{"id":16952,"date":"2026-04-10T14:24:47","date_gmt":"2026-04-10T14:24:47","guid":{"rendered":"https:\/\/dmsretail.com\/RetailNews\/powering-mwc-barcelona-building-a-unified-soc-and-noc-with-splunk-in-record-time\/"},"modified":"2026-04-10T14:24:47","modified_gmt":"2026-04-10T14:24:47","slug":"powering-mwc-barcelona-building-a-unified-soc-and-noc-with-splunk-in-record-time","status":"publish","type":"post","link":"https:\/\/dmsretail.com\/RetailNews\/powering-mwc-barcelona-building-a-unified-soc-and-noc-with-splunk-in-record-time\/","title":{"rendered":"Powering MWC Barcelona &#8211; Building a Unified SOC and NOC with Splunk in Record Time"},"content":{"rendered":"<p> <p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/>\n<\/p>\n<div>\n<p>Mobile World Congress (MWC) Barcelona is one of the most demanding environments for network and security operations. With thousands of attendees,\u00a0unmanaged\u00a0devices, and applications interacting in real time, operational visibility and threat detection must function flawlessly.<\/p>\n<p>For the 2<sup>nd<\/sup>\u00a0year,\u00a0the\u00a0Cisco\u00a0team\u00a0leveraged\u00a0Splunk,\u00a0in addition\u00a0to its other security\u00a0products,\u00a0to deliver a unified Security Operations Center (SOC) and Network Operations Center (NOC) experience. Together, we used\u00a0Splunk as the central data platform and integrating telemetry across a broad set of Cisco technologies.<\/p>\n<p>What made this deployment particularly notable was not just the breadth of integrations, but the speed and flexibility with which we operationalized the environment.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/04\/1-MWC2026CiscoBoothSetup-1024x768.webp\" alt=\"Cisco booth setup\" class=\"lazy lazy-hidden wp-image-489327\" style=\"width:724px;height:auto\"\/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/04\/1-MWC2026CiscoBoothSetup-1024x768.webp\" alt=\"Cisco booth setup\" class=\"wp-image-489327\" style=\"width:724px;height:auto\"\/><\/noscript><figcaption class=\"wp-element-caption\">People\u00a0getting the Cisco booth in preparation for Mobile World Congress 2026<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-22aa995b9ce9baf75dceb35b0d29a84f\" id=\"h-the-architecture-a-unified-operations-platform\" style=\"font-style:normal;font-weight:400\">The Architecture: A Unified Operations Platform<\/h2>\n<p>At the core of the deployment was Splunk Cloud, acting as the single pane of glass for both SOC and NOC workflows.<\/p>\n<p>We ingested data from multiple Cisco platforms, including:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/04\/2-MWC2026S-NOC-1024x576.webp\" alt=\"MWC 2026 NOC\" class=\"lazy lazy-hidden wp-image-489328\" style=\"width:762px;height:auto\"\/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/04\/2-MWC2026S-NOC-1024x576.webp\" alt=\"MWC 2026 NOC\" class=\"wp-image-489328\" style=\"width:762px;height:auto\"\/><\/noscript><figcaption class=\"wp-element-caption\">The SOC and NOC area at Mobile World Congress 2026\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>This architecture allowed us to converge traditionally siloed operational domains into a single analytics layer, enabling faster correlation between network events and security incidents.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/04\/3-MWC2026SOCdashboards-1024x576.webp\" alt=\"MWC 2026 SOC dashboards\" class=\"lazy lazy-hidden wp-image-489329\" style=\"width:726px;height:auto\"\/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/04\/3-MWC2026SOCdashboards-1024x576.webp\" alt=\"MWC 2026 SOC dashboards\" class=\"wp-image-489329\" style=\"width:726px;height:auto\"\/><\/noscript><figcaption class=\"wp-element-caption\">Clockwise from the upper left quadrant: Firepower in Security Cloud Control, Splunk Cloud dashboard for MWC, Splunk Enterprise Security Mission Control and Cisco XDR.<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-9aec775fefc72fcf833c80c9f17ea706\" id=\"h-building-noc-dashboards-in-an-afternoon\" style=\"font-style:normal;font-weight:400\">Building NOC Dashboards in an Afternoon<\/h2>\n<p>One of the most impactful outcomes was how quickly we were able to deliver operational visibility following various requests from other teams present at the event.<\/p>\n<p>Using Splunk\u2019s data platform and visualization capabilities, we were able to build a fully functional NOC dashboard in just a few hours. The dashboard provided:<\/p>\n<ul class=\"wp-block-list\">\n<li>Real-time network\u00a0usage\u00a0and availability<\/li>\n<li>Client connectivity metrics across wireless and wired environments<\/li>\n<li>Application\u00a0usage\u00a0indicators<\/li>\n<\/ul>\n<p>Because all telemetry was\u00a0collected\u00a0within Splunk, creating meaningful\u00a0dashboards\u00a0required minimal transformation work. This highlights a key advantage of using a unified data platform: once ingestion is solved, insights\u00a0can\u00a0follow quickly.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"452\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/04\/4-MWC2026CiscoSpacesDashboard-1024x452.webp\" alt=\"MWC 2026 Cisco space dashboard\" class=\"lazy lazy-hidden wp-image-489331\" style=\"width:786px;height:auto\"\/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"452\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/04\/4-MWC2026CiscoSpacesDashboard-1024x452.webp\" alt=\"MWC 2026 Cisco space dashboard\" class=\"wp-image-489331\" style=\"width:786px;height:auto\"\/><\/noscript><figcaption class=\"wp-element-caption\">One of the\u00a0dashboards\u00a0built using Splunk to track Cisco Spaces users across the venue.<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-996de317705f10b41a9da8c824f8f82a\" id=\"h-bridging-soc-and-noc-from-visibility-to-context\" style=\"font-style:normal;font-weight:400\">Bridging SOC and NOC: From Visibility to Context<\/h2>\n<p>Traditionally, SOC and NOC teams\u00a0operate\u00a0in parallel, often using separate tools and datasets. At MWC, we intentionally broke down that barrier.<\/p>\n<p>By leveraging Splunk as the common platform:<\/p>\n<ul class=\"wp-block-list\">\n<li>NOC events (e.g., latency spikes,\u00a0usage trends) could be correlated with<\/li>\n<li>SOC signals (e.g., anomalous traffic patterns, threat detections)<\/li>\n<\/ul>\n<p>This convergence enabled faster root cause analysis and reduced mean time to resolution (MTTR), particularly in scenarios where performance issues\u00a0or traffic anomalies\u00a0had potential security implications.<\/p>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-7424df5f558987eeef38874210b1f051\" id=\"h-a-first-deploying-the-cisco-6160-firewall-in-a-public-event\" style=\"font-style:normal;font-weight:400\">A First: Deploying the Cisco 6160 Firewall in a Public Event<\/h2>\n<p>A standout aspect of this deployment was the use of the\u00a0<strong>Cisco\u00a0Secure Firewall\u00a06160<\/strong>\u2014marking its first deployment in a public event environment.<\/p>\n<p>Bringing this data into Splunk\u00a0required\u00a0a bit of engineering:<\/p>\n<h3 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-44d763bdfdec1fc27f441cd0744208a7\" id=\"h-data-pipeline-design\" style=\"font-style:normal;font-weight:400\"><em>Data Pipeline Design<\/em><\/h3>\n<p>Because of the scale and performance characteristics of the\u00a0firewall, we implemented a structured ingestion pipeline:<\/p>\n<ol class=\"wp-block-list\">\n<li><strong>RSYSLOG Server<\/strong>\n<ul class=\"wp-block-list\">\n<li>Acted as the initial log aggregator\u00a0source for the\u00a0firewall<\/li>\n<li>Handled high-throughput syslog ingestion from the 6160<\/li>\n<li>Provided buffering and normalization capabilities<\/li>\n<li>Saved data on the file system, providing another layer of redundancy<\/li>\n<\/ul>\n<\/li>\n<li><strong>Splunk Heavy Forwarder<\/strong><strong>\u00a0(HF)<\/strong>\n<ul class=\"wp-block-list\">\n<li>Consumed logs from\u00a0files produced by\u00a0RSYSLOG<\/li>\n<li>Applied parsing, filtering, and metadata enrichment<\/li>\n<li>Forwarded\u00a0processed data securely to Splunk Cloud\u00a0using the S2S protocol<\/li>\n<\/ul>\n<\/li>\n<li><strong>Splunk Cloud<\/strong>\n<ul class=\"wp-block-list\">\n<li>Centralized indexing and analytics<\/li>\n<li>Enabled both SOC and NOC use cases<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>The following diagram illustrates the ingestion pipeline used to reliably transport high-volume\u00a0firewall\u00a0telemetry into Splunk Cloud:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"422\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/04\/5-MWC2026BlogDiagramCC-1024x422.webp\" alt=\"MWC 2026 blog diagram CC\" class=\"lazy lazy-hidden wp-image-489357\" style=\"width:760px;height:auto\"\/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"422\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/04\/5-MWC2026BlogDiagramCC-1024x422.webp\" alt=\"MWC 2026 blog diagram CC\" class=\"wp-image-489357\" style=\"width:760px;height:auto\"\/><\/noscript><figcaption class=\"wp-element-caption\"><strong>Figure:<\/strong>\u00a0Firewall telemetry ingestion pipeline used at MWC 2026, showing the flow from Cisco FTD 6160 through RSYSLOG and Splunk Heavy Forwarder into Splunk Cloud for centralized SOC and NOC analytics<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-15405c17c9a3268bc18efdd37b1ae6c8\" id=\"h-why-this-approach-worked\" style=\"font-style:normal;font-weight:400\">Why This Approach Worked<\/h2>\n<ul class=\"wp-block-list\">\n<li><strong>Scalability\u00a0&amp; Resiliency<\/strong>: RSYSLOG absorbed burst traffic without dropping events\u00a0and created a local copy of log files<\/li>\n<li><strong>Flexibility<\/strong>: The Heavy Forwarder allowed us to control parsing\/filtering\u00a0before ingestion, should we need to<\/li>\n<li><strong>Cloud Integration<\/strong>: Clean separation between on-prem data collection and cloud analytics<\/li>\n<\/ul>\n<p>This pipeline\u00a0ensured\u00a0reliable ingestion of high-volume\u00a0firewall\u00a0telemetry while\u00a0maintaining\u00a0performance and data integrity.<\/p>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-6d0637bc68a5f2d0f72a48080a9d363e\" id=\"h-lessons-learned\" style=\"font-style:normal;font-weight:400\">Lessons Learned<\/h2>\n<p>A few key takeaways from the deployment:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>Unification accelerates operations<\/strong>\n<p>Bringing SOC and NOC data into a single platform\u00a0improves operations and makes new insights possible<\/p>\n<\/li>\n<li><strong>Data onboarding is the hardest\u2014and most important\u2014step<\/strong>\n<p>Once data is flowing and normalized, building dashboards and detections becomes significantly easier.<\/p>\n<\/li>\n<li><strong>Edge engineering still matters in cloud-first architectures<\/strong>\n<p>Components like RSYSLOG and Heavy Forwarders\u00a0remain\u00a0critical for handling real-world data ingestion challenges.<\/p>\n<\/li>\n<li><strong>Speed is achievable with the right abstractions<\/strong>\n<p>Building a production-grade NOC dashboard in hours\u2014not days\u2014is realistic when the platform is designed for it.<\/p>\n<\/li>\n<\/ul>\n<p>Check out the\u00a0lessons learned\u00a0from\u00a0the Event SOCs we deploy around the world, with\u00a0the white paper\u00a0and latest blogs.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p class=\"has-text-align-center\" id=\"block-a1b11bef-8542-478b-95c4-6b43d582001b\"><em>We\u2019d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.<\/em><\/p>\n<p class=\"has-text-align-center\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cisco-green-color\">Cisco Security Social Media<\/mark><\/strong><\/p>\n<p class=\"has-text-align-center\" id=\"block-85b5e58a-7e0a-4b88-a1bd-54a5f658e51f\">LinkedIn<br \/>Facebook<br \/>Instagram<\/p>\n<\/p><\/div>\n<p><script async defer src=\"https:\/\/platform.instagram.com\/en_US\/embeds.js\"><\/script><br \/>\n<br \/><p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mobile World Congress (MWC) Barcelona is one of the most demanding environments for network and security operations. With thousands of attendees,\u00a0unmanaged\u00a0devices, and applications interacting in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":16953,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-16952","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/16952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/comments?post=16952"}],"version-history":[{"count":0,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/16952\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media\/16953"}],"wp:attachment":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media?parent=16952"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/categories?post=16952"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/tags?post=16952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}