惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
D
Docker
GbyAI
GbyAI
Y
Y Combinator Blog
Google DeepMind News
Google DeepMind News
G
Google Developers Blog
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
雷峰网
雷峰网
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
小众软件
小众软件
Engineering at Meta
Engineering at Meta
酷 壳 – CoolShell
酷 壳 – CoolShell
I
InfoQ
B
Blog
H
Help Net Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
B
Blog RSS Feed
Microsoft Security Blog
Microsoft Security Blog

Security @ Cisco Blogs

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Thrown into the SOC: A Black Hat First-Timer’s Story Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Distributed Latency Monitoring at Black Hat Black Hat USA 2026: Safeguarding DNS with Secure Access Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Frontier AI just raised the stakes, and the old playbook won’t hold up Crypto Agility: Why PQC Is Not a One-Time Upgrade From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified Class C (Moderate) to Certified Class D (High) Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Is your SD-WAN ready for AI-powered operations? The Zero Trust Imperative for the Frontier AI Era Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes The Journey towards Logically Air-Gapped Deployment Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026
From Log Flood to Threat Signal: Cisco and Splunk Bring C...
Vignesh Sathiamoorthy · 2026-06-01 · via Security @ Cisco Blogs

Security teams can often find themselves staring at a wall of logs, runtime events, firewall alerts, and workload signals, knowing the answer is probably in there somewhere, but not having the time to examine the details.

Applications now span Kubernetes clusters, cloud workloads, data centers, and branches, while teams try to connect signals from workloads, users, agents, logs, and firewalls. Each signal can tell part of the story, but with vulnerabilities being exploited faster than ever, it is easy to lose time chasing noise instead of finding threats.

That is why Cisco is bringing richer product telemetry into Splunk, along with the detections and correlation needed to make that telemetry useful. As organizations build toward a hybrid mesh firewall architecture, Cisco provides deeper visibility from runtime workloads and advanced firewall logging, while Splunk helps turn that visibility into detection, investigation, and action.

Move from isolated alerts to a clear picture of workload risk

Because modern applications are dynamic across containers, Kubernetes workloads, and services, it’s not enough to get an alert that something happened. Teams need to know what workload did it, what process caused it, and whether that behavior was expected.

Cisco Isovalent Enterprise Platform provides runtime visibility across Kubernetes and Linux workloads, including process execution, network connections, file access, and workload identity. Splunk brings that telemetry into the SOC with purpose-built detections and correlation, helping analysts understand suspicious behavior in context. Now, teams can move from manually interpreting direct runtime events to acting on correlated, high-confidence detections inside the Splunk workflows they already use.

Get detections with detailed logs as a native firewall capability

As a high-volume telemetry source, security teams rarely have time to move beyond alerts and examine firewall logs looking for small changes, unexpected patterns, or subtle signs of attacker behavior. Now, in its latest software release, Cisco Firewall introduces a native advanced logging capability, giving customers detailed, structured logs for richer protocol-level detail.

Splunk turns that detail into usable detections and correlation, helping teams surface meaningful patterns in DNS, HTTP, FTP, connection behavior, anomalies, and inspection events without manually sorting. With custom detections and correlation, Splunk can help analysts identify patterns that basic logs may miss, such as command-and-control behavior, DNS tunneling, suspicious downloads, beaconing, or unusual protocol activity.

Detect threats faster, before the incident escalates

Many attacks are not obvious at the point of entry, so when prevention misses something, detection speed matters. This is where the combination of Cisco telemetry and Splunk analytics becomes especially valuable.

For example, in an environment where Kubernetes egress traffic is inspected by Cisco Secure Firewall, a compromised web-service pod suddenly spawns a shell and starts reaching out through DNS. Splunk detections using Isovalent telemetry can show the pod, process, timing, and destination, while Cisco Secure Firewall advanced logging adds context like unusual query patterns or abnormal response sizes. Together, these signals help analysts connect workload behavior to network behavior, investigate with confidence, and respond faster.

Over time, this means customers have the advanced ability to:

  • Detect: Less manual event stitching for faster threat detection
  • Investigate: Get better context to increase confidence to act 
  • Act: Respond faster across hybrid environments

Cisco and Splunk are making that possible by bringing deeper product telemetry and purpose-built detection together in one security workflow. To multiply this advantage, check out the advanced threat detection, investigation, and response with Cisco Firewall Promotional Splunk Capacity (FTD).


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram