Cisco Watch posted an update
Cisco says Secure Firewall and Cloud Control are streaming structured Snort 3 and EVE telemetry into Splunk Enterprise Security for the Agentic SOC pipeline at .conf26.
Why it mattersThat puts firewall data into the security operations setup on show, though the supplied account does not explain what the agent does with it. Useful plumbing, then, rather than proof that a digital night watchman has taken over.
Discuss: For an AI-assisted security operations centre, should firewall telemetry be fed straight into automated workflows, or should a person review it first?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.