A Cisco product quality engineer shares their first-hand experience working in the Cisco Live AMER 2026 Security Operations Center. The post covers the full week: building the 'SOC in a Box' hardware stack (firewall, EndaceProbe, UCS compute, SPAN feeds), standing up the software portfolio (Cisco XDR, Splunk Enterprise Security, Secure Network Analytics, Foundation AI), and handling real incidents ranging from malicious website access to complex multi-stage attacks. A highlight was building 'AIM', a custom AI Tier-2 SOC analyst using Claude Opus, MCP servers for Endace and Splunk, and the XDR Conure API. The team also got hands-on with agentic SOC tools including the XDR Agentic Incident Attack Storyboard and Splunk Triage Agent, effectively being promoted to Tier 2 analysts on day one.

8m read timeFrom blogs.cisco.com
Post cover image
Table of contents
Why a product engineer ended up in a SOCDay 0 — Before the drama began: building the boxSetup — assembling the orchestraTrainingIncidents start flowing (and we got “promoted”)Innovate — we built our own AI Tier-2 analystEducate — the XDR booth and a great crowdProtect — from simple to complex, one after anotherBonus — threat hunting with Splunk ESAfter hours — because it’s VegasThe last day — a broken-hearted farewellAcknowledgements
87 Impressions