Use the Automation Builder Agent to build and understand playbooks

describes how to build and work with SOAR playbooks using the agent

Use the Splunk SOAR Automation Builder Agent to build and explain playbooks and their associated information. The Automation Builder Agent is available for new and existing playbooks, including playbooks you are in the middle of creating.

Before you begin

Note: This feature is not available on FedRAMP Splunk SOAR stacks.

Your stack must be running Splunk Cloud Platform 10.1 or higher

Splunk SOAR (Cloud) must be paired with Splunk Enterprise Security version 8.6.0 or higher. For pairing details, see the following documentation and consult your Splunk administrator:

Users must use their Splunk user account in one of these ways:

  • Log into Splunk SOAR with their Splunk user account

  • Log into Splunk Enterprise Security and navigate to Splunk SOAR.

The Automation Builder Agent works with the following playbook types:

  • SOAR playbooks: References SOAR container information

  • Enterprise Security playbooks: References Enterprise Security investigations and findings.

Capabilities and prompt suggestions

The Automation Builder Agent includes the following capabilities to help you with your organization's automation. After each capability are examples of how you might prompt the agent for specific actions and information.

Note: As with all AI, include a human in the loop. Review and test the playbook before marking it as active and using it.

Create and configure playbooks.

  • Ask the agent to create a playbook with specific functionalities.

  • Ask the agent to configure a specific playbook block with a specific datapath.

Explain and describe playbooks.

  • Ask what a certain playbook or playbook block does and how it works, especially under specific conditions.

  • Ask how a certain playbook would respond to a specific incident or type of incident.

Run and troubleshoot playbooks.

  • Ask the agent to run a specific playbook. If the playbook fails, the agent can then point out where the failure occurred and provide potential fixes.

  • Ask the agent if it can find issues with items outside of the playbook, like permissions on an asset, and suggest fixes. If the agent has control over that item, you can ask the agent to fix the item.

  • Explain SOAR concepts interactively.

    • Ask about the purpose of a specific playbook block type.

    • Ask what a datapath signifies in a specific playbook block.

    Make targeted, in-place edits to existing blocks (datapaths, filter conditions, parameters) without rewriting the rest of the playbook.

    • Ask the agent to change conditions of a filter block within a playbook.

    • Ask the agent to use a different datapath in a specific action block.

Recommend and identify best practices.

  • Ask if a specific playbook is following best practices.

  • Ask the agent to update a specific playbook to follow best practices.

  • Ask about common automation use cases that you might want to use.

Understand the environment beyond the playbooks to find and make recommendations.

  • Ask which apps are available for a certain topic, like enrichment.

  • Ask for suggestions for which app to use for a certain activity, like quarantining hosts.

  • Ask to find an incident that you recently worked on, then work to automate it.

  • Describe an internal SOC workflow that you want to automate and ask to make a playbook for it.

Locate the Automation Builder Agent in the Visual Playbook Editor

Reach the Automation Builder Agent within the Splunk SOAR Visual Playbook Editor (VPE).

To open the Visual Playbook Editor, follow these steps:

  1. Open the Playbooks page:

    • Within Splunk SOAR: From the Home menu, select Playbooks. Open an existing playbook or select +Playbook.

    • Within Splunk Enterprise Security: From the Security content menu, select SOAR Playbooks.

  2. Select an existing playbook or select +Playbook to create a new playbook.

Interact with the Automation Builder Agent

  • To start a chat with the Automation Builder Agent, select the circle sparkle icon AI sparkle icon surrounded by a circle.

  • In the prompt field, ask a question or select one of the suggested prompts. Continue to use the same chat to ask related questions and refine your prompt.

    If you ask the agent to create or configure a playbook or playbook block, the agent makes suggestions on the playbook editor canvas. Review the suggestions carefully. When ready, accept the suggestions in the chat.

  • To start a new chat, abandoning your current thread, select the new chat icon chat bubble icon with a plus sign inside, used to indicate creating a new chat.

  • Copy or download the agent response to use or save it somewhere else. Select the copy copy icon in the agent chat or download download icon in the agent chaticon.

  • Provide feedback to the agent's response by selecting the thumbs up or thumbs down icon within the chat panel.

See also

For details on playbooks and the Visual Playbook Editor, review other portions of this guide, including: