Working within the live Security Operations Center (SOC) at Cisco Live AMER provided valuable insights into the practical application of AI, detection, and response technologies, according to a product manager's recent account. The SOC at the event functions as a real-time security operation, integrating analysts, telemetry, detection mechanisms, and response workflows across the conference network.
The experience combined customer interactions with hands-on investigation within the SOC environment. By engaging with security operations teams and observing their workflows, the product manager identified common challenges such as investigation slowdowns, loss of context, and the need for manual data correlation. The direct involvement in the Cisco Live SOC allowed for a deeper understanding of these pain points through real-time investigations.
A key takeaway was that effective detection and response is fundamentally a workflow challenge rather than a singular product solution. Investigations often span multiple tools and data sources, beginning with a detection in a firewall, being enriched by XDR, requiring historical data from Splunk Enterprise Security, and potentially needing packet capture analysis. The analyst's role involves synthesizing this information to determine if a detection is a true positive or false positive, whether an action was blocked, and if an asset is compromised.
Artificial intelligence proved to be a significant aid in accelerating the investigation process. It helped in quickly orienting the analyst by providing intelligence, context, and initial hypotheses, which was particularly beneficial in an unfamiliar environment. While AI did not replace the analyst's investigative actions, it reduced the time needed to understand the situation, identify critical elements, and determine next steps. AI assisted in translating complex log data, normalizing timestamps, interpreting network addresses, summarizing packet evidence, and distinguishing between a rule match and an actual compromise.
Real-world investigations highlighted the importance of reaching clear, evidence-backed conclusions, even when no compromise was confirmed. These outcomes, such as a blocked connection with no evidence of compromise or a signature match identified as a likely false positive due to normal network behavior, are crucial. Such findings allow analysts to quickly dismiss benign alerts and focus on more significant threats, underscoring the value of efficient investigation workflows.
The synergy between Splunk Enterprise Security and XDR was evident throughout the investigations. Splunk Enterprise Security excelled in providing depth, enabling detailed searches across raw events, validation of timestamps, and examination of activity before and after a detection. XDR served as an effective starting point, offering hypotheses, key evidence, and analysis that connected related entities and detections.
The combined use of these tools facilitated a smoother investigative flow. XDR provided an overview of the investigation's scope, while Splunk allowed for deep dives into the details, corroborating XDR's findings with more granular evidence. This collaborative approach was particularly valuable for an analyst new to the environment, helping to quickly resolve numerous investigations with a high degree of confidence.
The experience underscored the need for seamless integration between investigation views and deep evidence search capabilities. The ideal scenario involves a unified experience where analysts can review all relevant data, extract supporting evidence, and reach conclusions rapidly and with confidence. This approach avoids forcing analysts to choose between an investigation map and data depth, instead combining their strengths for faster decision-making.
The product manager concluded that future detection and response products should be designed as connected investigation systems that minimize the "translation work" for analysts. AI can empower analysts to ask the right questions more quickly without diminishing their critical judgment. The goal is to build products that make complexity understandable, preserve evidence, respect analyst judgment, and transform customer challenges into improved workflows.






