priority Tier 3 Incident Response investigation by Richard Marsh, as deep Endace packet capture and Zeek telemetry uncovered 15 exposed endpoints across the venue.

Richard isolated one attendee laptop that had arrived on-site already infected and was actively exchanging encrypted application data with adversary command-and-control infrastructure. By cross-referencing authentication and network activity, the team physically located the impacted Splunk customer on the show floor, contained the compromised laptop, and guided the customer through full on-site malware remediation, credential rotation, and session revocations. Read more about this real-world incident where an AI-assisted triage seamlessly empowered junior analysts to detect critical threats and accelerate high-impact incident response.

Learn From Our Experiences

Our thanks to the engineers and analysts who wrote about their experiences. Check out their blogs:

Stats

Statistics are always a popular part of the SOC Tours. Here are those from .conf26, for context on the scope of the four days of operations (13-16 September 2026):

Year
2026
Attendees (.conf)
5,100+
Total packets captured (Endace)
31.5 Billion
Total logs captured (Splunk)
4.75 Billion
Total sessions (Endace)
155 Million
Total unique devices
15,259 (DHCP)
Total packets written to disk (Endace)
31.6 TB
Total logs written to cloud (Splunk)
1.5 terabytes
Peak bandwidth utilization (Endace)
2.36 Gbps
DNS Requests (Cisco)
8.7 million / 20.5k blocked
Total clear text username/passwords (Endace)
3,589
Unique devices / accounts with clear text usernames / passwords (Endace)
83
Files sent for malware analysis (Endace)
  • 111k file objects reconstructed by Endace
  • 5,906 sent to Splunk Attack Analyzer

What Customers Saw, Live

Customers joining public or private Agentic SOC tours left with three core takeaways:

ops-4.png

Acknowledgements

Our thanks to the engineers who built the Agentic SOC and the Humans who provided decision making expertise.

Related Articles

Cisco Intends to Acquire Threat Detection and Defense Company SnapAttack, Driving Further Splunk Innovation to Power the SOC of the Future
Security
2 Minute Read

Cisco Intends to Acquire Threat Detection and Defense Company SnapAttack, Driving Further Splunk Innovation to Power the SOC of the Future

Cisco announces it intent to acquire threat detection and defense company SnapAttack, driving further Splunk innovation to power the SOC of the future.
Staff Picks for Splunk Security Reading May 2021
Security
2 Minute Read

Staff Picks for Splunk Security Reading May 2021

Check out the favorite security-centric presentations, white papers and customer case studies from various peeps in the Splunk (or not) security world that WE think everyone should read.
I Scream, You Scream, We All Scream For BOTS!
Security
1 Minute Read

I Scream, You Scream, We All Scream For BOTS!

We are excited to announce our August Boss of the SOC (BOTS) V event! What’s new in BOTS V? I’m glad you asked. This year, we find our favorite brewery, Frothly, converting to a remote model and embracing the cloud for ‘all the things.'