By Andrew Merica,
Publication Date: 2026-10-08 15:00:00
At Splunk .conf26 in Denver, our team operated the live Security Operations Center (SOC) protecting more than 5,145 attendees representing 70 countries, including all attending Splunkers. We monitored multi-gigabit traffic while defending live capture the flag attack simulations and dynamic demo environments running throughout the venue. The real innovation was not the sheer volume of traffic, but the architecture of the SOC itself.
We built the event SOC around a multi-stage agentic pipeline:
- Live telemetry feeds Splunk Enterprise Security
- Autonomous triage agents accelerate Tier 1 analysis
- Cisco Cloud Control enforces confidence gates
- Human analysts make decisive response calls
In this model, the firewall acts as the stage one signal engine. Because the entire agentic workflow is capped by the quality of initial data, maximizing inspection depth without adding venue latency was paramount.
The event Network Operations Center (NOC) managed the venue network, providing our SOC…



