Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Splunk.conf: Cisco and Splunk expand agentic SOC vision | Computer Weekly

By Computer Weekly by By Computer Weekly
September 10, 2025
Home Uncategorized
Share on FacebookShare on Twitter


At Splunk’s annual .Conf event, the Cisco-backed observability and data security specialist made its first run at the agentic artificial intelligence (AI) enhanced security operations centre (SOC), unveiling two agent-powered security operations (SecOps) tools for users to explore.

In a Tuesday keynote address, Splunk security senior vice president and general manager Mike Horn said that SecOps must to evolve and the need to simplify workflows, accelerate and enhance SOC operations, and expand detection capabilities and threat visibility were clear.

Splunk Enterprise Security Essentials Edition and Splunk Enterprise Security Premier Edition – delivered within version 8.2 of the firm’s Enterprise Security (SEC) security information and event management (SIEM) solution – unify a number of security workflows in the threat detection, investigation and response (TDIR) sphere.

Essentials Edition unifies SEC 8.2 with Splunk AI Assistant in Security and is available today, while Premier goes a step further adding Splunk SOAR and Splunk UEBA, and enters controlled availability later in September.

Splunk and Cisco – which have made significant and speedy progress on technical integration since coming together in 2024 – claim that the new features will place agentic AI at the heart of the SOC in order to extend security intelligence across the network.

“Our security offerings unify detection, investigation, and response into a single, intuitive workspace, eliminating tool fragmentation and significantly boosting efficiency,” said Horn.

“Built-in AI can help cut alert noise and reduce investigation time from hours to minutes. Now every SOC can better position to stay ahead of advanced threats and empower analysts at every level.”

“With today’s increasingly sophisticated threats and sprawling attack surfaces, security teams can’t afford to waste time switching between fragmented tools and operating with siloed visibility,” added Michelle Abraham, research director for security and trust at IDC.

“By integrating multiple security capabilities into a single, cohesive environment, security platforms empower organisations to move from reactive to proactive security, streamlining workflows, improving detection and response, and ultimately reducing risk.”

In addition to this, parent Cisco plans to release a number of additional AI features to power the agentic SOC, with the intent of enabling cyber pros to keep focus on more strategic aspects of their roles while agent bots sift the raw security data and perform proactive, autonomous SecOps.

Some of the agentic capabilities in development include triaging to evaluate, prioritise and explain security alerts; malware reversal to explain malicious scripts; playbook authoring to translate natural language intent into functional SOAR playbooks; response importer, using multi-modal large language models (LLMs) to import standard operating procedures into security response plans; detection library to help turn detections from hypotheses to production, and personalised detection SPL generator to personalise detections within the library to align with customer SOC environments.

Additionally, Splunk expanded the integration of Cisco Isovalent Runtime Security (eBPF) into Splunk, enhancing workload visibility and better pinpointing issues, and announced that Splunk Cloud Platform’s Federated Search for Amazon S3 and Security Analytics and Logging (SAL) will allow cyber pros to run security analytics on Cisco firewall logs stored in SAL directly, without needed to ingest.

These features and capabilities will come on-stream within the next 12 months.

Era of simplification

Speaking to Computer Weekly at .Conf, James Hodge, Splunk GVP and chief strategy advisor for EMEA, said that the advent of the agentic SOC heralded an era of simplification for cyber security professionals, describing the underlying technology as “phenomenally complicated” in many ways.

“I was really encouraged, and really excited this week, because from a user perspective we’re simplifying all of that. We’re abstracting that complexity, and just surfacing what you need,” said Hodge.

“For anyone that works with it, the word I’d use is liberating, because you’re no longer battling with tools or techniques, you’re able to go and get that question answered so you can go and progress,” he added. “For people, it means they can get on with doing what they’re paid to do.”



Source link

By Computer Weekly

By Computer Weekly

Next Post
Wells Fargo CEO says Trump is entitled to be vocal about the Fed

Wells Fargo CEO says Trump is entitled to be vocal about the Fed

Recommended.

Appfire Launches Cloud Advantage Alliance to Optimize Atlassian Ecosystem Transitions and Drive Customers’ Sustained Success in the Cloud

Appfire Launches Cloud Advantage Alliance to Optimize Atlassian Ecosystem Transitions and Drive Customers’ Sustained Success in the Cloud

April 7, 2025
Interactive Voice Response (IVR) Software Market is Segmented by Type (Monthly Subscription, Annual Subscription), by Application (SME (Small and Medium Enterprises), Large Enterprise)

Interactive Voice Response (IVR) Software Market is Segmented by Type (Monthly Subscription, Annual Subscription), by Application (SME (Small and Medium Enterprises), Large Enterprise)

January 17, 2025

Trending.

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

October 6, 2025
Cloud Computing on the Rise: Market Projected to Reach .6 Trillion by 2030

Cloud Computing on the Rise: Market Projected to Reach $1.6 Trillion by 2030

August 1, 2025
Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

July 14, 2025
The Ultimate MSP Guide to Structuring and Selling vCISO Services

The Ultimate MSP Guide to Structuring and Selling vCISO Services

February 19, 2025
Translators’ Voices: China shares technological achievements with the world for mutual benefit

Translators’ Voices: China shares technological achievements with the world for mutual benefit

June 3, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio