Cisco and Splunk deployed a first-of-its-kind closed-loop SOC at Cisco Live Amsterdam 2026, integrating Cisco XDR with Splunk Enterprise Security. The setup enabled Tier 1/2 analysts to handle complex investigations previously reserved for Tier 3, with automated incident synchronization between XDR and Splunk ES. The portable 'SOC in a Box' was deployed in 12 hours, capturing 130 billion packets and 6.96 billion logs across 21,000 attendees. Key innovations included unified incident management, role-based access via Duo Directory, closed-loop automation, and rapid analyst onboarding under one hour. The architecture also addressed BYOD constraints and encrypted traffic detection using Endace packet capture, Zeek logs, and sandboxing via Splunk Attack Analyzer and Cisco Secure Malware Analytics.

7m read timeFrom blogs.cisco.com
Post cover image
Table of contents
Harnessing the Power of Splunk SecurityThe Deployment: SOC in a BoxThe SOC Architecture: A “System of Systems”The StatisticsSOC Findings and Lessons LearnedAcknowledgements

Sort: