Agentic AI offerings in Splunk Enterprise Security

overview of available AI-powered agents

Splunk Enterprise Security offers the following AI-powered agents to assist with tasks such as create SPL for detections, triage findings, and so on.

Read below the table for important information on all agents.

Note: The AI features in Splunk Enterprise Security are subject to Microsoft's Azure OpenAI

Acceptable Use Policy

and Code of Conduct Content requirements.

Compatibility information for AI agents in Splunk Enterprise Security

The following table provides information on the AI agents in Splunk Enterprise Security such as compatibility and availability:

Agent name Description Availability Compatibility information
Automation Builder agent Build and explain playbooks and their associated information. Available for new and existing playbooks. For more information, see Use the Automation Builder Agent to build and understand playbooks. Essentials and Premier (Cloud only) Paired SOAR instance on your deployment of Splunk Enterprise Security
Detection Builder agent Create, tune, validate, and troubleshoot detections using the integrated AI Assistant available in the detection editors to optimize their effectiveness and reduce the time required to create the SPL query. For more information, see Author detections using the Detection Builder agent in Splunk Enterprise Security. Essentials and Premier (Cloud, North America only)
  • Splunk Platform version 10.1.x or higher
  • Splunk Enterprise Security version 8.6 or higher
Guided Response agent Identify and run SOAR response actions on findings using the using the integrated AI assistant so that you can accelerate the security response in Splunk Enterprise Security. For more information, see Run SOAR response actions using the Guided Response Agent in Splunk Enterprise Security. Essentials and Premier (Cloud only)
  • Splunk Platform version 10.2.x or higher
  • Splunk Enterprise Security version 8.6 or higher.
  • Paired SOAR instance on your deployment of Splunk Enterprise Security
Malware Reversing and Phishing agent Review and investigate potentially malicious scripts by automatically generating a structured summary of script behavior to help reverse malware or analyze a phishing attempt. For more information, see Analyze scripts using the AI-powered Malware Reversing Agent and Phishing Analysis Agent in Splunk Enterprise Security. Premier (cloud only)
  • Splunk Enterprise Security version 8.5 or higher
  • Paired SOAR instance on your deployment of Splunk Enterprise Security
.
Standard Operation Procedure (SOP) agent Import an existing Standard Operation Procedure (SOP) in Splunk Enterprise Security and convert it into a structured response plan. For more information, see Create response plans with the SOP agent. Essentials and Premier (Cloud only)
  • Enterprise Security AI assistant enabled on your Enterprise Security deployment.

  • Individuals using the SOP agent must have view and edit response template capabilities.

Triage agent Autonomously investigate findings as they are displayed in a queue by providing a disposition, a clear rationale, and recommended next steps before a human touches the finding. For more information, see Setting up the Triage agent in Splunk Enterprise Security. Premier (Cloud only)
  • Splunk Platform version 10.2.x or higher
  • Splunk Enterprise Security version 8.6 or higher.
  • Paired SOAR instance on your deployment of Splunk Enterprise Security
Note: Agentic chat version 1 is available on both on-premises and Cloud deployments of Splunk Enterprise Security. Agentic chat model version 2 is available on Cloud only.

Turn agentic AI offerings on or off

You can configure all agentic AI offerings to be either on or off for your organization. Agentic AI offerings will not work if set to off.

  1. In Splunk Enterprise Security, select Configure and then All configurations.
  2. Select Security AI Assistant settings.
  3. In the AI Assistant availability section, toggle the setting to turn on or turn off the AI Assistant.