Specify SOAR connectors to enrich findings using the Triage agent
Specify the SOAR connectors that the Triage agent can use for autonomous enrichment or to perform adaptive response actions in Splunk Enterprise Security.
Follow these steps to specify the SOAR connectors that the Triage agent can use for autonomous enrichment or to perform adaptive response actions in Splunk Enterprise Security:
- In Splunk Enterprise Security, select Configure and then All configurations.
- Select Triage agent.
- Select the Connectors tab to view a list of SOAR connectors that are pre-selected for access by the triage agent.
- Select the connectors to which you want to provide access to the Triage agent. For example, you can select MaxMind that provides IP geolocation. Alternatively, you can also deselect connectors from the list. For example, if you have a limited quota for VMRay, you might want to deselect that connector.
- Select the actions from the list that you want the Triage agent to use enriching findings and investigations. For example, test connectivity, geolocate ip, update data, on poll, and so on.