Machine Speed, Human Judgment: Inside the Cisco Live Agentic SOC

Security Jessica Oppenheimer

Key takeaways

  1. Cisco Live Americas 2026 showcased an Agentic SOC where AI accelerated triage and investigations while analysts retained control of validation, escalation, and response decisions.
  2. Splunk Enterprise Security served as the evidence and investigation hub, connecting telemetry, detections, packet capture, malware analysis, and agentic workflows for faster, auditable decisions.
  3. The live SOC showed that effective agentic security requires AI, automation, governance, and human oversight working together to turn complex security data into actionable insights.

At Cisco Live Americas 2026, Cisco Security and Splunk Security built the first Agentic SOC for a major Cisco event.

The goal was not to replace analysts with AI. The goal was to change the operating model: use agentic workflows to reduce repetitive triage, summarize evidence, recommend next steps, and preserve auditability, while keeping humans responsible for validation, escalation, and response decisions.

Security operations teams do not need another black box. They need faster ways to understand what happened, why it matters, what evidence supports the conclusion, and what action should come next. At Cisco Live Americas, Splunk Enterprise Security served as the evidence and investigation plane for that model.

The SOC and NOC were placed at the center of the World of Solutions, giving attendees a live view into how networking, security, observability, packet capture, malware analysis, automation, and AI-assisted workflows come together in a real event environment. The SOC was built in two days using the evolving SOC in a Box architecture, cloud-based security services, Splunk Cloud, Splunk Enterprise Security, Endace full packet capture, Cisco Security telemetry, threat intelligence, and agentic capabilities under active development.

clema-2.png

The operating loop was simple:

Incident. Agentic review. Evidence summary. Human validation. Action or closure. Audit.

Splunk Enterprise Security was central because agentic recommendations are only useful when analysts can validate them. When an agentic workflow summarized an incident or suggested a next step, analysts needed to see the underlying searches, detections, events, malware analysis, packet evidence, and investigation context. Splunk provided the place where that evidence could be searched, correlated, reviewed, and retained.

At Cisco Live Americas 2026, the scale was substantial. The SOC supported more than 20,700 attendees, captured 5.6 billion logs in Splunk, wrote 7.4 terabytes of logs to Splunk Cloud, captured 202.9 billion packets through Endace, observed more than 270 million DNS requests, and added perimeter firewall data from more than 10 million external attempts to attack the network.

That volume creates a real challenge for analysts, especially in an event environment where baselines are short, devices are unmanaged, and the network is intentionally open enough to support labs, demos, and attendee activity.

This is where the Agentic SOC model showed its value.

Agentic workflows helped analysts move faster from alert to understanding. Cisco XDR Attack Storyboard and Verification helped explain what happened and whether the available evidence supported escalation, closure, or continued monitoring. Splunk Enterprise Security Triage Agent helped answer the next question: what does the evidence say? Endace packet capture helped prove or disprove hypotheses with packet-level detail. Splunk Attack Analyzer supported file and URL analysis. AI Defense and DefenseClaw helped inspect, guardrail, and audit agentic workflows.

The result was not autonomous security operations. It was auditable acceleration.

The SOC trained more than a dozen new analysts and empowered them to operate at a Tier 2 level with agentic support. That may be the most important lesson from Cisco Live: AI did not remove the analyst from the workflow. It gave analysts a better starting point. Instead of spending their first hours learning where every tool lived and how to assemble context manually, analysts could begin with a structured incident narrative, supporting evidence, and recommended next steps.

Splunk also helped preserve the learning loop. Dashboards tracked agentic-assisted incident investigations and escalations. Investigation data, telemetry, detections, and evidence could be reviewed after the fact. That is essential for trust. In an Agentic SOC, teams need to know not only what conclusion was reached, but how that conclusion was reached.

One example was cleartext credential exposure. The SOC observed 43,322 cleartext usernames and passwords across 686 unique devices or accounts. In some cases, automation could notify attendees and close the incident without requiring manual analyst review. That kind of workflow is exactly where automation belongs: repeatable, evidence-backed, low ambiguity, and auditable.

clema-3.png

The same evidence-first model applied to malware analysis. Endace reconstructed file objects from network traffic, and thousands were sent to Splunk Attack Analyzer for analysis. This gave analysts a practical path from network observation to artifact analysis to investigation context.

The broader lesson is that Agentic SOC is not a single product or feature. It is an operating model. It requires telemetry, detections, enrichment, packet evidence, malware analysis, workflow automation, AI governance, and human validation to work together.

For Splunk Security, Cisco Live Americas showed how Splunk Enterprise Security can serve as the center of gravity for evidence-driven agentic operations. Splunk ES gives analysts the workspace to investigate. Splunk Cloud provides the scale to retain and search event telemetry. Splunk SOAR connects repeatable workflows to action. Splunk Attack Analyzer brings malware and URL analysis into the investigation path. And Splunk’s detection and risk frameworks provide the foundation for turning high-volume telemetry into decision-ready findings.

The Agentic SOC at Cisco Live Americas was not a lab demo. It was a live operating environment with real traffic, real incidents, real analysts, and real constraints.

That is what made it valuable.

clema-4.png

The future of security operations will not be defined by AI alone. It will be defined by whether AI can help analysts make better, faster, more defensible decisions. At Cisco Live Americas 2026, we saw what that future can look like: agents assist, Splunk grounds the evidence, and humans stay in control.

Agentic SOC Findings and Lessons Learned

Check out the blogs by the engineers who worked inside the SOC at Las Vegas:

Acknowledgements

Our thanks to the engineers who made the first Agentic SOC at Cisco Live a success, by protecting the network and educating attendees (and you).

clamer-5.jpg

Network Operations Center Liaisons

Cisco Security and Splunk SOC Team

Endace SOC Team

Related Articles

AI: Keep Your Feet on the Ground
Security
1 Minute Read

AI: Keep Your Feet on the Ground

Splunk is excited about AI, but we're keeping our boots on the ground as we partner with customers to leverage AI to improve efficiency while continuing the essentials via Splunk’s platform.
Splunk is a Leader and Placed Highest in Execution in the Gartner® Magic Quadrant™ for SIEM
Security
4 Minute Read

Splunk is a Leader and Placed Highest in Execution in the Gartner® Magic Quadrant™ for SIEM

Splunk has once again been named a Leader in the 2025 Gartner® Magic Quadrant™ for Security Information and Event Management (SIEM) — our eleventh consecutive placement.
Staff Picks for Splunk Security Reading February 2024
Security
3 Minute Read

Staff Picks for Splunk Security Reading February 2024

The Splunk security team shares a curated list of presentations, whitepapers, and customer case studies they feel are worth a read.