Turn on or turn off the Triage agent
-
You must have Splunk Enterprise Security version 8.6 or higher (Premier edition), Splunk Platform version 10.1.x or higher on AWS Cloud.Note: The Triage agent is supported only on ES 8.6 Premier Edition.
-
You must pair Splunk Enterprise Security with Splunk SOAR. See Pair Splunk Enterprise Security with Splunk SOAR.
-
You must have the
es_ai_edit_settingscapability assigned to your role in order to use the Triage agent. -
You must turn on the AI Assistant in order to use the Triage agent. See Turn the AI Assistant on or off in Splunk Enterprise Security.
- In Splunk Enterprise Security, select Configure and then All configurations.
- Select Triage agent.
- In the AI agent activation box, turn on or turn off Allow the AI agent to review findings in your queue.