Splunk is presenting numerous sessions throughout the week at Cisco Live. Check out the highlights.
KDDOBS-1000 - Digital Resilience Redefined: What it takes to Win in the Agentic Era
When: Wednesday, Nov 11, 11:15 AM - 12:00 PM AEDT Centre Stage, World of Solutions
As autonomous agents reshape operations and the Mythos threat landscape accelerates, digital resilience needs a new playbook. See how Cisco and Splunk help organizations turn machine data into agentic action, defend at machine speed and optimize AI at scale with agentic capabilities, AI guardrails and end-to-end visibility.
CENOBS-1198 - The AI Reality Check: Defending Your Infrastructure Against Costs and Attacks with Splunk
When: Tuesday, Nov 10, 4:30 PM - 5:00 PM AEDT Centre Stage - World of Solutions
AI is reshaping both the threat landscape and the economics of security. As adversaries use AI to move faster and adapt in real time, security teams need more than faster alerts—they need coordinated action, trusted automation, and human oversight.
In this session, you’ll learn how Splunk helps organizations build an Agentic SOC that uses trusted agents to investigate and respond at machine speed while keeping people in control. See how distributed defenses and enterprise-wide visibility help disrupt attacks closer to their source, and how continuous exposure management helps teams identify, prioritize, and mitigate business-critical risk.
ITLGEN-2013 - Shared Risk, Unified Defense: Resilience in the Agentic Era
When: Wednesday, Nov 11, 4:00 PM - 4:30 PM AEDT Melbourne Room 2
Agentic AI and machine-speed threats are rewriting the rules of enterprise risk. Fragmented IT and security silos with disjointed tools can leave dangerous blind spots across the digital estate, while massive data proliferation and runaway AI costs strain IT budgets. Digital resilience in the agentic era demands a new operation model: analyzing petabytes of telemetry where data lives, maximizing value while governing AI spend through rigorous tokenomics, and enforcing real-time guardrails before autonomous agents execute risky transactions.
We examine how a converged strategy – that only Cisco can deliver – unifies and empowers IT and security teams to secure and support the business while accelerating innovation with trusted AI.
BRKOBS-2625 - One Step Ahead: Detecting and Defeating Adversarial Attacks with Cisco XDR and Splunk ES
When: Tuesday, Nov 10 | 3:45 PM - 4:45 PM AEDT
Adversarial attacks are becoming increasingly sophisticated, leveraging multiple vectors and evasion techniques to bypass traditional defenses. In this session, we’ll explore how Cisco security detects, correlates, and responds to these complex attacks across the entire organization. You’ll learn what defines an adversarial attack, how attackers move laterally through systems, and how Cisco XDR and Splunk Enterprise Security integrate telemetry from multiple security tools to provide unified visibility and faster response. Through live demonstrations, we’ll walk through real-world adversarial attack scenarios showing hidden relationships, prioritising critical alerts, and empowering analysts to quickly contain and remediate threats. Whether you’re a SOC analyst, incident responder, or security leader, this session will give you a practical view of how Cisco helps defenders stay one step ahead of adversaries.
BRKOBS-2626 - Solving the Detection Dilemma: Underpinning/Transforming/Reinforcing/Renovating your security foundations for an agentic SOC future
When: Wednesday, Nov 11 | 10:30 AM - 11:30 AM AEDT
Since the dawn of SecOps, detection dilemmas have been the persistent thorn in the side of SOC teams around the globe. From false positives and benign positives that drown out the true positives, to the increasing rates of organisations who failing to detect malicious activity and instead are being notified by external entities, it has become accepted fact that SOC teams have always and will always be overwhelmed. But it really doesn't have to be that way and the best part, you don’t even need AI to get your SOC team back from the brink. So, please join me for this fast-paced session where I will cover they key problems with SOC efficacy and detail exactly the way we are solving many of these damned detection dilemmas with what will seem like a commonsense method once you hear the details. So, if you are after guidance on how you can also adopt a transformative approach to threat detection that is based on a completely redesigned detection framework, this is the session you need. The only prerequisites to attend this session is to forget everything you were ever told about threat detection.
BRKOBS-2629 - Attackers got Agentic. Your SOC needs more than Agents
When: Wednesday, Nov 11 | 1:00 PM - 2:30 PM AEDT
Everyone is talking about AI agents. Almost no one is talking about what agents actually need to work safely in a production SOC: a unified data foundation, a context layer that enriches every decision, and an operational layer that connects agent actions to real-world outcomes — with human governance built in at every step. This session shows you how to build the harness, not just deploy the model. Using the Cisco Data Fabric and Splunk Platform, you'll see how Detection, Investigation, and Response Agents work together — each handing off to the next through a governed decision gate where your team controls exactly how much autonomy the system has. The result: a SOC that acts at machine speed, with human judgment exactly where it belongs.
BRKOBS-2630 - Digital Resilience by Design: Evaluating the Business Impact of AI Agents
When: Tuesday, Nov 10 | 8:30 AM - 10:00 AM AEDT
In today’s digital enterprise, the success of a business process is no longer defined solely by server uptime or application latency—it is defined by the efficacy of the AI agents powering the customer journey. When an AI agent handles a critical transaction, it becomes a vital node in your business workflow. But are you monitoring the health of the business outcome or just the health of the code? In this session, we will explore how to integrate AI agents into your broader business process monitoring strategy using Splunk IT Service Intelligence (ITSI). We will demonstrate how to map AI-driven interactions to key business journeys, allowing you to visualise how agent performance directly impacts revenue, customer satisfaction, and operational efficiency. You will learn how to leverage ITSI’s predictive analytics to identify when an AI agent’s behaviour is deviating from expected business KPIs, enabling you to resolve issues before they disrupt the customer journey.
BRKOBS-2656 - From Experiment to Production: A guide to Trustworthy, Resilient AI Agents with Splunk
When: Tuesday, Nov 10 | 5:00 PM - 6:00 PM AEDT
AI agents are quickly becoming the new front door to your business — the first (and sometimes only) interface your customers use to get help, complete a transaction, or make a decision. But an AI agent that gives a wrong answer, misreads intent, or quietly degrades doesn't just create a bad experience — it breaks a business process and erodes customer trust in real time. This session is a practical, no-prior-experience-required introduction to keeping AI agents healthy from both a human and a business perspective. We'll cover two things every organisation deploying AI agents needs to get right: is the AI actually helping (accuracy, relevance, trust, safety), and is the AI actually delivering the business outcome it was built for (revenue, CSAT, operational efficiency). We'll show how to build your own AI Agents and move beyond traditional infrastructure metrics, like uptime and latency, to a conversation-centric view of AI quality, and how to evaluate your AI agent behaviour. You'll leave with a simple mental model for AI agent health, a starting framework for quality evaluation and governance, and a clear picture of how Splunk gives you visibility from "is the agent talking sense" all the way to "is the agent making the business money.
BRKOBS-2627 - One Observability Strategy for Every Workload: From Legacy Applications to Cloud Native and AI Agents
When: Wednesday, Nov 11 | 3:00 PM - 4:00 PM AEDT
Enterprise environments span decades of technology. A single business transaction may traverse legacy applications, cloud native services, Kubernetes workloads, and AI powered agents before delivering an outcome. As architectures become more diverse, achieving consistent observability across every workload becomes increasingly challenging. This session explores how OpenTelemetry enables a unified approach to observability across modern software landscapes. We'll examine when traditional application instrumentation provides the deepest insights, where eBPF fills visibility gaps without code changes, and how OpenLLMetry extends OpenTelemetry to AI agents and LLM powered applications. Through practical examples and architectural walkthroughs, you'll learn how these complementary approaches fit together, when to use each, and how they help build an end to end view of complex systems that span legacy applications, cloud native platforms, and AI driven workloads.
CSSOBS-2396 - Resilience Blueprint: NH Bank and Cisco CX Co-Engineered AI-Ready Network Operation Model
When: Monday, Nov 9 | 4:30 PM - 5:15 PM AEDT
Enterprise environments span decades of technology. A single business transaction may traverse legacy applications, cloud native services, Kubernetes workloads, and AI powered agents before delivering an outcome. As architectures become more diverse, achieving consistent observability across every workload becomes increasingly challenging. This session explores how OpenTelemetry enables a unified approach to observability across modern software landscapes. We'll examine when traditional application instrumentation provides the deepest insights, where eBPF fills visibility gaps without code changes, and how OpenLLMetry extends OpenTelemetry to AI agents and LLM powered applications. Through practical examples and architectural walkthroughs, you'll learn how these complementary approaches fit together, when to use each, and how they help build an end to end view of complex systems that span legacy applications, cloud native platforms, and AI driven workloads.
BRKOBS-2624 - Data Federation Made Easy with Cisco Data Fabric
When: Monday, Nov 9 | 3:15 PM - 4:15 PM AEDT
With over a 30% growth in data across the globe in one year (175 zettabytes 2025 to 230 in 2026) a new way of providing insights from that data is needed. Cisco and Splunk has introduced the Cisco Data Fabric. This session will go through what the Cisco Data Fabric is, what technologies underpin the Data Fabric from data routing and manipulation, data landing capabilities around S3 promote, Machine Data Lake and traditional Splunk models then how to we gain insights from those data sources using MCP, Next Gen Federated Search and AI Canvas. This will be a 200/300 level discussion on the technologies that underpin the Cisco Data Fabric covering off not only the what but the why we have them.
BRKOBS-2628 - Building Intelligent Network Operations with Cisco Data Fabric and Splunk Platform
When: Thursday, Nov 12 | 10:30 AM - 12:00 PM AEDT
Modern networks generate enormous amounts of telemetry, yet network teams still struggle with siloed data, rising costs, and increasingly complex environments. In this 90 minute session, join a Splunk principal data architect to see how Splunk Machine Data Platform helps network engineers bring together data from across network domains and technologies to gain true end-to-end visibility and faster insights. Through practical and foundational examples, we will explore how Splunk and Cisco Data Fabric enable scalable network analytics, cost effective data tiering and optimisation, and access to a rich ecosystem of network focused applications and integrations. We will also discuss how building the right data foundation today prepares organisations for the next wave of AI driven and agentic network operations. Whether you are running enterprise or service provider networks, this session will provide fundamental understanding of Splunk platform and practical approaches to modernising network operations and unlocking more value from your network data, followed by a real world use case.
