Machine Speed, Human Judgment: Inside the Cisco Live Agentic SOC
Security Jessica OppenheimerKey takeaways
- Cisco Live Americas 2026 showcased an Agentic SOC where AI accelerated triage and investigations while analysts retained control of validation, escalation, and response decisions.
- Splunk Enterprise Security served as the evidence and investigation hub, connecting telemetry, detections, packet capture, malware analysis, and agentic workflows for faster, auditable decisions.
- The live SOC showed that effective agentic security requires AI, automation, governance, and human oversight working together to turn complex security data into actionable insights.
At Cisco Live Americas 2026, Cisco Security and Splunk Security built the first Agentic SOC for a major Cisco event.
The goal was not to replace analysts with AI. The goal was to change the operating model: use agentic workflows to reduce repetitive triage, summarize evidence, recommend next steps, and preserve auditability, while keeping humans responsible for validation, escalation, and response decisions.
Security operations teams do not need another black box. They need faster ways to understand what happened, why it matters, what evidence supports the conclusion, and what action should come next. At Cisco Live Americas, Splunk Enterprise Security served as the evidence and investigation plane for that model.
The SOC and NOC were placed at the center of the World of Solutions, giving attendees a live view into how networking, security, observability, packet capture, malware analysis, automation, and AI-assisted workflows come together in a real event environment. The SOC was built in two days using the evolving SOC in a Box architecture, cloud-based security services, Splunk Cloud, Splunk Enterprise Security, Endace full packet capture, Cisco Security telemetry, threat intelligence, and agentic capabilities under active development.
The operating loop was simple:
Incident. Agentic review. Evidence summary. Human validation. Action or closure. Audit.
Splunk Enterprise Security was central because agentic recommendations are only useful when analysts can validate them. When an agentic workflow summarized an incident or suggested a next step, analysts needed to see the underlying searches, detections, events, malware analysis, packet evidence, and investigation context. Splunk provided the place where that evidence could be searched, correlated, reviewed, and retained.
At Cisco Live Americas 2026, the scale was substantial. The SOC supported more than 20,700 attendees, captured 5.6 billion logs in Splunk, wrote 7.4 terabytes of logs to Splunk Cloud, captured 202.9 billion packets through Endace, observed more than 270 million DNS requests, and added perimeter firewall data from more than 10 million external attempts to attack the network.
That volume creates a real challenge for analysts, especially in an event environment where baselines are short, devices are unmanaged, and the network is intentionally open enough to support labs, demos, and attendee activity.
This is where the Agentic SOC model showed its value.
Agentic workflows helped analysts move faster from alert to understanding. Cisco XDR Attack Storyboard and Verification helped explain what happened and whether the available evidence supported escalation, closure, or continued monitoring. Splunk Enterprise Security Triage Agent helped answer the next question: what does the evidence say? Endace packet capture helped prove or disprove hypotheses with packet-level detail. Splunk Attack Analyzer supported file and URL analysis. AI Defense and DefenseClaw helped inspect, guardrail, and audit agentic workflows.
The result was not autonomous security operations. It was auditable acceleration.
The SOC trained more than a dozen new analysts and empowered them to operate at a Tier 2 level with agentic support. That may be the most important lesson from Cisco Live: AI did not remove the analyst from the workflow. It gave analysts a better starting point. Instead of spending their first hours learning where every tool lived and how to assemble context manually, analysts could begin with a structured incident narrative, supporting evidence, and recommended next steps.
Splunk also helped preserve the learning loop. Dashboards tracked agentic-assisted incident investigations and escalations. Investigation data, telemetry, detections, and evidence could be reviewed after the fact. That is essential for trust. In an Agentic SOC, teams need to know not only what conclusion was reached, but how that conclusion was reached.
One example was cleartext credential exposure. The SOC observed 43,322 cleartext usernames and passwords across 686 unique devices or accounts. In some cases, automation could notify attendees and close the incident without requiring manual analyst review. That kind of workflow is exactly where automation belongs: repeatable, evidence-backed, low ambiguity, and auditable.
The same evidence-first model applied to malware analysis. Endace reconstructed file objects from network traffic, and thousands were sent to Splunk Attack Analyzer for analysis. This gave analysts a practical path from network observation to artifact analysis to investigation context.
The broader lesson is that Agentic SOC is not a single product or feature. It is an operating model. It requires telemetry, detections, enrichment, packet evidence, malware analysis, workflow automation, AI governance, and human validation to work together.
For Splunk Security, Cisco Live Americas showed how Splunk Enterprise Security can serve as the center of gravity for evidence-driven agentic operations. Splunk ES gives analysts the workspace to investigate. Splunk Cloud provides the scale to retain and search event telemetry. Splunk SOAR connects repeatable workflows to action. Splunk Attack Analyzer brings malware and URL analysis into the investigation path. And Splunk’s detection and risk frameworks provide the foundation for turning high-volume telemetry into decision-ready findings.
The Agentic SOC at Cisco Live Americas was not a lab demo. It was a live operating environment with real traffic, real incidents, real analysts, and real constraints.
That is what made it valuable.
The future of security operations will not be defined by AI alone. It will be defined by whether AI can help analysts make better, faster, more defensible decisions. At Cisco Live Americas 2026, we saw what that future can look like: agents assist, Splunk grounds the evidence, and humans stay in control.
Agentic SOC Findings and Lessons Learned
Check out the blogs by the engineers who worked inside the SOC at Las Vegas:
- Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026
- The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth
- Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC
- What Working the Cisco Live SOC Taught Me About AI, Detection, and Response
- Educate at Event Speed: Inside the Cisco Live SOC
- Elevating Expertise in the SOC
- Machine Speed, Human Judgement: How AI Changed the SOC in 2026
- SharpHound Recon Attack - How AI enhanced the threat hunt
- Endace: Using LLMs and Endace Full Packet Capture for Incident Response
- Endace: Never Underestimate Cisco Live!
- Endace: Supporting Encryption vs. Using Encryption: When the best laid plans go astray
Acknowledgements
Our thanks to the engineers who made the first Agentic SOC at Cisco Live a success, by protecting the network and educating attendees (and you).
Network Operations Center Liaisons
- Freddy Bello, Andy Phillips and Scott Neuman
Cisco Security and Splunk SOC Team
- SOC in a Box hardware: Aditya Sankar
- Splunk Security Integrations: Ivan Berlinson, Paul Pelletier and Josh Wilson
- Splunk Security: Drew Church, Erik Dove, Todd Dow, Daniel Christiansen, Logan Buntrock
- Cisco Security: Lou Norman and Oscar Ramirez
- Analysts: John Park, Abhishek Dubey, Manoj Sudhakara, Pujan Trivedi, Bilal Qamar, Michelle Hermosillo, Ray Aragon, Kellie Cottingame, Alfredo Jurado, Jeremy Stanley, Chris Perkins, Paul Jeffery, Chris Lijoi, Adam Alkishawi, Maurali Ananth, Bill Radford, Brian Rees and Chris Ochia-Belen
- Remote support: Adam Kilgore, Kenneth Bouchard, Aditya Raghavan, Chris Anderson, Kevin Wofford
Endace SOC Team
- Cary Wright, Barry ‘Baz’ Shaw, Stephen Donnelly, Elliott Hinson and Michael Morris
Related Articles

AI: Keep Your Feet on the Ground

Splunk is a Leader and Placed Highest in Execution in the Gartner® Magic Quadrant™ for SIEM
