惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
L
LangChain Blog
爱范儿
爱范儿
博客园_首页
Stack Overflow Blog
Stack Overflow Blog
MongoDB | Blog
MongoDB | Blog
博客园 - 三生石上(FineUI控件)
大猫的无限游戏
大猫的无限游戏
宝玉的分享
宝玉的分享
GbyAI
GbyAI
H
Help Net Security
A
About on SuperTechFans
Recent Announcements
Recent Announcements
Hugging Face - Blog
Hugging Face - Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
雷峰网
雷峰网
D
Docker
博客园 - Franky
有赞技术团队
有赞技术团队
G
Google Developers Blog

Cisco Blogs

Edge opportunity for service providers: Turn infrastructure into new services MRC and SRv6: How Foundational Networking Innovations Are Enabling the Next Generation of AI Supercomputers The SMB Marketing Reset: Winning Customer Trust in a Digital-First Economy Inside the SOC: AI-powered DNS defense against ransomware Our Path Forward Securing the Federal Digital Experience with Cisco ThousandEyes for Government Cisco at ONUG Dallas 2026: Securing the AI Data Center in the Agentic Era Cisco and Red Hat are powering intelligent core to edge: Red Hat Summit insights Building the Capabilities That Win: How Cisco Partners Can Lead in the SMB & Mid-Market Era How Two Hours Felt Bigger Than My To-Do List Announcing Foundry Security Spec Ace the CCIE Collaboration Lab: Success Tips from a TAC Engineer Turned CCIE Protecting Agents with Cisco AI Defense and Google Agent Development Kit Powering an Inclusive Future: Your guide to the Purpose Pavilion at Cisco Live Las Vegas The Infrastructure Behind the Mission: SOF Week 2026 Cisco Networking App Marketplace Partners at Cisco Live 2026 Beyond the Pilot: Building the Clinical Data Fabric for the Agentic Era Benchmarking scale-out AI fabrics with Cisco N9000 + AMD Pensando™ Pollara 400 NICs Month of Developer Productivity: Build and Forget The race to autonomous transport networks: A new study Lean IT, future-ready: How to save time and simplify wireless management with AI Reading Between the Pixels: Failure Modes in Vision Language Models Biochar’s triple win: Healthier soils, improved crops, and decarbonization Designing a Proactive Customer Journey Modernize your data center operations with Cisco Nexus Dashboard Why your automation stack needs Cisco Agentic Workflows Try Cisco AI Defense Explorer Edition in this hands-on lab From Bandwidth to Intelligence: How Cisco is Powering AI-Ready Networks Spotlight on digital transformation | FY25 Purpose Report Galaxy Mode is live: A limited-time look at what your Cisco AI Assistant and AgenticOps can already do
From Log Flood to Threat Signal: Cisco and Splunk Bring C...
Vignesh Sathiamoorthy · 2026-06-01 · via Cisco Blogs

Security teams can often find themselves staring at a wall of logs, runtime events, firewall alerts, and workload signals, knowing the answer is probably in there somewhere, but not having the time to examine the details.

Applications now span Kubernetes clusters, cloud workloads, data centers, and branches, while teams try to connect signals from workloads, users, agents, logs, and firewalls. Each signal can tell part of the story, but with vulnerabilities being exploited faster than ever, it is easy to lose time chasing noise instead of finding threats.

That is why Cisco is bringing richer product telemetry into Splunk, along with the detections and correlation needed to make that telemetry useful. As organizations build toward a hybrid mesh firewall architecture, Cisco provides deeper visibility from runtime workloads and advanced firewall logging, while Splunk helps turn that visibility into detection, investigation, and action.

Move from isolated alerts to a clear picture of workload risk

Because modern applications are dynamic across containers, Kubernetes workloads, and services, it’s not enough to get an alert that something happened. Teams need to know what workload did it, what process caused it, and whether that behavior was expected.

Cisco Isovalent Enterprise Platform provides runtime visibility across Kubernetes and Linux workloads, including process execution, network connections, file access, and workload identity. Splunk brings that telemetry into the SOC with purpose-built detections and correlation, helping analysts understand suspicious behavior in context. Now, teams can move from manually interpreting direct runtime events to acting on correlated, high-confidence detections inside the Splunk workflows they already use.

Get detections with detailed logs as a native firewall capability

As a high-volume telemetry source, security teams rarely have time to move beyond alerts and examine firewall logs looking for small changes, unexpected patterns, or subtle signs of attacker behavior. Now, in its latest software release, Cisco Firewall introduces a native advanced logging capability, giving customers detailed, structured logs for richer protocol-level detail.

Splunk turns that detail into usable detections and correlation, helping teams surface meaningful patterns in DNS, HTTP, FTP, connection behavior, anomalies, and inspection events without manually sorting. With custom detections and correlation, Splunk can help analysts identify patterns that basic logs may miss, such as command-and-control behavior, DNS tunneling, suspicious downloads, beaconing, or unusual protocol activity.

Detect threats faster, before the incident escalates

Many attacks are not obvious at the point of entry, so when prevention misses something, detection speed matters. This is where the combination of Cisco telemetry and Splunk analytics becomes especially valuable.

For example, in an environment where Kubernetes egress traffic is inspected by Cisco Secure Firewall, a compromised web-service pod suddenly spawns a shell and starts reaching out through DNS. Splunk detections using Isovalent telemetry can show the pod, process, timing, and destination, while Cisco Secure Firewall advanced logging adds context like unusual query patterns or abnormal response sizes. Together, these signals help analysts connect workload behavior to network behavior, investigate with confidence, and respond faster.

Over time, this means customers have the advanced ability to:

  • Detect: Less manual event stitching for faster threat detection
  • Investigate: Get better context to increase confidence to act 
  • Act: Respond faster across hybrid environments

Cisco and Splunk are making that possible by bringing deeper product telemetry and purpose-built detection together in one security workflow. To multiply this advantage, check out the advanced threat detection, investigation, and response with Cisco Firewall Promotional Splunk Capacity (FTD).


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram