Turn on or turn off the Triage agent

  • You must have Splunk Enterprise Security version 8.6 or higher (Premier edition), Splunk Platform version 10.1.x or higher on AWS Cloud.
    Note: The Triage agent is supported only on ES 8.6 Premier Edition.
  • You must pair Splunk Enterprise Security with Splunk SOAR. See Pair Splunk Enterprise Security with Splunk SOAR.

  • You must have the es_ai_edit_settings capability assigned to your role in order to use the Triage agent.

  • You must turn on the AI Assistant in order to use the Triage agent. See Turn the AI Assistant on or off in Splunk Enterprise Security.

Start setting up the Triage agent to autonomously investigate findings as they show up in queues.
Note: Only frontier models for the Triage agent are supported. Selecting support for the Splunk hosted option does not apply. If this is incompatible with your deployment, you must not turn on the agent.
  1. In Splunk Enterprise Security, select Configure and then All configurations.
  2. Select Triage agent.
  3. In the AI agent activation box, turn on or turn off Allow the AI agent to review findings in your queue.
Turn on or turn off the triage agent for certain detections