Agentic AI offerings in Splunk Enterprise Security

overview of available AI-powered agents

Use the agentic AI offerings in Splunk Enterprise Security to assist with tasks such as creating SPL for detections, triaging findings, investigating malicious scripts, building playbooks, and so on. The AI agents can help you work through investigations by summarizing findings, explaining activity in clear language, suggesting next steps. You can also use these agents to explore related activity and create notes or reports directly from an investigation. This can save time during triage and help you decide when to escalate, thus transforming your security operations center (SOC) into a truly agentic SOC.

Splunk Enterprise Security offers AI-powered agents for the following workflows to make the detection, investigation, and response to security threats faster and easier:

*AI SOC analyst

*AI detection engineer

*AI SOC architect

*AI threat hunter

Note: The AI features in Splunk Enterprise Security are subject to Microsoft's Azure OpenAI

Acceptable Use Policy

and Code of Conduct Content requirements.

Compatibility information for AI agents in Splunk Enterprise Security

The following table provides information on the AI agents in Splunk Enterprise Security such as compatibility and availability:

Agent name Description Availability Compatibility information
Automation Builder agent Build and explain new and existing playbooks and their associated information. For more information, see Use the Automation Builder Agent to build and understand playbooks. Essentials and Premier (Cloud only)
  • Paired SOAR instance on your deployment of Splunk Enterprise Security

  • Splunk Enterprise Security version 8.6 or higher

Connector Builder Agent Create connectors faster with an AI agent that can generate, test, and refine connectors, increasing automation coverage across more tools. For more information, see Create and edit connectors with the Connector Builder Agent Essentials and Premier (Cloud only)
  • Paired SOAR instance on your deployment of Splunk Enterprise Security
  • Splunk Enterprise Security version 8.7 or higher
Detection Builder agent Create, tune, validate, and troubleshoot detections using the integrated AI Assistant available in the detection editors to optimize their effectiveness and reduce the time required to create the SPL query. For more information, see Author detections using the Detection Builder agent in Splunk Enterprise Security. Essentials and Premier (Cloud only)
  • Splunk Platform version 10.1.x or higher
  • Splunk Enterprise Security version 8.6 or higher
AI SOC analyst agent Improves the quality and consistency of security decisions through an end-to-end explainable AI-assisted workflow from detection and triage to investigation and response. For more information, see Use SOC agent in Splunk Enterprise Security. Note: Contact your Splunk representative to turn on the SOC agent. Premier (Cloud only)
  • Splunk Platform version 10.2.x or higher
  • Splunk Enterprise Security version 8.6 or higher
  • Paired SOAR instance on your deployment of Splunk Enterprise Security
Malware Reversing and Phishing agent Review and investigate potentially malicious scripts by automatically generating a structured summary of script behavior to help reverse malware or analyze a phishing attempt. For more information, see Analyze scripts using the AI-powered Malware Reversing Agent and Phishing Analysis Agent in Splunk Enterprise Security. Premier (cloud only)
  • Splunk Enterprise Security version 8.5 or higher
  • Paired SOAR instance on your deployment of Splunk Enterprise Security
.
Standard Operation Procedure (SOP) agent Import an existing Standard Operation Procedure (SOP) in Splunk Enterprise Security and convert it into a structured response plan. For more information, see Create response plans with the SOP agent. Essentials and Premier (Cloud only)
  • Enterprise Security AI assistant enabled on your Enterprise Security deployment.

  • Individuals using the SOP agent must have view and edit response template capabilities.

Note: Agentic chat version 1 is available on both on-premises and Cloud deployments of Splunk Enterprise Security. Agentic chat model version 2 is available on Cloud only.

Turn agentic AI offerings on or off

You can configure all agentic AI offerings so that they are turned on or turned off for your organization.
Note: Agentic AI offerings won't work if they are turned off.
Follow these steps to turn agentic AI offerings on or off:
  1. In Splunk Enterprise Security, select Configure and then All configurations.
  2. Select AI and then select Global AI settings.
  3. In the AI availability section, toggle the setting to turn on or turn off all AI capabilities in your environment.