Splunk .conf26: Tracking the Triage Agent in the Agentic SOC

Source: Cisco Blogs•

Splunk .conf26: Tracking the Triage Agent in the Agentic SOC

How Cisco used Splunk as the SOC data platform at .conf26 to unify security telemetry and track the Splunk AI Triage Agent with human-validated workflows.

Splunk .conf26 gave us the opportunity to operate a live Agentic Security Operations Center (SOC) in the middle of the Splunk community. We brought together Cisco, Splunk, and Endace telemetry, a blended analyst team, and the Splunk Enterprise Security (ES) AI Triage Agent to show how a modern SOC can move from live data to human-validated decisions.

The event environment was noisy, temporary, and highly dynamic. Devices, identities, applications, and network behaviors changed throughout the day. That made .conf26 a useful proving ground for a simple operating principle: agents can prepare the work, but people must be able to inspect the evidence and decide what happens next.

Protect First Then Innovate

The first mission of an event SOC is to protect the network and the people depending on it. The network must work, the customer experience must be preserved, and investigations must move quickly without turning every unusual event into an incident.

At .conf26 activity that would be alarming on a corporate network could be normal in a conference, training, demo, or research environment. The SOC had to determine what activity meant in context. Splunk provided the evidence layer for that decision, while analysts remained responsible for validation and response.

Splunk ES as the SOC data platform

Splunk ES served as the primary analyst workspace and evidence system for the SOC. It centralized detections, risk context, findings, investigations, dashboards, SPL searches, and analyst workflows so the team could work from a common operational picture.

The unified platform also gave the team a practical place to measure agentic work. The same data used to investigate findings could show how many queries the Triage Agent generated, how much evidence it considered, what confidence it returned, and how its recommendations moved into human review.

The Telemetry

The data became useful when it was normalized, correlated, searched, and enriched into evidence that an analyst could trust. The SOC combined security telemetry with network and identity context from the convention center environment.

  • Cisco Duo for account and login information.
  • Cisco Secure Endpoint for endpoint activity and security events.
  • Cisco Firewall Threat Defense for perimeter and threat telemetry.
  • Convention-center provider for NOC DHCP and DNS data for network assignment, name resolution, and device context.
  • Endace Zeek, Suricata IDS, and PCAP data for network detection and packet-level investigation. Endace is one of Cisco’s preferred partners for event SOC deployments.
  • Splunk Exposure Analytics for exposure and risk context.
  • Splunk Attack Analyzer for automated analysis of suspicious files, URLs, and other artifacts.

Together, these sources gave analysts a way to connect who was involved, what happened on an endpoint, how activity moved across the network, which infrastructure was exposed, and what additional analysis was available. The goal was not to make every signal a high-cost alert. Different signals could support detection, risk context, hunting, or a focused investigation.

A blended analyst team

The technology was only one part of the SOC. Splunk, Cisco, and Endace employees worked together across the roles needed to run and improve a live security operation.

  • Tier 1 analysts monitored the queue, reviewed initial findings, and handled first-level triage.
  • Tier 2 analysts investigated more complex findings and correlated activity across the available data sources.
  • Tier 3 analysts performed deeper threat hunting and escalated the most complex or consequential activity.
  • Detection Engineers tuned existing content and developed detections as the team learned more about the event environment.
  • The Splunk Threat Research Team contributed threat research, hunting expertise, and guidance for analyzing emerging activity.

This structure gave the AI Triage Agent the right operating context. The agent could prepare findings and surface supporting evidence, while analysts with different levels of specialization validated the result, pursued deeper questions, and fed improvements back into detections and workflows.

Building the Triage Agent Dashboard in an Afternoon

Once the data was flowing and the agent was active, we built an operations dashboard in an afternoon. It tracked the finding lifecycle, agent activity, confidence, analysis coverage, suggested dispositions, and the handoff to analysts.

The dashboard made the agent’s work visible to the SOC. Over the course of the conference, it reported 1,503 AI agentic events, 7,605 SPL queries generated and run, 26,207 pieces of evidence considered, 14,279 hypotheses considered, and 11,250 threat intelligence lookups. It also showed 94% triage analysis coverage, confidence bands, suggested dispositions, and current finding status.

Those metrics were useful because they supported a shared conversation about how the agent was operating. Analysts could see whether the agent was active, understand the scale of its work, inspect the balance between automated preparation and analyst action, and identify where additional tuning or investigation was needed in real-time.

Prepared. Decided. Proven. The Triage Agent is designed to investigate findings as they appear in an analyst queue. It gathers relevant context, evaluates the finding, and provides a suggested disposition, rationale, and recommended next steps before a human analyst takes ownership.

That workflow gives analysts a stronger starting point without removing accountability. Agents can perform repetitive investigative work at machine speed. Analysts review the recommendation, drill into the underlying data, and decide whether the finding should be closed, escalated, investigated further, or acted on.

For the .conf26 deployment, human validation was part of the design. The team preserved a path from telemetry to finding, from finding to agent analysis, and from agent analysis to an analyst decision. The result was an explainable operating model that could be reviewed, tuned, and reused.

Dashboard Snapshot

The following values are a snapshot from the displayed Triage Agent operations dashboard and should be read as event-environment observations rather than product benchmarks.

Sharing Our Experiences

A core mission of the event SOC is “Educate”, sharing our experiences. Customers who toured the SOC saw a working example of how a data platform, security analytics, partner telemetry, AI-assisted triage, and human analysts can operate together.

  • Splunk Enterprise Security provided a common analysis surface for findings, risk, investigations, dashboards, and evidence.
  • The agentic workflow accelerated triage and evidence gathering while analysts retained responsibility for decisions and governed response.
  • The breadth of telemetry made it possible to pivot from access and identity context to endpoint, firewall, DNS, Zeek, Suricata, PCAP, exposure, and artifact analysis as needed.

What We Learned

Data onboarding is the force multiplier. Once the right security, network, and identity data was available in Splunk, new searches, panels, and workflows could be built quickly.

Agent visibility matters as much as agent availability. SOC teams need to understand what the agent is doing, how much of the queue it covers, what evidence it uses, how confident it is, and where analysts accept or challenge its recommendations. To be clear, this was just a start, but it gave us ideas for improvements which could then be fed back to our product teams.

The most practical model is human-led and evidence-based. The agent prepares the work, analysts validate it, and the platform preserves the evidence that connects the two. That model gives the SOC a way to expand automation without giving up oversight or accountability.

Acknowledgements

Our thanks to the Splunk, Cisco, and Endace employees who operated the SOC, supported setting up the required hardware, deployed and managed the data integrations, developed detections, investigated findings, and helped customers understand the workflow. We also recognize the Splunk Threat Research Team and the practitioners who provided the human expertise behind the operation.

I am honored to have been part of this great team at Splunk’s own main event of the year! Check out the other blogs by our fellow humans in the Agentic SOC.

What this article says