Turn on or turn off the triage agent for certain detections

You must turn on the AI triage agent. See Turn on or turn off the triage agent.

Start setting up the AI triage agent to autonomously investigate findings as they show up in queues. Select which event-based detections the AI triage agent analyzes findings for.
  1. In Splunk Enterprise Security, select Configure and then All configurations.
  2. Select Triage agent.
  3. Select the Detections tab.
  4. (Optional) Filter for certain event-based detections using the drop-down menus for Detection status and AI triage status.
  5. To turn or turn off the AI agent for event-based detections, you can do one or both of the following:
    Note: You can only turn on the AI triage agent for event-based detections that are already on. If the Detection status is off, you must turn it on in the detection editor before using it with the AI triage agent.
    1. For a single detection, use the drop-down menu in the AI agent triage status column to select On or Off.
    2. For multiple detections, select the check boxes for the detections you want, and then select Turn on AI triage or Turn off AI triage.
For more information on how to use the AI triage agent, see AI analysis in Splunk Enterprise Security.