At Splunk .conf26 in Denver, our team operated the live Security Operations Center (SOC) protecting more than 5,145 attendees representing 70 countries, including all attending Splunkers. We monitored multi-gigabit traffic while defending live capture the flag attack simulations and dynamic demo environments running throughout the venue. The real innovation was not the sheer volume of traffic, but the architecture of the SOC itself.
We built the event SOC around a multi-stage agentic pipeline:
- Live telemetry feeds Splunk Enterprise Security
- Autonomous triage agents accelerate Tier 1 analysis
- Cisco Cloud Control enforces confidence gates
- Human analysts make decisive response calls
In this model, the firewall acts as the stage one signal engine. Because the entire agentic workflow is capped by the quality of initial data, maximizing inspection depth without adding venue latency was paramount.
The event Network Operations Center (NOC) managed the venue network, providing our SOC firewalls with dedicated SPAN feeds directly from their core switches. By running Secure Firewall 10, our physical and virtual firewalls delivered wire-speed Snort 3 detection, Encrypted Visibility Engine telemetry, and protocol anomaly tracking with zero impact on production traffic. Behind the scenes, Cisco Cloud Control unified our on-premises and Cloud-Delivered Firewall Management Center (FMC) deployments into a single console, keeping analysts focused squarely on active investigations.
Tapping the Wire
In modern enterprise networks where encrypted traffic is the standard default, traditional 5-tuple firewall rules and static port filters generate overwhelming noise while missing real adversary behavior. To feed high context data into Splunk Enterprise Security (ES) and empower autonomous agents, firewall telemetry must evolve from raw connection logs into high value behavioral stories.
Inside Cisco Cloud Control, that story comes together in Unified Events. Rather than forcing firewall administrators to jump between disjointed dashboards and raw syslog streams, Unified Events unifies the entire spectrum of firewall telemetry into a single cohesive view. It captures standard Connection events to track application identity and byte volumes, correlates them with Security related connection events from domain filtering and TLS policies, and layers on deep Intrusion events from Snort 3. When suspicious payloads cross the wire, network File events and sandbox Malware verdicts attach directly to the flow, while underlying Troubleshoot events provide immediate operational context if packets drop or engines strain.
This unified lens transforms threat detection from atomic alerts into meaningful security context. Snort 3 prioritizes high-impact classifications and groups related events across multiple endpoints, instantly revealing lateral movement and active scanning. For encrypted sessions, the Encrypted Visibility Engine (EVE) inspects Client Hello handshakes, packet lengths, and timing dynamics directly on the wire. This identifies malicious processes and command and control traffic with high confidence, all without the performance or privacy overhead of SSL decryption. Meanwhile, monitoring outbound byte surges catches data staging in real time, cleartext protocol audits uncover exposed credentials before they can be abused, and DNS sinkholing delivers a zero false positive alert the second an infected device tries to call home.
Advanced Logging to Splunk & Tuning
The core operational feedback loop starts with high fidelity data delivery. Instead of overwhelming the SOC with unstructured syslog dumps, our firewalls stream structured telemetry directly into Splunk Enterprise Security using Advanced Logging in JSON format. This supplies Splunk ES with standardized Common Information Model fields on arrival. EVE process tags, Snort 3 classifications, Talos threat scores, and DNS sinkhole indicators arrive fully packaged, giving Splunk AI Triage Agents immediate and undisputed ground truth.
This structured telemetry drives a fundamental shift in daily operations by moving security analysts beyond isolated alerts and atomic findings into unified Investigations. Rather than chasing hundreds of disconnected notable events, Splunk ES combines rich firewall signals with endpoint, identity, and cloud telemetry to assemble a single incident narrative. Autonomous triage agents can trace an attacker from their initial exploit attempt to encrypted command and control beaconing in minutes.
While Splunk drives active investigations in the SOC, administrators maintain firewall health directly within Cloud Control. Inside Security, AgenticOps applies AI intelligence to firewall management by analyzing rule hit counts, pruning shadow rules, and optimizing policy evaluation order. This slashes the SIEM ingest tax by eliminating redundant log volume before it ever leaves the firewall, while keeping compute resources focused on deep behavioral inspection.
The Horizon: Cisco Cloud Control & AI Canvas
Security is now natively built into Cisco Cloud Control, the unified operations platform that brings Networking, Security, Observability, and Cloud into one consistent environment. Without replacing individual product controllers, Cisco Cloud Control unifies inventory, topology, actions, identity, and workflows into a single operational interface. This supports an AgenticOps model where governed AI agents help operators correlate cross-domain telemetry, investigate emerging issues, and take decisive action across the entire IT estate.
Central to this experience is AI Canvas, a shared workspace where human operators and AI agents collaborate to resolve complex incidents. Rather than starting from scratch, administrators can prompt AI Canvas for situational best practices, such as asking how to optimally structure, filter, and stream Cisco Secure Firewall logs into Splunk. AI Canvas unifies telemetry from Cisco platforms and organizational knowledge into a single, structured investigation. It preserves the entire chain of questions, evidence, and decisions so teams collaborate seamlessly without losing context.
This bridges the traditional divide between Network Engineering and the SOC. When firewall administrators design inspection with intent, leverage AgenticOps to optimize firewall health, and stream structured telemetry into Splunk, they elevate the entire security organization.
Check out the other blogs by our Agentic SOC team at .conf26.
Cisco Cybersecurity Viewpoints
Where security insights and innovation meet. Read the e-book, see the video, dive into the infographic and more…
Get expert perspectives now




