Splunk .conf26: Proving the Agentic SOC in the Center of the Community
Security Jessica OppenheimerKey takeaways
- AI agents helped analysts quickly gather evidence and investigate threats, but humans made all final decisions on what was true and how to respond.
- Splunk Enterprise Security 8.7 served as one unified workspace where analysts investigated threats without switching between multiple separate tools.
- A junior analyst using an AI Triage Agent uncovered a real credential-theft attack, leading to fast detection and containment of an infected laptop on-site.
Splunk .conf26 gave us the opportunity to build a real Agentic Security Operations Center (SOC) in the middle of the Splunk community, with live data, human analysts, Black Hat refined detections, and customer conversations happening around it. With our Cisco, Splunk, Endace and Jamf team, we created the SOC from our experiences at Cisco Live, Black Hat, RSAC, the NFL Super Bowl, and protecting other large-scale events.
Check out the recap video below.
Event SOCs are noisy, temporary, highly dynamic, and full of devices and behaviors we do not completely control, except for the conference devices themselves. That is what makes these SOCs such powerful proving grounds. They force the SOC team to make fast, evidence-based, risk-aware decisions under conditions that look a lot like the hardest parts of enterprise security operations.
At .conf26, our goal was to operate a live Agentic SOC that protected the event, educated customers and the field, and validated the future of security operations with Splunk Enterprise Security (ES) 8.7 at the center. We appreciate David Bombal stopping by to talk about how to spot a real Agentic SOC.
Protect First, Then Innovate
The first mission of any event SOC is always to protect the network and the people depending on it. The network must work. The customer experience must be preserved. The SOC must investigate quickly, but it also must respond carefully.
That balance was especially important at .conf26. Activity that would be alarming on a corporate network may be normal in Splunk University, Boss of the SOC capture the flag, a demo environment, or a security research setting. At the same time, real threats can appear in the same telemetry. The challenge was not just detecting activity. The challenge was determining which activity was truly malicious in context.
This is where the Agentic SOC model had direct impact. Agents helped gather context, summarize evidence, identify gaps, and recommend next steps. Humans still decided what was true, what mattered, and whether response was appropriate. When we could trust the autonomy of the agents, after extensive testing, we then handed off those tasks to be completed (with an audit trail) without further human gatekeeping.
A common discussion topic for customers who toured the SOC was, “Is AI replacing analysts?” For our Agentic SOC, the architecture was agent-assisted, evidence-backed, human-validated security operations.
Splunk ES as the Unified TDIR Center
At .conf26, Splunk ES served as the primary analyst workspace, evidence system, and Unified Threat Detection, Investigation, and Response (TDIR) platform for the SOC. Splunk ES centralized detections, risk events, Findings, investigations, dashboards, searches, response plans, and analyst workflows.
Instead of analysts jumping across many tools to build a story from scratch, Splunk ES became the place where the evidence came together, with the new Agentic SOC Workforce. Role-based access made that operating model practical: SOC leaders, analysts, threat hunters, detection engineers, and response owners could work from the same investigation record while seeing and doing only what their role allowed.
Operating Splunk ES as a unified TDIR workspace proved that consolidating detection through documentation eliminated unnecessary pivots, preserved a shared investigation record across all tiers, and empowered teams to make faster, evidence-backed decisions with governed response controls.
What Fed the SOC
Below you can see a graphic of the telemetry that was ingested into Splunk ES. This data was not valuable simply because it existed. It became valuable when it was normalized, correlated, searched, enriched, and turned into evidence that an analyst could trust. Our thanks to Josh Wilson, who led the architect team.
The operating flow was designed around that principle: telemetry entered Splunk Cloud, ES detections and risk-based alerting identified activity of interest, Findings were reviewed by the Agentic SOC Workforce Triage skill, humans validated the evidence, and deeper investigation pivoted into SPL, Endace packet capture, Splunk Attack Analyzer, Secure Malware Analytics, endpoint context, DNS, firewall, and identity data as needed.
Agents Prepared. Humans Decided. Evidence Proved.
One of the most important lessons from Cisco Live Americas 2026 was that agentic workflows can raise the starting point for analysts. New analysts do not need to begin with a raw alert queue and a dozen product consoles. They can begin with an evidence package: what happened, what is known, what is uncertain, what the agent recommends, and what a human needs to validate.
At .conf26, the Agentic SOC Workforce is made of several AI skills, as natural extensions of their human counterparts: AI Assistant in Security, Triage Agent, Guided Response, Malware Threat Reversing, and response-plan driven automation. The practical question was not whether one agent could replace an analyst. The question was which parts of triage, evidence gathering, and response preparation could be accelerated while keeping permissioned actions governed. Humans remained accountable for decisions that affected event availability, attendee experience, or customer operations.
For example, in her very first hour on her first day in the Agentic SOC, Oxana Sannikova, a Tier 1 analyst leveraging the Triage Agent investigated an assessed likely true positive outbound connection to a suspicious domain (moonlighthathel[.]org), which the AI agent rapidly enriched and correlated against a malicious fake-Corepack credential-theft and proxyware campaign. What began as an automated alert triage was immediately escalated into a high-priority Tier 3 Incident Response investigation by Richard Marsh, as deep Endace packet capture and Zeek telemetry uncovered 15 exposed endpoints across the venue.
Richard isolated one attendee laptop that had arrived on-site already infected and was actively exchanging encrypted application data with adversary command-and-control infrastructure. By cross-referencing authentication and network activity, the team physically located the impacted Splunk customer on the show floor, contained the compromised laptop, and guided the customer through full on-site malware remediation, credential rotation, and session revocations. Read more about this real-world incident where an AI-assisted triage seamlessly empowered junior analysts to detect critical threats and accelerate high-impact incident response.
Learn From Our Experiences
Our thanks to the engineers and analysts who wrote about their experiences. Check out their blogs:
- The Queue Is a Graph, Not a To-Do List
- Trusted Agentic SOC: The AI in Security and the Security in AI
- A Network Engineer Walks into the Agentic SOC: What AI Taught Me About Security Operations
- Scalpel Versus Sledgehammer
- Tracking the Triage Agent in the Agentic SOC at Splunk .conf26
- The Zero-Day Blind Spot: Why Your Agentic SOC needs Retrospective Packet Replay
- Chasing AMMYY at Splunk .conf
- Admin in the Loop: Firewalls and the Agentic SOC
- From Novice to Senior - How an MCP-Enabled Capture Appliance Changes Threat Hunting
- Decode First, Panic Later: A Tier 3 Analyst's Case for Staying in the Loop
- Endace: Why Full Packet Capture Becomes Mission-Critical in the Agentic SOC
- Endace: Richer Data for the Agentic SOC
- Endace: Letting the Agentic SOC Handle the Drudgery So the Humans Can Dig Deeper
Stats
Statistics are always a popular part of the SOC Tours. Here are those from .conf26, for context on the scope of the four days of operations (13-16 September 2026):
- 111k file objects reconstructed by Endace
- 5,906 sent to Splunk Attack Analyzer
What Customers Saw, Live
Customers joining public or private Agentic SOC tours left with three core takeaways:
- First, Splunk has a real AI story grounded in actual SOC work, not a generic AI overlay. Agentic AI was applied to real workflows: triage, detection engineering, investigation, response planning, automation, malware analysis, and analyst guidance.
- Second, Splunk ES is becoming a Unified TDIR workspace. The SOC team investigated from one primary analysis plane, while still preserving pivots to the right supporting evidence: packet capture, malware analysis, DNS, firewall, endpoint, identity, and threat intelligence.
- Third, the economics and architecture of security data are changing. Not every signal needs to become a high-cost alert. Some data should become risk context. Some should feed hunting. Some should trigger immediate investigation. The Agentic SOC gave us a practical way to show how data, detections, agents, and human judgment can work together.
Acknowledgements
Our thanks to the engineers who built the Agentic SOC and the Humans who provided decision making expertise.
- SOC Co-Leader Architecture: Paul Pelletier
- Agentic SOC Innovation: Ryan Maclennan & Aditya Sankar
- Splunk Integrations: Josh Wilson & Christian Cloutier
- SOC Analysts: Christopher Van Der Made, Sean Clapper, Oxana Sannikova, Daniel Christiansen, Lily Lee, Dan Burke, Kyle Vaughan & Ray Aragon
- Cisco Security Firewall / Switching: Adam Kilgore & Andrew Merica
- SOC VIP Tours Coordinator/Ops: Michelle Hermosillo
- Threat Hunter Tier 3/IR: Richard Marsh & Allison Gallo
- Detection Engineer: Rod Soto
- AI Canvas / XDR Forensics: Rob Gresham
- AI SOC Analyst Engineering: Fred Frey
- Remote support: Bhavin Patel, Shyue Hong Chuang, Nasreddine Bencherchali, Onur Erdogan, Nathan Schoen, Paul Carrillo, Jon Lane, Ryan Stillions & Raven Tait
- Endace Full Packet Capture: Michael Morris, Tom Leahy, Anantha Srinivasan, Elliott Hinson & Andreas Lof
- Jamf proof of value: Adam Derrick
Related Articles

Cisco Intends to Acquire Threat Detection and Defense Company SnapAttack, Driving Further Splunk Innovation to Power the SOC of the Future

Staff Picks for Splunk Security Reading May 2021
