From Live Event Telemetry to Action: Lessons from the 10th RSAC SOC
Security Jessica OppenheimerKey takeaways
- RSAC 2026 marked the 10th year of Cisco and Splunk supporting the Security Operations Center, using integrated telemetry, automation, and evidence to strengthen security operations.
- Splunk Enterprise Security helped analysts correlate security and network data, while automation reduced repetitive work and saved more than nine hours of analyst time.
- The RSAC SOC demonstrated key Agentic SOC principles: preserve evidence, automate repeatable workflows, use AI for decision support, and keep humans in control of critical responses.
At RSAC 2026 Conference, Cisco Security and Splunk Security supported the 10th year of the Security Operations Center. For a decade, the SOC mission has remained consistent: protect the conference network, educate attendees about real-world network risk, and innovate with new security operations practices.
The 2026 SOC was also an important step toward the Agentic SOC.
We were not operating a fully agentic SOC at RSAC 2026, but the foundation was taking shape: integrated telemetry, automated escalation, full packet evidence, AI-protected workflows, and a closed-loop operating model between Cisco Security and Splunk Enterprise Security. Those lessons helped inform the Agentic SOC work that followed at Cisco Live Americas 2026.
RSAC is a uniquely valuable environment for security operations because it looks like the real world. The conference wireless network is open and unsecured, similar to the networks people use every day in hotels, airports, coffee shops, and major events. The SOC does not decrypt attendee traffic, and it does not control attendee endpoints. That means analysts must work from the evidence available to them: DNS visibility, network telemetry, firewall events, packet capture, threat intelligence, malware analysis, and investigation workflows.
For RSAC 2026, the team deployed the SOC in a Box architecture, connecting Endace full packet capture, Splunk Enterprise Security, Cisco XDR, Cisco Secure Firewall, Cisco Secure Access, Cisco AI Defense, ThousandEyes, Splunk Attack Analyzer, Cisco Secure Malware Analytics, Cisco Talos intelligence, and partner and community threat intelligence sources.
The scale was significant. The SOC observed more than 20,000 unique devices, over 63 million DNS requests, 29.5 billion packets captured by Endace, and more than 25 terabytes of packet data written to disk. Splunk Cloud aggregated telemetry and events across security and network infrastructure sources, creating a searchable operating environment for investigation, detection engineering, reporting, and automation.
That searchable evidence layer matters.
In a live event SOC, time is compressed. There is limited baselining. The environment is noisy. Many devices are unmanaged. Analysts need to move quickly from signal to evidence to decision. Splunk Enterprise Security helped provide a common workspace where detections, risk events, telemetry, investigation notes, and enrichment could come together.
One of the clearest examples was the SOC’s response to cleartext credentials.
Cleartext usernames and passwords continued to appear on the RSAC network through insecure or legacy protocols such as HTTP and unencrypted POP3. In prior years, this type of finding could require manual analyst work to identify the affected user, document the issue, notify the attendee, and close the case.
At RSAC 2026, the team advanced that workflow. Complex searches that originally supported dashboard visibility were converted into formal detections in Splunk Enterprise Security. Splunk ES automation rules linked those detections directly to a Splunk SOAR playbook. The playbook extracted the affected user information, sent a standardized notification, updated the finding disposition, and closed the case.
That automation saved more than nine hours of analyst time during the event. More importantly, it turned a repeatable operational problem into a repeatable security workflow.
This is where live event SOCs become especially valuable for product and detection teams. The network produces real telemetry, real edge cases, and real analyst friction. A detection is not just a search. It has to be understandable, actionable, routed correctly, enriched with the right context, and connected to an outcome.
The SOC also highlighted the importance of evidence-driven investigation. Endace full packet capture provided a forensic record of network activity, while Splunk Enterprise Security provided the environment for correlation, hunting, and reporting. Files reconstructed from network traffic could be routed to Splunk Attack Analyzer and Cisco Secure Malware Analytics for analysis, helping the team understand malware blast radius without overloading analysts or tools.
Encrypted traffic was another major theme. Encryption protects privacy, and the SOC does not decrypt attendee traffic. But defenders still need ways to identify suspicious behavior. Cisco Secure Firewall’s Encrypted Visibility Engine provided meaningful signals in encrypted sessions without decryption. Those signals could then be correlated with Splunk data, packet evidence, DNS activity, and other telemetry to support investigation and response.
The report also shows how broad the threat landscape has become. The SOC observed phishing and scam infrastructure, typo-squatting domains, malware investigations, accidental data exposure, insecure email, misconfigured access paths, exposed storage, and AI-related risk. In one case, an AI agent demonstration environment transmitted sensitive configuration and identity-related data without transport-level encryption.
That is an important lesson for every security team: AI is both a defensive opportunity and a new surface to secure.
At RSAC 2026, Cisco AI Defense helped provide visibility into generative AI application usage and helped protect on-premises AI models running in the SOC in a Box. At the same time, the SOC observed that AI and agentic applications can introduce risk when basic secure communication and identity controls are missed.
For Splunk Security, the larger takeaway is clear: the future of security operations depends on turning diverse telemetry into decision-ready workflows.
That requires more than collecting data. It requires detection engineering, normalization, enrichment, automation, evidence preservation, and analyst-centered workflow design. It also requires feedback from live operating environments where teams can see what actually helps analysts move faster and what creates friction.
RSAC 2026 helped prove several patterns that carry directly into the Agentic SOC:
- Use Splunk Enterprise Security as the analyst workspace and evidence system.
- Convert high-value searches into ES-native detections and findings.
- Use Splunk SOAR to automate repeatable, low-risk workflows.
- Preserve packet evidence so conclusions can be validated.
- Treat AI as decision support, not an accountability replacement.
- Keep humans in control of response decisions that affect users, availability, or trust.
After 10 years, the RSAC SOC continues to be more than an event security operation. It is a live validation environment for how modern SOCs can work: integrated telemetry, evidence-led investigation, automation where it reduces toil, and human judgment where it matters most. Our thanks to the engineers and analysts who made the SOC a success.
Download the full RSAC 2026 SOC Findings Report to see the architecture, metrics, investigations, lessons learned, and recommendations from the 10th year of the SOC.
Related Articles

High(er) Fidelity Software Supply Chain Attack Detection

