What a Decade of Live-Event SOCs Teaches About Network Telemetry: Enriched, Normalized, Decision-Ready

For ten years, Cisco and Splunk have run the Security Operations Center at the RSAC Conference, and this year Splunk published a retrospective on what a decade of live-event SOCs has taught them. It is worth reading, because a conference SOC is one of the most honest stress tests in security. The network is open and unmanaged, there is almost no time to baseline, the traffic is noisy, and analysts have to move from signal to evidence to decision in minutes.

The scale alone makes the point. This year the RSAC SOC observed more than 20,000 unique devices, over 63 million DNS requests, and more than 25 terabytes of packet data. In that environment, the lesson Splunk draws is not about any single tool. It is about the shape of the data. As they put it, the future of security operations depends on turning diverse telemetry into decision-ready workflows, which requires normalization, enrichment, and automation before an analyst ever sees it.

That is the network-telemetry problem NetFlow Optimizer exists to solve. The RSAC SOC frames it clearly, and the framing applies far beyond the conference floor.

A Detection Is Not Just a Search

One line from the retrospective captures the whole idea. Describing what they learned from turning live-event findings into real detections, the Splunk team writes that a detection “is not just a search. It has to be understandable, actionable, routed correctly, enriched with the right context, and connected to an outcome.” That is a precise description of why raw telemetry is not enough.

Raw network flow is the opposite of decision-ready. A NetFlow record shows source and destination IPs, ports, and byte counts. It is not enriched with the user behind an address, the application in use, or the reputation of a destination. It is not normalized to a consistent schema. In a live SOC, where there is, in Splunk’s words, limited baselining, a noisy environment, and many unmanaged devices, handing an analyst raw flow records is handing them more work at the worst possible moment.

Splunk’s ten-year lesson from the RSAC SOC: the value is not in collecting telemetry, it is in making it decision-ready before the analyst sees it. Normalized, enriched, connected to an outcome. That is exactly what a network telemetry pipeline has to do to NetFlow before it reaches the SIEM.

Where NFO Fits the RSAC SOC Pattern

The RSAC SOC in a Box connected many tools: full packet capture, Splunk Enterprise Security, firewall and access telemetry, threat intelligence, and more. NetFlow Optimizer (NFO) occupies one specific and essential place in a pattern like this: it turns raw, binary network flow into the normalized, enriched, decision-ready telemetry the SOC lesson calls for.

NFO parses the binary NetFlow, IPFIX, sFlow, and J-Flow that network devices export, which a SIEM cannot ingest in raw form, normalizes it to a common information model, and enriches every record with user identity, application, threat intelligence, and geographic context. It reduces volume by 80 to 90% through aggregation so that full-fidelity flow telemetry is sustainable at scale. What lands in Splunk is already in the form the RSAC lesson describes.

RSAC SOC lessonWhat NFO does to NetFlow
Normalize diverse telemetryParses binary flow to a common information model
Enrich with the right contextAdds user, application, threat intel, geo per record
Make it sustainable at scaleReduces volume 80 to 90% via aggregation
Connect signal to outcomeDelivers decision-ready records to the SIEM

The detection, correlation, and automated response happen where the RSAC SOC put them: in Splunk Enterprise Security and SOAR, where the team builds and owns the logic. NFO does not detect, alert, or decide. It ensures the network telemetry feeding those workflows is already decision-ready, which is precisely the gap the retrospective identifies.

The Cleartext Credentials Example

The retrospective gives a concrete case: cleartext usernames and passwords still appearing on the network through insecure or legacy protocols such as HTTP and unencrypted POP3. The SOC turned that recurring finding into a formal detection wired to an automated response, work that ultimately saved more than nine hours of analyst time during the event.

Flow telemetry is well suited to surfacing exactly this class of signal. NFO delivers enriched records showing traffic on the ports and protocols associated with legacy or unencrypted services, attributed to a user and application. It does not inspect the payload or read the credentials, that is not what flow data does, but it makes the presence of legacy-protocol traffic visible and attributable in the SIEM, where the detection logic then fires. The pattern is identical to the RSAC lesson: enriched, attributed telemetry in, detection and automated outcome out.

What NFO Does Not Do, and Why That Matters Here

The RSAC SOC leaned heavily on capabilities NFO deliberately does not provide, and being clear about that boundary matters. The SOC ran Endace full packet capture for forensic, packet-level evidence, and used Cisco’s Encrypted Visibility Engine to derive signals from encrypted sessions without decryption. NFO is not a packet capture tool and does not inspect or decrypt payloads. It operates at the flow layer.

These are complementary, not competing. Packet capture gives you the deep forensic record for the cases that need it. Enriched flow telemetry gives you continuous, attributed, affordable visibility across the whole network, the always-on layer that tells you what is communicating with what, enriched with the context an analyst or a detection needs. A well-built SOC, at RSAC or in production, uses both: flow for breadth and continuous context, packet capture for depth where an investigation demands it.

The Bottom Line

Ten years of running the RSAC SOC led Splunk to a clear conclusion: telemetry only matters when it is normalized, enriched, and decision-ready before the analyst sees it. For network flow data, that transformation is exactly what NetFlow Optimizer performs, parsing binary flow, enriching every record with identity, application, and threat context, reducing volume so it is sustainable, and delivering it to the SIEM in a form the detection logic can act on.

The conference network is a compressed version of every enterprise network: noisy, partly unmanaged, and short on time. The lesson travels. Decision-ready network telemetry is not a luxury for the busiest moments. It is the foundation the busiest moments depend on.

Want your NetFlow decision-ready in Splunk before it reaches an analyst? Start a free 60-day trial of NetFlow Optimizer or schedule a technical demo with a NetFlow Logic engineer.

Start Free Trial  |  Schedule a Demo  |  Splunk Integration  |  NFO Documentation

Scroll to Top