Splunk .conf26: Why Endace Full Packet Capture Becomes Mission-Critical in the Agentic SOC

By Michael Morris, Director of Global Business Development, Endace


Michael Morris, Director of Global Business Development, EndaceWhy Full Packet Capture Matters More as AI Becomes a Security Analyst

The security industry is entering a new operational era. For years, Security Operation Center (SOC) modernization focused on improving detection. Better analytics. Better threat intelligence. Better correlation. More automation. Today, the focus has shifted.

The emergence of Agentic SOC architectures is changing the fundamental question from: “Can we detect threats?” to “Can we trust the conclusions generated by autonomous investigations?“

As AI agents take on larger portions of triage, enrichment, evidence gathering, and investigation, one reality becomes increasingly apparent: The success of the Agentic SOC is not determined by AI alone. It is determined by the quality of evidence available to AI.

At Splunk .conf26, Endace demonstrated why full packet capture is rapidly becoming one of the most important sources of evidence in modern security operations.

Security Teams Have Solved the Visibility Problem

For most organizations, the lack of data is no longer the problem. SOCs are flooded with telemetry:

  • Security logs
  • DNS activity
  • Endpoint events
  • Firewall records
  • NetFlow
  • Application telemetry
  • Identity data
  • Threat intelligence feeds
  • Cloud activity

The challenge today is not collecting data. The challenge is determining which data is trustworthy enough to support increasingly autonomous security decisions. As investigations become more automated, the distinction between telemetry and evidence becomes critical. Telemetry tells you something happened. Evidence tells you exactly what happened. That distinction separates packet capture from virtually every other data source in the SOC.

The Agentic SOC Needs Ground Truth

One of the most important architectural principles emerging from modern security operations is the concept of ground truth.


AI systems consume evidence. They assess confidence. They eliminate noise. They prioritize risk. They recommend actions. But every recommendation ultimately depends on the underlying data. If the evidence is incomplete, conclusions become uncertain. If the evidence is delayed, investigations slow down. If the evidence is ambiguous, analysts lose confidence.

Full packet capture solves this problem by preserving the original network conversation. Instead of relying solely on summaries, metadata, or derived analytics, analysts and AI agents can continuously return to the authoritative source. In a world increasingly driven by machine reasoning, packet capture provides something rare: A verifiable record of reality.

Splunk .conf26 Demonstrated the Scale of the Challenge

The event network operated at a scale that most enterprise security teams would recognize immediately.

Endace captured:

  • 30 TB of packet data
  • 31.6 billion packets
  • 154.7 million unique sessions
  • 9,443 unique clients

Beyond pure scale, packet analysis revealed operational insights that would have been difficult to uncover through logs alone:

  • 111,062 files extracted
  • 5,839 files submitted for advanced analysis
  • 3,589 plaintext password sightings
  • 83 unique accounts transmitting credentials in clear text
Statistics from Splunk .conf26
Statistics from Splunk .conf26

These are not simply interesting statistics. They illustrate why packet capture remains unique. Every file transfer. Every protocol exchange. Every credential exposure. Every network session. Every byte of communication. All available for validation long after the original event occurred.

Packet Capture Is No Longer a Forensics Tool

Historically, packet capture occupied a specialized role. A major security incident occurred. An analyst opened packet data. Investigators reconstructed what happened. A report was written. The incident was closed. That model no longer reflects how modern SOCs operate. The Agentic SOC requires evidence continuously, not occasionally. Investigations happen in real time. AI agents gather context automatically. Analysts expect immediate answers. Executive stakeholders demand traceable decisions. Packet capture has therefore evolved from a forensic platform into an operational system. Instead of helping explain yesterday’s incident, packet data actively informs today’s decision-making. That shift represents a fundamental change in the value proposition of full packet capture.

The Network Still Tells the Truth

One challenge every security team faces is fragmented visibility. Endpoint data may be unavailable. Cloud telemetry may be incomplete. Third-party systems may lack instrumentation. Logs may be sampled. Alerts may be suppressed. Users may operate devices outside administrative control. The network remains the common denominator. Every system communicates. Every application transmits data. Every attack generates traffic. Every compromise leaves traces. Packet capture therefore provides visibility that does not depend upon deployment models, operating systems, agents, or administrative ownership.

For environments with large populations of unmanaged devices, such as conferences, campuses, hospitals, universities, manufacturing facilities, and guest networks, packet capture is especially valuable because it remains available even when other telemetry sources – such as end point telemetry – are not.

What AI Learns from Packets

Discussions around the use of AI in cybersecurity typically focus on its ability to increase the speed of response. Speed is undeniably important, but the greater value is context.

Full Packet data provides context that is unavailable from any other source of data:
• Complete session reconstruction
• Application behavior
• File movement
• Protocol misuse
• Credential exposure
• The detail of command-and-control communications
• User activity patterns
• Traffic timelines

When these elements are combined with threat intelligence, security analytics, and behavioral detections, AI systems gain access to evidence rather than indicators alone. That changes the quality of investigation outcomes. Instead of reporting: “a suspicious event occurred” the system can determine: “this event occurred, these systems communicated, these files were transferred, this protocol was used, and this is the evidence that supports the conclusion.” The result is not simply faster investigations. The result is more trustworthy investigations.

Building Explainable Security Operations

One of the greatest risks facing security organizations is the emergence of black-box decision making. The more autonomous systems become, the more important explainability becomes.

Security leaders need to know:

  • Why a finding was escalated
  • Why an event was closed
  • Why an investigation was prioritized
  • Why a response action was recommended

Answers require evidence. Evidence requires records. Records require preservation.

That is the role packet capture fulfills. Endace provides the evidentiary foundation that connects AI reasoning, analyst decision-making, and organizational accountability. It allows every conclusion to be traced back to observable network activity.

The Future of the Agentic SOC

Over the next several years, most security operations centers will adopt some level of agentic capability. AI-driven triage will become standard. Autonomous investigations will become common. Machine-generated recommendations will become expected. What will differentiate successful organizations from unsuccessful ones will not be solely the intelligence of the agents. It will be the quality of the evidence available to those agents. The organizations that achieve the greatest value from AI will be those that provide their AI tools with the richest, most complete, and most trustworthy data foundation. That foundation increasingly requires full packet capture.

At Splunk .conf26, Endace demonstrated that packet capture is no longer just about retrospective forensics. It is about enabling trustworthy AI, explainable investigations, and evidence-based security operations. As the industry moves toward the Agentic SOC, one conclusion becomes clear:

AI may become the analyst’s co-pilot, but packet capture remains the system of record.

Acknowledgements

Our thanks go to the Splunk .conf26 SOC team, led by Jessica Oppenheimer,  for the opportunity to integrate EndaceProbes with the Splunk .conf26 Agentic SOC architecture. 

The SOC team is a collection of Cisco, Splunk and Endace experts across many domains who were a pleasure to work and innovate with, and we came away with a great appreciation for the power of the Cisco and Splunk tools.

The teams were able to prove out integration innovations and test them in earnest in a real-world environment in preparation for making them generally available to the market.

More from Endace, Splunk and Cisco in the SOC series

Read all about the Agentic Security Operations Center at Splunk .conf26, including an overview from Jessica Oppenheimer, and posts and use cases from Splunk and Cisco SOC team members:

Read about the Endace team’s experience working in the SOC at Splunk .conf26:

For more Endace blogs in our SOC series, see here:
https://blog.endace.com/tag/soc/ 

Cisco Event SOC Website 
Visit Cisco’s Event SOC website for full details of the SOC-in-a-Box setup, and download the detailed architecture blueprint and report by Jessica Oppenheimer:
https://www.cisco.com/site/us/en/products/security/event-soc-report.html