A Cisco product manager shares firsthand experience working in the Cisco Live AMER Security Operations Center, using Splunk Enterprise Security and XDR alongside AI assistance to investigate real detections. Key takeaways include how AI accelerated orientation and context-gathering without replacing analyst judgment, how Splunk and XDR complemented each other (XDR for investigation shape and hypothesis, Splunk for deep evidence search), and why the hardest part of detection is understanding what an alert means in context rather than just knowing it fired. The experience reinforced a product vision of unified investigation workflows that reduce translation work for analysts.
Table of contents
Inside the Cisco Live SOCFrom Customer Conversations to Live InvestigationsThe Messy Middle of Detection and ResponseWhere AI Helped Me Move FasterWhat Real Investigations ReinforcedWhere Splunk and XDR Shined TogetherBuilding Toward Better Analyst Experiences57 Impressions