Choose which models the AI Assistant uses in Splunk Enterprise Security

Note: The AI Assistant for Splunk Enterprise Security is not automatically available by default. An administrator must reach out to their account team to get started. The AI Assistant understands and supports natural language and is subject to Microsoft's Azure OpenAI

Acceptable Use Policy

and Code of Conduct Content requirements.

The AI Assistant uses data models to provide results for your prompts. Choose between Frontier or Splunk-hosted models for the AI Assistant to use based on your organization's compliance requirements.

To modify the model settings in Splunk Enterprise Security, follow these steps:

  1. In Splunk Enterprise Security, select Configure then All configurations and then Security AI Assistant settings.
  2. In the Model choice section, select the bubble for your preferred model usage.
  3. Select Save.