Choose which models the AI Assistant uses in Splunk Enterprise Security

Note: AI features for Splunk Enterprise Security must be turned on by an administrator on the Security AI Assistant settings page.The AI features in Splunk Enterprise Security are subject to Microsoft's Azure OpenAI

Acceptable Use Policy

and Code of Conduct Content requirements.

The AI Assistant uses data models to provide results for your prompts. Choose between Frontier or Splunk-hosted models for the AI Assistant to use based on your organization's compliance requirements.

To modify the model settings in Splunk Enterprise Security, follow these steps:

  1. In Splunk Enterprise Security, select Configure then All configurations and then Security AI Assistant settings.
  2. In the Model choice section, select the bubble for your preferred model usage.
  3. Select Save.