{"id":98014,"date":"2026-07-07T18:21:12","date_gmt":"2026-07-07T18:21:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/98014\/"},"modified":"2026-07-07T18:21:12","modified_gmt":"2026-07-07T18:21:12","slug":"building-the-agentic-soc-at-cisco-live-americas-2026","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/98014\/","title":{"rendered":"Building the Agentic SOC at Cisco Live Americas 2026"},"content":{"rendered":"<p>Building on the Cisco Live EMEA SOC, Cisco Live Americas placed the Security Operations Center (SOC) and Network Operations Center (NOC) at the center of the World of Solutions, demonstrating the power of Cisco in bringing Networking, Security and Observability together.<\/p>\n<p>Like any successful SOC, planning starts with a close partnership with the NOC, which deploys a team of engineers to build the network in the weeks ahead of the conference. The Cisco Live Americas Agentic SOC architecture shows how a \u201cOne Cisco\u201d approach brings different security tools together to eliminate data silos, in close partnership with the NOC. This directly supported our three missions.<\/p>\n<p>To Protect: agentic workflows helped analysts triage and validate incidents faster<br \/>\nTo Educate: they helped turn complex investigations into clear, human-readable narratives for tours and post-event learning. In the agentic SOC, we trained over a dozen new analysts, empowering them to as Tier 2 analysts, with agentic workflows<br \/>\nTo Innovate: The live environment is an opportunity to pressure test how Cisco Security and Splunk Security can work together in a next-generation SOC where AI assists, evidence grounds the decision, and humans remain in control<\/p>\n<p style=\"text-align: center;\">Watch the recording of the live interview at the SOC on Cisco TV.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-medium_large wp-image-494138\" data-lazy-type=\"image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1-CLAMER2026SOC-768x576.webp\" alt=\"\" width=\"768\" height=\"576\"\/><\/p>\n<p>The SOC at Cisco Live was set up in just two days, thanks to <a href=\"https:\/\/www.cisco.com\/site\/us\/en\/products\/security\/event-soc-report.html\" rel=\"nofollow noopener\" target=\"_blank\">lessons learned and continuous evolution<\/a>. The \u2018SOC in a Box\u2019 is on the left.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-medium_large wp-image-494139\" data-lazy-type=\"image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/2-CLAMER2026SOCinaBox-768x432.webp\" alt=\"\" width=\"768\" height=\"432\"\/><\/p>\n<p>The SOC in a Box also included a UCS M8 with three NVIDIA GPUs, giving the team room to test local and protected AI workflows inside the event environment. That mattered because SOC data can include sensitive details. AI Defense and DefenseClaw provided guardrails and auditability around these workflows, helping the team inspect prompts, responses, and agent actions rather than treating AI as a black box.<\/p>\n<p>The SOC Architecture<\/p>\n<p>We connected developing agentic capabilities into a governed SOC workflow so every incident could be summarized, validated, investigated, and audited with a human still in control.<\/p>\n<p>For Cisco Live AMER, we treated agentic AI as an auditable review layer across the SOC, not as a replacement for analysts. Incidents still started from real telemetry and detections, but agentic workflows helped summarize what happened, identify supporting evidence, recommend next steps, and preserve the reasoning for human review. Analysts remained accountable for closure, escalation, and any action that could affect the event network.<\/p>\n<p>Splunk Enterprise Security served as the evidence and investigation plane. When agentic workflows produced a summary or recommendation, analysts could validate the underlying events, searches, detections, malware analysis, and packet evidence rather than relying on an uncited AI answer. Where possible, agentic workflow activity and guardrail events were made searchable so the team could review not just the conclusion, but how the conclusion was reached.<\/p>\n<p>Cisco XDR provided the incident narrative layer for frontline analysts. Attack Storyboard and Verification helped convert correlated detections into a guided explanation of what happened, which entities were involved, and whether the available evidence supported escalation, closure, or continued monitoring. Every incident could receive agentic review, but agentic review did not mean autonomous response. The workflow was deliberately human-in-the-loop: agents summarized and recommended; analysts validated and decided.<\/p>\n<p>Firepower SnortML and Encrypted Visibility Engine helped answer a critical question in an event SOC: what can the network tell us even when endpoints are unmanaged and much of the traffic is encrypted? These detections gave the SOC high-value signals that could be correlated in XDR and validated in Splunk.<\/p>\n<p>Incidents were investigated in Splunk Security, with threat intelligence provided by Cisco Talos, and licenses donated by\u202f <a href=\"https:\/\/www.alphamountain.ai\/\" target=\"_blank\" rel=\"noopener nofollow\">alphaMountain<\/a>, <a href=\"https:\/\/pulsedive.com\/\" target=\"_blank\" rel=\"noopener nofollow\">Pulsedive<\/a>, and <a href=\"https:\/\/www.stealthmole.com\/\" target=\"_blank\" rel=\"noopener nofollow\">StealthMole<\/a> along with community sources.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-medium_large wp-image-494140\" data-lazy-type=\"image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/3-CLAMER26SOCArchitecture-768x431.webp\" alt=\"\" width=\"768\" height=\"431\"\/><\/p>\n<p>Telemetry creates incidents. Agents accelerate understanding. Splunk grounds the evidence. Cisco XDR guided the incident narrative. AI Defense and DefenseClaw govern the workflow. Humans make the decision. The whole process can be reviewed.<\/p>\n<p>Agentic SOC: Incident -&gt; Agentic Review -&gt; Evidence Summary -&gt;&#13;<br \/>\nHuman Validation -&gt; Action \/ Close -&gt; Audit<\/p>\n<p>Agentic Capability<br \/>\nQuestion It Helped Answer<\/p>\n<p>Firepower SnortML + Encrypted Visibility Engine<br \/>\nWhat is the network telling us, even through encrypted traffic?<\/p>\n<p>XDR Attack Storyboard \/ Verification<br \/>\nWhat happened, and does the incident require action?<\/p>\n<p>Splunk Enterprise Security Triage Agent<br \/>\nWhat does the evidence say?<\/p>\n<p>AI Studio + Endace<br \/>\nWhat packet evidence proves or disproves the hypothesis?<\/p>\n<p>Splunk Attack Analyzer AI Reversing Agent<br \/>\nWhat does this file or URL do?<\/p>\n<p>Foundation AI with Cisco XDR workflows<br \/>\nHow do we summarize and document the investigation?<\/p>\n<p>AI Defense + DefenseClaw<br \/>\nHow do we inspect, guardrail, and audit agentic workflows?<\/p>\n<p>The SOC team used <a href=\"https:\/\/duo.com\/docs\/duo-central\" target=\"_blank\" rel=\"noopener nofollow\">Duo Central<\/a> for Single Sign-On access to the tools, both on-premises and in the cloud, executing from the first <a href=\"https:\/\/blogs.cisco.com\/security\/black-hat-asia-2025-identity-intelligence\" rel=\"nofollow noopener\" target=\"_blank\">customer experience at Black Hat<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-medium_large wp-image-494141\" data-lazy-type=\"image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/4-DuoDirectory-768x461.webp\" alt=\"\" width=\"768\" height=\"461\"\/><\/p>\n<p>By leveraging cloud-based solutions like <a href=\"https:\/\/www.cisco.com\/site\/us\/en\/products\/security\/xdr\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">XDR<\/a> and <a href=\"https:\/\/www.splunk.com\/en_us\/products\/splunk-cloud-platform.html\" target=\"_blank\" rel=\"noopener nofollow\">Splunk Cloud<\/a>, this also minimized the amount of work that was needed in a very tight setup window. Configurations and other data were already ready to go from previous events as well, including dashboards in Splunk. The SOC manager dashboard was used to track status of Agentic AI assisted incident investigations and escalations.<\/p>\n<p>There were some use cases where no human involvement was necessary, such as when an attendee\u2019s device or accounts were found to be compromised or unsecure, the SOC team used automation to notify the attendee with Endace and Splunk SOAR, resolving the Incident without human intervention.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-medium_large wp-image-494142\" data-lazy-type=\"image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/5-SplunkSOAR-768x421.webp\" alt=\"\" width=\"768\" height=\"421\"\/><\/p>\n<p>The Splunk Packet Peekers Prize Board was the most popular for attendees to view (and hope their account was not one of the redacted on the dashboard).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-medium_large wp-image-494143\" data-lazy-type=\"image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/6-SplunkESPasswordintheClear-PacketPeekersPrizeBoard-768x399.webp\" alt=\"\" width=\"768\" height=\"399\"\/><\/p>\n<p>The Statistics<\/p>\n<p>Statistics are always a popular part of the SOC Tours. Below are the stats from this year\u2019s event. In addition, the perimeter firewalls of the NOC blocked over 10 million external attempts to attack the network, with those logs added to the SOC Splunk Enterprise Security platform.<\/p>\n<p>Year<br \/>\n2026<br \/>\n2025<\/p>\n<p>Attendees (Cisco Live)<br \/>\n20,000+<br \/>\n22,000+<\/p>\n<p>Total packets captured (Endace)<br \/>\n202.9 billion<br \/>\n99.5 billion<\/p>\n<p>Total logs captured (Splunk)<br \/>\n5.6 billion<br \/>\n4.5 billion<\/p>\n<p>Total sessions (Endace)<br \/>\n1.74 billion<br \/>\n1.49 billion<\/p>\n<p>Total unique devices<br \/>\n62,790 (DHCP)<br \/>\n37,052 (DNS)<\/p>\n<p>Total packets written to disk (Endace)<br \/>\n199 TB<br \/>\u2013 100 TB IPv6<br \/>\u2013 89 TB IPv4<br \/>\u2013 4 GB non IP<br \/>\n78.9 TB (IPv4 only)<\/p>\n<p>Total logs written to cloud (Splunk)<br \/>\n7.4 terabytes (added perimeter firewall logs)<br \/>\n1.99 terabytes<\/p>\n<p>Peak bandwidth utilization (Endace)<br \/>\n10 Gbps (saturated)<br \/>\n4.85 Gbps<\/p>\n<p>DNS Requests (Cisco)<br \/>\n270.4 million \/ 60.1k blocked<br \/>\n261.3 million \/ 28.3k blocked<\/p>\n<p>Total clear text username\/passwords (Endace)<br \/>\n43,322<br \/>\n2,256<\/p>\n<p>Unique devices \/ accounts with clear text usernames \/ passwords (Endace)<br \/>\n686<br \/>\n97<\/p>\n<p>Files sent for malware analysis (Endace)<br \/>\n2.392 million 740,172 file objects reconstructed by Endace<br \/>\u2013 23,368 sent to Splunk Attack Analyzer<br \/>\u2013 Sent to Secure Malware Analytics<br \/>\n740,172 file objects reconstructed by Endace<br \/>\u2013 42,813* sent to Splunk Attack Analyzer<br \/>\u2013 13.05k sent to Secure Malware Analytics<br \/>* De-duplication started afternoon of 11 June 2025, as part of tuning<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-medium_large wp-image-494144\" data-lazy-type=\"image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/7-CLAMER26SOCTour-768x307.webp\" alt=\"\" width=\"768\" height=\"307\"\/><\/p>\n<p>Agentic SOC Findings and Lessons Learned<\/p>\n<p>Check out the blogs by the engineers who worked inside the SOC at Las Vegas:<\/p>\n<p>Acknowledgements<\/p>\n<p>Our thanks to the engineers who made the first Agentic SOC at Cisco Live a success, by protecting the network and educating attendees (and you).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-medium_large wp-image-494145\" data-lazy-type=\"image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/8-CLAMER2026SOCteam-768x460.webp\" alt=\"\" width=\"768\" height=\"460\"\/><\/p>\n<p>Network Operations Center Liaisons<\/p>\n<p>Freddy Bello, Andy Phillips and Scott Neuman<\/p>\n<p>Cisco Security and Splunk SOC Team<\/p>\n<p>SOC in a Box hardware: Aditya Sankar<br \/>\nSplunk Security Integrations: Ivan Berlinson, Paul Pelletier and Josh Wilson<br \/>\nSplunk Security: Drew Church, Erik Dove, Todd Dow, Daniel Christiansen, Logan Buntrock<br \/>\nCisco Security: Lou Norman and Oscar Ramirez<br \/>\nAnalysts: John Park, Abhishek Dubey, Manoj Sudhakara, Pujan Trivedi, Bilal Qamar, Michelle Hermosillo, Ray Aragon, Kellie Cottingame, Alfredo Jurado, Jeremy Stanley, Chris Perkins, Paul Jeffery, Chris Lijoi, Adam Alkishawi, Maurali Ananth, Bill Radford, Brian Rees and Chris Ochia-Belen<br \/>\nRemote support: Adam Kilgore, Kenneth Bouchard, Aditya Raghavan, Chris Anderson, Kevin Wofford<\/p>\n<p>Endace SOC Team<\/p>\n<p>Cary Wright, Barry \u2018Baz\u2019 Shaw, Stephen Donnelly, Elliott Hinson and Michael Morris<\/p>\n","protected":false},"excerpt":{"rendered":"Building on the Cisco Live EMEA SOC, Cisco Live Americas placed the Security Operations Center (SOC) and Network&hellip;\n","protected":false},"author":2,"featured_media":98015,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,1763,34783,1765,1768,1770,1771,1772,313,40924,40925,23155,21767,1780,51161,1781,51162],"class_list":["post-98014","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-cisco-breach-protection","tag-cisco-live","tag-cisco-secure-access","tag-cisco-security-cloud","tag-cisco-talos","tag-cisco-user-protection","tag-cisco-xdr","tag-cybersecurity","tag-network-operations-center","tag-noc","tag-security-operations-center","tag-soc","tag-splunk","tag-splunk-cloud","tag-splunk-enterprise-security","tag-thousandeyes"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/98014","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=98014"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/98014\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/98015"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=98014"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=98014"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=98014"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}