惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
C
CERT Recently Published Vulnerability Notes
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
C
CXSECURITY Database RSS Feed - CXSecurity.com
AWS News Blog
AWS News Blog
V
Vulnerabilities – Threatpost
T
Tenable Blog
P
Proofpoint News Feed
C
Check Point Blog
T
The Exploit Database - CXSecurity.com
F
Full Disclosure
P
Privacy & Cybersecurity Law Blog
美团技术团队
U
Unit 42
C
Cyber Attacks, Cyber Crime and Cyber Security
阮一峰的网络日志
阮一峰的网络日志
Simon Willison's Weblog
Simon Willison's Weblog
量子位
AI
AI
Spread Privacy
Spread Privacy
Help Net Security
Help Net Security
Know Your Adversary
Know Your Adversary
IT之家
IT之家
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
P
Proofpoint News Feed
Recent Commits to openclaw:main
Recent Commits to openclaw:main
L
LangChain Blog
I
Intezer
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
月光博客
月光博客
Recorded Future
Recorded Future
O
OpenAI News
WordPress大学
WordPress大学
Microsoft Security Blog
Microsoft Security Blog
J
Java Code Geeks
Y
Y Combinator Blog
Engineering at Meta
Engineering at Meta
S
Security @ Cisco Blogs
Recent Announcements
Recent Announcements
P
Privacy International News Feed
NISL@THU
NISL@THU
MongoDB | Blog
MongoDB | Blog
W
WeLiveSecurity
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
博客园 - Franky
Cyberwarzone
Cyberwarzone
H
Hacker News: Front Page

Security @ Cisco Blogs

Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026 Uplevelling Black Hat Threat Hunters Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia Cisco Secure Access with MCP Infrastructure at Black Hat Asia 2026 The Essence of Black Hat – Collaboration with Partners Black Hat Asia 2026: A Decade in Singapore Black Hat Asia 2026: Threat Hunters’ Corner Unveiling the Power of Integration: XDR, Splunk, Corelight, Arista and Palo Alto Networks in Action at Black Hat Asia Security in the Post-Mythos Era Cisco SASE with Meraki: Get in the Fast Lane to SASE Extending Zero Trust Across the Agentic AI Workflow Strengthening the Foundation: A Predictable, Customer focused Response to AI-Accelerated Vulnerability Discovery Quantum Resilience Needs a Common Language. Here’s Where to Start. Security at Cisco Live: Going Shields Up for the Agentic Era Identity Elevated: A New Unified Identity Experience in Cisco Cloud Control Security Needs a New Operating Model Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection Cisco Secure Access and Island Browser Enable Zero Trust Everywhere Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense Cisco Secure Access and Microsoft Edge for Business Integration Why Network Segmentation Projects Fail: Four Patterns Cisco’s Risk-Based Vulnerability Disclosure in the Age of AI Enhancing Cisco Secure Email Gateway: Safer Clicks and Cleaner Files AI-generated reporting: Lessons learned from Cisco Talos Incident Response Inside the SOC: AI-powered DNS defense against ransomware Security Insights: A Threat-First View for the Platform That Enforces Access From Strategy to Architecture: How Cisco is Building a Quantum-Safe Future AI-Ready, Simpler, and More Secure WAN: Cisco SD-WAN Innovations Designing for What’s Next: Securing AI-Scale Infrastructure Without Compromise Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap Mobile World Congress 2026: AI-powered Network Security AI-powered Network Security at the Mobile World Congress 2026 SNOC Inside the Mobile World Congress 2026 SOC: Detecting Shadow Traffic with Firepower 6100 Data Optimization in Security: A Splunk Architect’s Perspective Inside the Talos 2025 Year in Review: A discussion on what the data means for defenders Zero Trust for Agentic AI: Safeguarding your Digital Workforce The Agent Trust gap: What Our Research Reveals About Agentic AI Security Meet Your Incident Responders
Powering MWC Barcelona – Building a Unified SOC and NOC with Splunk in Record Time
2026-04-09 · via Security @ Cisco Blogs

Mobile World Congress (MWC) Barcelona is one of the most demanding environments for network and security operations. With thousands of attendees, unmanaged devices, and applications interacting in real time, operational visibility and threat detection must function flawlessly.

For the 2nd year, the Cisco team leveraged Splunk, in addition to its other security products, to deliver a unified Security Operations Center (SOC) and Network Operations Center (NOC) experience. Together, we used Splunk as the central data platform and integrating telemetry across a broad set of Cisco technologies.

What made this deployment particularly notable was not just the breadth of integrations, but the speed and flexibility with which we operationalized the environment.

Cisco booth setup
People getting the Cisco booth in preparation for Mobile World Congress 2026

The Architecture: A Unified Operations Platform

At the core of the deployment was Splunk Cloud, acting as the single pane of glass for both SOC and NOC workflows.

We ingested data from multiple Cisco platforms, including:

MWC 2026 NOC
The SOC and NOC area at Mobile World Congress 2026 

This architecture allowed us to converge traditionally siloed operational domains into a single analytics layer, enabling faster correlation between network events and security incidents.

MWC 2026 SOC dashboards
Clockwise from the upper left quadrant: Firepower in Security Cloud Control, Splunk Cloud dashboard for MWC, Splunk Enterprise Security Mission Control and Cisco XDR.

Building NOC Dashboards in an Afternoon

One of the most impactful outcomes was how quickly we were able to deliver operational visibility following various requests from other teams present at the event.

Using Splunk’s data platform and visualization capabilities, we were able to build a fully functional NOC dashboard in just a few hours. The dashboard provided:

  • Real-time network usage and availability
  • Client connectivity metrics across wireless and wired environments
  • Application usage indicators

Because all telemetry was collected within Splunk, creating meaningful dashboards required minimal transformation work. This highlights a key advantage of using a unified data platform: once ingestion is solved, insights can follow quickly.

MWC 2026 Cisco space dashboard
One of the dashboards built using Splunk to track Cisco Spaces users across the venue.

Bridging SOC and NOC: From Visibility to Context

Traditionally, SOC and NOC teams operate in parallel, often using separate tools and datasets. At MWC, we intentionally broke down that barrier.

By leveraging Splunk as the common platform:

  • NOC events (e.g., latency spikes, usage trends) could be correlated with
  • SOC signals (e.g., anomalous traffic patterns, threat detections)

This convergence enabled faster root cause analysis and reduced mean time to resolution (MTTR), particularly in scenarios where performance issues or traffic anomalies had potential security implications.

A First: Deploying the Cisco 6160 Firewall in a Public Event

A standout aspect of this deployment was the use of the Cisco Secure Firewall 6160—marking its first deployment in a public event environment.

Bringing this data into Splunk required a bit of engineering:

Data Pipeline Design

Because of the scale and performance characteristics of the firewall, we implemented a structured ingestion pipeline:

  1. RSYSLOG Server
    • Acted as the initial log aggregator source for the firewall
    • Handled high-throughput syslog ingestion from the 6160
    • Provided buffering and normalization capabilities
    • Saved data on the file system, providing another layer of redundancy
  2. Splunk Heavy Forwarder (HF)
    • Consumed logs from files produced by RSYSLOG
    • Applied parsing, filtering, and metadata enrichment
    • Forwarded processed data securely to Splunk Cloud using the S2S protocol
  3. Splunk Cloud
    • Centralized indexing and analytics
    • Enabled both SOC and NOC use cases

The following diagram illustrates the ingestion pipeline used to reliably transport high-volume firewall telemetry into Splunk Cloud:

MWC 2026 blog diagram CC
Figure: Firewall telemetry ingestion pipeline used at MWC 2026, showing the flow from Cisco FTD 6160 through RSYSLOG and Splunk Heavy Forwarder into Splunk Cloud for centralized SOC and NOC analytics

Why This Approach Worked

  • Scalability & Resiliency: RSYSLOG absorbed burst traffic without dropping events and created a local copy of log files
  • Flexibility: The Heavy Forwarder allowed us to control parsing/filtering before ingestion, should we need to
  • Cloud Integration: Clean separation between on-prem data collection and cloud analytics

This pipeline ensured reliable ingestion of high-volume firewall telemetry while maintaining performance and data integrity.

Lessons Learned

A few key takeaways from the deployment:

  • Unification accelerates operations

    Bringing SOC and NOC data into a single platform improves operations and makes new insights possible

  • Data onboarding is the hardest—and most important—step

    Once data is flowing and normalized, building dashboards and detections becomes significantly easier.

  • Edge engineering still matters in cloud-first architectures

    Components like RSYSLOG and Heavy Forwarders remain critical for handling real-world data ingestion challenges.

  • Speed is achievable with the right abstractions

    Building a production-grade NOC dashboard in hours—not days—is realistic when the platform is designed for it.

Check out the lessons learned from the Event SOCs we deploy around the world, with the white paper and latest blogs.


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram