惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
GRAHAM CLULEY
Recorded Future
Recorded Future
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
小众软件
小众软件
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 叶小钗
A
About on SuperTechFans
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
MongoDB | Blog
MongoDB | Blog
Apple Machine Learning Research
Apple Machine Learning Research
罗磊的独立博客
人人都是产品经理
人人都是产品经理
Engineering at Meta
Engineering at Meta
WordPress大学
WordPress大学
博客园 - Franky
Google DeepMind News
Google DeepMind News
Security Latest
Security Latest
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Project Zero
Project Zero
N
News and Events Feed by Topic
I
Intezer
C
Check Point Blog
V
Visual Studio Blog
T
Tenable Blog
博客园 - 司徒正美
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
PCI Perspectives
PCI Perspectives
H
Help Net Security
www.infosecurity-magazine.com
www.infosecurity-magazine.com
The Cloudflare Blog
SecWiki News
SecWiki News
Vercel News
Vercel News
爱范儿
爱范儿
Recent Announcements
Recent Announcements
Spread Privacy
Spread Privacy
T
Threatpost
Last Week in AI
Last Week in AI
V
V2EX
O
OpenAI News
M
MIT News - Artificial intelligence
博客园 - 【当耐特】
腾讯CDC
Forbes - Security
Forbes - Security
Microsoft Security Blog
Microsoft Security Blog
AI
AI
Hacker News - Newest:
Hacker News - Newest: "LLM"
F
Full Disclosure
C
CXSECURITY Database RSS Feed - CXSecurity.com
P
Palo Alto Networks Blog

Security @ Cisco Blogs

We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026 Uplevelling Black Hat Threat Hunters Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia Cisco Secure Access with MCP Infrastructure at Black Hat Asia 2026 The Essence of Black Hat – Collaboration with Partners Black Hat Asia 2026: A Decade in Singapore Black Hat Asia 2026: Threat Hunters’ Corner Unveiling the Power of Integration: XDR, Splunk, Corelight, Arista and Palo Alto Networks in Action at Black Hat Asia Security in the Post-Mythos Era Cisco SASE with Meraki: Get in the Fast Lane to SASE Extending Zero Trust Across the Agentic AI Workflow Strengthening the Foundation: A Predictable, Customer focused Response to AI-Accelerated Vulnerability Discovery Quantum Resilience Needs a Common Language. Here’s Where to Start. Security at Cisco Live: Going Shields Up for the Agentic Era Identity Elevated: A New Unified Identity Experience in Cisco Cloud Control Security Needs a New Operating Model Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection Cisco Secure Access and Island Browser Enable Zero Trust Everywhere Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting Cisco Secure Access and Microsoft Edge for Business Integration Why Network Segmentation Projects Fail: Four Patterns Cisco’s Risk-Based Vulnerability Disclosure in the Age of AI Enhancing Cisco Secure Email Gateway: Safer Clicks and Cleaner Files AI-generated reporting: Lessons learned from Cisco Talos Incident Response Inside the SOC: AI-powered DNS defense against ransomware Security Insights: A Threat-First View for the Platform That Enforces Access From Strategy to Architecture: How Cisco is Building a Quantum-Safe Future AI-Ready, Simpler, and More Secure WAN: Cisco SD-WAN Innovations Designing for What’s Next: Securing AI-Scale Infrastructure Without Compromise Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap Mobile World Congress 2026: AI-powered Network Security Powering MWC Barcelona – Building a Unified SOC and NOC with Splunk in Record Time AI-powered Network Security at the Mobile World Congress 2026 SNOC Inside the Mobile World Congress 2026 SOC: Detecting Shadow Traffic with Firepower 6100 Data Optimization in Security: A Splunk Architect’s Perspective Inside the Talos 2025 Year in Review: A discussion on what the data means for defenders Zero Trust for Agentic AI: Safeguarding your Digital Workforce The Agent Trust gap: What Our Research Reveals About Agentic AI Security Meet Your Incident Responders
From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense
Vignesh Sathiamoorthy · 2026-06-01 · via Security @ Cisco Blogs

Security teams can often find themselves staring at a wall of logs, runtime events, firewall alerts, and workload signals, knowing the answer is probably in there somewhere, but not having the time to examine the details.

Applications now span Kubernetes clusters, cloud workloads, data centers, and branches, while teams try to connect signals from workloads, users, agents, logs, and firewalls. Each signal can tell part of the story, but with vulnerabilities being exploited faster than ever, it is easy to lose time chasing noise instead of finding threats.

That is why Cisco is bringing richer product telemetry into Splunk, along with the detections and correlation needed to make that telemetry useful. As organizations build toward a hybrid mesh firewall architecture, Cisco provides deeper visibility from runtime workloads and advanced firewall logging, while Splunk helps turn that visibility into detection, investigation, and action.

Move from isolated alerts to a clear picture of workload risk

Because modern applications are dynamic across containers, Kubernetes workloads, and services, it’s not enough to get an alert that something happened. Teams need to know what workload did it, what process caused it, and whether that behavior was expected.

Cisco Isovalent Enterprise Platform provides runtime visibility across Kubernetes and Linux workloads, including process execution, network connections, file access, and workload identity. Splunk brings that telemetry into the SOC with purpose-built detections and correlation, helping analysts understand suspicious behavior in context. Now, teams can move from manually interpreting direct runtime events to acting on correlated, high-confidence detections inside the Splunk workflows they already use.

Get detections with detailed logs as a native firewall capability

As a high-volume telemetry source, security teams rarely have time to move beyond alerts and examine firewall logs looking for small changes, unexpected patterns, or subtle signs of attacker behavior. Now, in its latest software release, Cisco Firewall introduces a native advanced logging capability, giving customers detailed, structured logs for richer protocol-level detail.

Splunk turns that detail into usable detections and correlation, helping teams surface meaningful patterns in DNS, HTTP, FTP, connection behavior, anomalies, and inspection events without manually sorting. With custom detections and correlation, Splunk can help analysts identify patterns that basic logs may miss, such as command-and-control behavior, DNS tunneling, suspicious downloads, beaconing, or unusual protocol activity.

Detect threats faster, before the incident escalates

Many attacks are not obvious at the point of entry, so when prevention misses something, detection speed matters. This is where the combination of Cisco telemetry and Splunk analytics becomes especially valuable.

For example, in an environment where Kubernetes egress traffic is inspected by Cisco Secure Firewall, a compromised web-service pod suddenly spawns a shell and starts reaching out through DNS. Splunk detections using Isovalent telemetry can show the pod, process, timing, and destination, while Cisco Secure Firewall advanced logging adds context like unusual query patterns or abnormal response sizes. Together, these signals help analysts connect workload behavior to network behavior, investigate with confidence, and respond faster.

Over time, this means customers have the advanced ability to:

  • Detect: Less manual event stitching for faster threat detection
  • Investigate: Get better context to increase confidence to act 
  • Act: Respond faster across hybrid environments

Cisco and Splunk are making that possible by bringing deeper product telemetry and purpose-built detection together in one security workflow. To multiply this advantage, check out the advanced threat detection, investigation, and response with Cisco Firewall Promotional Splunk Capacity (FTD).


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram