This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Au cœur du SOC Agentique : De l’alerte à la réponse guidée avec Splunk Enterprise Security et Cisco

Download resources

About this session

Alexandre Argeris, a systems engineer at Splunk covering Quebec and the Maritimes, walks a security-operations-center audience through Splunk's shift to an 'agentic SOC' built on Splunk Enterprise Security and integrated with Cisco Cloud Control. He frames the case for change around alert fatigue, the SOC talent shortage, and detection tools that generate more events than analysts can absorb, then argues for narrow, task-specific AI agents under human-defined access and supervision rather than general-purpose chatbots. He walks through agents mapped to each stage of an investigation: an AI-powered data-onboarding agent, a Detection Builder agent that writes SPL search rules from a plain-language description, a procedure agent that ingests existing incident playbooks, a SOAR playbook-configuration agent that builds and self-tests automation workflows from a conversation, and triage and investigation-summary agents. He stresses that agents run inside the Splunk platform to limit data leaving the environment, and that Cisco Cloud Control adds Splunk-monitored, non-Cisco event context to Cisco's own investigations. An audience Q&A covers agent orchestration, data confidentiality with external versus local LLMs, and realistic limits on eliminating alert fatigue.

Face à la prolifération exponentielle des alertes et à la complexité croissante des environnements hybrides, moderniser le centre des opérations de sécurité est devenu un impératif stratégique pour permettre aux équipes de neutraliser les menaces avec rapidité et précision. Cette session explore les fondements et les bénéfices opérationnels du SOC Agentique propulsé par Splunk Enterprise Security (ES). Découvrez comment transformer la chaîne de traitement des incidents de la qualification initiale de l'alerte jusqu'à l'orchestration de la réponse guidée en combinant analyse avancée, contextualisation dynamique et assistance intelligente.

Key takeaways

  • Keep existing detection tools (EDR, next-gen firewall, SSE) in place; an agentic SOC adds an orchestration and context layer rather than replacing current investments.
  • Prefer narrow, task-specific AI agents with explicitly defined access and privileges over general-purpose chatbots built on broad LLMs.
  • Run agents inside the platform that holds your security data where possible, to minimize how much sensitive data transits to an external LLM.
  • Feed existing written incident-response procedures into a dedicated agent so it can suggest the right playbook during a live investigation.
  • Expect an agentic SOC to reduce alert fatigue rather than eliminate it, and treat data confidentiality with an external LLM as a vendor-by-vendor decision.

Speakers

Alexandre Argeris
Alexandre Argeris
Staff Solution Designer · Splunk
Alexandre has more than 25 years of technical experience in the IT industry with a security focus. Working as a Cyber Security Sales Consultant for 12 years at Cisco, his daily goal was to help customers across Canada to mitigate their cyber… Read moreRead less

Alexandre has more than 25 years of technical experience in the IT industry with a security focus. Working as a Cyber Security Sales Consultant for 12 years at Cisco, his daily goal was to help customers across Canada to mitigate their cyber security challenges using the Cisco Security Solutions. In the last 2 months, he has moved to Splunk, a Cisco company, where he is helping customers with Data Analytics for Security, Observability and AI. Prior to joining Cisco, Alexandre has been implementing security architectures and solutions for many major companies in Canada. He has also spoke at many different BSides Security conferences and present at Cisco Connect across Canada for many years and Cisco Live EU & US for the last 3 years.

Resources

Photos

Tags

More from GoSec 2026

Also from Alexandre Argeris

On the same topic