Improving your SOC operations with Cisco Security Cloud integrations
Cisco offers a wide range of security products which protect your networks from many different angles. Comprehensive security is great, but not when managing the software and alerts becomes overwhelming. The Splunk platform is the ideal solution for managing alerts and data from fourteen different security applications all in one place. Previously, to bring all the Cisco data into one location, you needed a different Splunkbase add-on for each tool. Now, with Cisco Security Cloud, you can deploy a single add-on to manage data from all these different Cisco security applications:
- Cisco XDR
- Cisco Secure Network Analytics
- Cisco Duo
- Cisco AI Defense
- Cisco Secure Email Threat Defense
- Cisco Multicloud Defense
- Cisco Secure Firewall
- Cisco Secure Malware Analytics
- Cisco Secure Endpoint
- Cisco Vulnerability Intelligence
- Cisco Identity Intelligence
- Cisco NVM
- Cisco Secure Workload
- Cisco Isovalent
Besides the data ingestion benefit, the add-on automatically maps incoming data from all these security tools to the Splunk Common Information Model. This means that all the disparate data and fields and values can easily be correlated and enriched in the Splunk platform for greater SOC efficiency.
This article describes key use cases for a number of these Cisco applications and how their functionality is enhanced through integrations with the Splunk platform, Splunk Enterprise Security, and Splunk SOAR.
How to use Splunk software for this use case
Cisco XDR
You receive an alert that a user has a local malware payload. Of course you want to shut down the user's machine, but you need to do much more than that. You want to investigate how the malware got there and what other systems the user accessed from the machine after the malware got there, especially if they logged in as an administrator. You need to correlate data to get a complete picture. With a Cisco XDR and Splunk integration, you get the following:
- A comprehensive view of security-related threats targeting your environment across multiple security control points
- The Splunk integration ingests and maps XDR Incidents to the Alert CIM data model
- The XDR incident that is ingested contains all of the observables that were correlated together from various XDR sources
- The XDR incident can be promoted to a Splunk Enterprise Security finding that will contain all of the observables and context from XDR automatically, manually or both
Cisco Secure Network Analytics
Secure Network Analytics (SNA) analyzes network traffic to detect threats, such as malicious communications and anomalies. The Splunk integration ingests and maps SNA events and alerts to the Alert, Network, Web CIM data models. From there, you have the ability to promote an SNA alert into an ES finding or RBA event based on criteria you set related to the severity of the alert. This all provides deep network visibility and seamless threat detection and investigation.
If you also install the Cisco Secure Network Analytics (Stealthwatch) App for Splunk Enterprise, you'll have the ability to filter high fidelity events and access ready-made dashboards that facilitate a workflow for incident response and investigation. Most of the queries in the dashboards leverage the SNA API and present the data on-demand, which means that the app does not impact your Splunk license usage limits.
Cisco Duo
Cisco Duo is a multi-factor authentication and secure remote access tool that assists implementation of zero trust. With Duo, you'll always know if your users try to access something they aren't supposed to. Additionally, Duo logs help you discover if a user was hacked, and if so, what did the hacker do? Did they try to log into a different account or use a temporary profile? You can incorporate Duo events into Splunk ES findings to detect and respond to these suspicious user activities and more.
The Splunk integration ingests and maps Duo system log events to the Authentication CIM model. Common Duo detections and alerts that are sent to the Splunk platform include:
-
- Fraudulent Duo user
- High number of MFA request
- User authentication
- User set to bypass status
- User set to disable
- User accessing from new location
- New admin account created
- Authentication policy changed
- Security keys presented in plain text
- Delete an integration
Current Duo suspicious activity alerts are based on profiles, not machine learning. For example, you can set a different level of "normal" for the number of authentications per day you might expect from a developer versus an administrator, assigning users to those roles. For more granular levels of learning individual user behavior, look into Splunk User and Entity Behavior Analytics.
Cisco AI Defense
Your AI systems need to be secure. New systems and apps create new visibility gaps, and ever changing models are open to vulnerabilities. Cisco AI Defense helps you protect against these weaknesses, as well as understand usage, such as which users or applications use a lot of tokens. The add-on includes an out-of-the-box Splunk Enterprise Security detection that creates a search and surfaces potential attacks against the AI models running in your environment, so your configuration effort is minimal.
Cisco Secure Email Threat Defense
Cisco Secure Email Threat Defense analyzes emails looking for phishing attempts and malicious indicators of compromise (IOCs). When combined with out-of-the-box Splunk Enterprise Security content that detects suspicious or malicious emails, threat response accuracy is improved. The Splunk integration ingests threat messages found and convicted by Cisco Secure Email Threat Defense solution, including all the IOCs that led to the message conviction. Events and alerts are mapped to the Email CIM data model.
Splunk customers who use Attack Analyzer have Secure Email Threat Defense already. No further action is required to use this integration.
Cisco Multicloud Defense
Cisco Multicloud Defense gives your organization more control over what developers are doing. Developers tend to use a wide cloud-based tool set, and it's difficult to combine data from different tools to get an overview of activities. Multicloud Defense protects environments by blocking inbound, lateral movement attacks and exfiltration of data. Then, the Splunk integration ingests and maps events and alerts from their different modules (WAF, AV, DLP, DDOS, Errors, Malware, FQDN) into the Network, Malware, IDS, and Web CIM models. This normalization means you can equate and compare what is happening in different cloud providers (AWS, GCP, and Azure) for a more complete picture, better cloud incident management, and robust cloud security.
Cisco Secure Firewall
Cisco Secure Firewall is a network security device that monitors and filters incoming and outgoing network traffic. The Splunk integration allows you to pool firewall information and transfer it, rather than connecting firewalls one by one. The integration spans Secure Firewall, IDS, Connection, and Malware event types, and ingests and maps them to IDS, Endpoint, and Network Traffic CIM models. Dashboards in the Splunk platform profile IOCs and details for connection and malware events. You can also use out-of-the-box ES content to detect suspicious or malicious network attacks and malicious communication.
Cisco Secure Malware Analytics
Cisco Secure Malware Analytics analyzes files and URLs in a sandbox to identify malicious IOCs. The Splunk integration ingests and maps the output of the analysis done by the submission to the sandbox to the Malware CIM data model. Then, in Splunk Enterprise Security, you can correlate findings on related URLs and artifacts, streamlining malware investigations. You can also use out-of-the-box ES content for detecting malware.
If you use either Splunk SOAR or Attack Analyzer, you already have an API key to connect directly to Cisco Secure Malware Analytics.
Cisco Secure Endpoint
Cisco Secure Endpoint helps you dig into process execution and command line activities, looking for suspicious or malicious activity that is an indication of a compromised host. The Splunk integration maps the alerts generated by Secure Endpoint to the Alert CIM model, while malware-related activity is mapped to the Malware CIM models. Splunk ES findings provide enriched investigations and event correlation, improving endpoint security. You can also use out-of-the-box ES content for detecting endpoint activities.
Cisco Vulnerability Intelligence
Cisco Vulnerability Intelligence assists with compliance. After you've identified a vulnerability, patching the problem can take time. With Cisco Vulnerability Intelligence, you can actively monitor everything exposed by the breach while you wait for the patch. Cisco Vulnerability Management works with Vulnerability Intelligence to provide context to Common Vulnerabilities and Exposures (CVE) about their risk. You can better prioritize them based on severity, likelihood of being exploited, and other factors.
The Splunk integration ingests vulnerability intelligence into the Splunk platform, maps it to the Vulnerabilities CIM model, and stores it in lookup tables to enrich investigations with context. Then, dashboards provide the ability to browse the vulnerabilities being reported and search on the ones that you want more information on.
Cisco Identity Intelligence
Cisco Identity Intelligence provides a full picture of identity activity to help you identify risky accounts. For example, a single user might have different user names for different systems, such as Cisco, AWS, GitHub. Cisco Identity Intelligence provides identity resolution for this situation, and identifies high-risk access attempts, and resources and privileges that are associated with users. The Splunk integration ingests alerts from Identity Intelligence into the Splunk platform and maps them to the Alerts CIM model for enrichment and correlation.
Additional resources
Now that you understand the power of the Cisco Security Cloud add-on and the integrations it enables with Splunk software, watch the full talk from Cisco Live EMEA 2026, Leverage the Power of Splunk Using the Latest Cisco Security Integrations for more detail. You'll learn about additional integrations as well, including Cisco Kenna VI Feed, Cisco Isovalent, and Cisco Talos.
In addition, you might find the following resources helpful for achieving this use case:
- Splunk Help: Overview of the Splunk Common Information Model
- Cisco DevNet: Cisco Secure Access Add-On for Splunk Guide

