Setting up the AI SOC analyst agentic workflow in Splunk Enterprise Security
Use this agent for a complete end-to-end AI-assisted workflow from detection and triage to investigation and response. By preserving the context and providing a coherent analysis, this explainable agentic experience helps to reduce the review time and improves the quality and consistency of your security decisions, as you triage findings and move them to an investigation. Thus, you can reduce the risk of genuine critical threats slipping through the review process as you discard the false or benign positives and focus on investigating real security threats.
What the AI SOC analyst agent does
When you select a finding in the queue, an AI Analysis section appears in the side panel. The agent has already investigated the finding by the time you open it, searching your third-party connectors and gathering relevant evidence.
If you want to investigate further, select View details for a step-by-step breakdown of the agent's investigation, including the full timeline of actions taken and the specific evidence that informed each conclusion. You can ask questions about which finding was most important or which SPL was run. You can also summarize the analysis for multiple findings in an investigation as long as at least one finding was processed by the AI SOC analyst agent. Every step is documented inline, so that analysts can follow the agent's reasoning and act with confidence.
This AI analysis includes the following information:
- A suggested disposition recommendation. For example: true positive, false positive, benign positive, or other.
- A summary of the finding and the reasoning behind the recommended disposition.
- The tools and evidence consulted to reach the conclusion, including any connectors used during analysis.
- The triage coverage of findings. For example, the analysis might indicate how many findings were triaged, such as 4 out of 5 findings were triaged.
- The relationships between findings.
- Any key evidence and justification for the analysis.
- Specific findings that drove the analysis and triage results.
You have the option to set the condition so that the AI SOC analyst agent can promote a finding to an investigation. The AI SOC analyst can also identify and run the SOAR response actions on findings by following the response plan. You can set conditions such as Automatic run or Approval required for the various SOAR response actions and also configure an exception list using Exposure Analytics. You can also configure a post triage automation rule for specific detection types to configure a playbook that can be run after a finding is processed by the AI SOC analyst agent.
Response plans that are assigned to investigations are used to guide the agent. You can add descriptions, embed actions, and SPL searches to the agent so that it can prescribe tools that are more specific for the investigation.
How to use recommendations from the agent
The AI SOC analyst agent never changes any fields on your behalf. Its role is to give you a well-reasoned starting point so that you can make a faster, more confident decision. You remain in control of the final disposition.
When the AI SOC analyst agent is turned on by your administrator, it automatically analyzes incoming findings and surfaces its results directly in your workflow. Use the recommendation to validate your own assessment, skip repetitive investigative steps you would otherwise perform manually, or quickly close out findings the agent has identified as false or benign positives with high confidence.
Customize the scope of the SOC agent
Follow these steps to configure the scope of the agent and specify the actions that you want the agent to perform:
- In Splunk Enterprise Security, go to Configure.
- Select AI and then select AI SOC analyst for disposition suggestions using connectors and detections.
- Go to Allowed actions to select the actions that the agent can take such as start investigations or close findings.
- Set conditions for each suggested action that the agent is configured to do. For example, you can select Allow the AI SOC analyst to start investigations from findings when identified as Benign Positive. You can select Allow AI SOC analyst to close findings when identified as True Positive.
- Go to Connections to select the default SOAR asset for the connector.
- Select the actions to allow the agent to use them for finding or investigation enrichment. For example, you can select whether to run an action, the SOAR asset for the action, or wait for approval for the action, or whether to apply for a prompt exception.
- Go to Detections to change the investigation type for each detection and the primary response plan for each detection. For more information, see Run SOAR response actions using the Guided Response Agent in Splunk Enterprise Security.
Prerequisites to use the AI SOC analyst agent
Ensure that you meet the following guidelines to use this agent:
*The AI SOC analyst agent in Splunk Enterprise Security is supported on Cloud, if you are using the Premier Edition in Splunk Enterprise Security, where the agentic chat experience is available.
*You must turn on the AI Assistant. See Turn the AI Assistant on or off in Splunk Enterprise Security.
*You must also upgrade to Splunk Platform version 10.2 or higher and Splunk Enterprise Security version 8.7 or higher.
*Additionally, you must pair SOAR on your deployment of Splunk Enterprise Security.
*No specific capabilities are required to use the AI SOC analyst agent from the AI Assistant for Security. However, you must have permissions to the SOAR connectors that the agent runs. The AI SOC analyst agent inherits the SOAR permissions.
*You must have the required permissions to view the investigation.
*Your investigation must include at least one finding with AI triage results. Adding a finding later to the investigation won't generate results from the AI SOC analyst agent.
* Contact your Splunk representative to turn on the AI SOC analyst agent.
Analyze the findings using the AI SOC analyst agent
Use the AI SOC analyst agent to automatically analyze and triage findings by assigning a disposition to them based on evidence.
Follow these steps to analyze the findings using the AI SOC analyst agent:
- In Splunk Enterprise Security, go to the Analyst queue and access the finding details.
- Go to the AI Analysis panel. The Analysis panel contains the following fields:
- Summary: Describes the incident and the disposition outcome.
- Justification: Provides details on how the disposition was reached.
- Tools: Provides a record of all the tools used to gather additional information.
- Evidence: Provides hypothesis analysis and supporting data.
- Analysis Details: Provides details of the finding and the precise steps that are run for the investigation, analysis, reasoning details, and how the evidence was weighed to reach the final disposition.
Note: The daily finding limit is approximately 200 findings for each tenant each day.
Specify SOAR connectors to enrich findings using the AI SOC analyst agent
Specify the SOAR connectors that the AI SOC analyst agent can use for autonomous enrichment or to perform adaptive response actions in Splunk Enterprise Security.
Follow these steps to specify the SOAR connectors that the AI SOC analyst agent can use for autonomous enrichment or to perform adaptive response actions in Splunk Enterprise Security:
- In Splunk Enterprise Security, select Configure and then All configurations.
- Select AI SOC analyst agent.
- Select the Connectors tab to view a list of SOAR connectors that are pre-selected for access by the AI SOC analyst agent.
- Select the connectors to which you want to provide access to the AI SOC analyst agent. For example, you can select MaxMind that provides IP geolocation. Alternatively, you can also deselect connectors from the list. For example, if you have a limited quota for VMRay, you might want to deselect that connector.
- Select the actions from the list that you want the AI SOC analyst agent to use enriching findings and investigations. For example, testing connectivity, geolocating IP address, updating data, and so on.
Run SOAR response actions using the AI SOC analyst agent in Splunk Enterprise Security
Identify and run SOAR response actions on findings using the AI SOC analyst agent so that you can accelerate the security response in Splunk Enterprise Security by making it accessible to all. For more information on response plans, see Create response plans in Splunk Enterprise Security.
Note: Installing new connectors on SOAR automatically adds those connectors into the pre-selected list of connectors. The agent inherits SOAR permissions.
Following are some ways in which the AI SOC analyst agent can help suggest and run AI-assisted security response actions:
-
Identify the appropriate SOAR response action to run on the finding using a natural language prompt since multiple options to select response actions can create confusion.
-
Run the same response action across multiple connectors simultaneously, if required, to review one indicator of compromise (IOCs) across multiple sources.
-
Define response actions using the guidance provided by the agent based on several parameters in the context of the finding since most SOAR response actions have between three to six parameters.
-
Target multiple observables and run the same response action across several IOCs to get aggregated results for batch enrichment since findings in the real world rarely have a single IOC.
-
Couple data lookups with SOAR response actions so that there is adequate context for the suggested actions to be relevant and useful.
-
Initiate a SOAR response action that waits instead of returning results immediately since many SOAR actions are asynchronous and require human approval.
Follow these steps to use the AI SOC analyst agent to run response actions in Splunk Enterprise Security:
- In Splunk Enterprise Security, go to Automation.
- In the agentic chat, enter a prompt such as Check the reputation of the domain in the senders email address or Run Cisco Talos reputation on IP address xxx.xxx.xx.xxx to trigger the agent and identify the most appropriate SOAR response action to run.
The following table provides some sample prompts to run on the agentic chat for this agent:
| Sample prompt | Action description |
|---|---|
| Block an IP address <IP address> | The agent select the correct IP address to block based on context or provides a list of Ip addresses to block based on context. |
| Disable a user <username> | The agent requests double confirmation prior to disabling a user and the correct user is selected when multiple similar usernames might exist. |
| Check IP reputation <IP address> | The agent summarizes the information on the reputation of the provided IP address. |
| Enrich an IPaddress <IP address> across multiple threat intelligence sources such as Talos and VirusTotal | The agent provides results from both threat intelligence sources side by side and highlights discrepancies between the results surfaced without merging them. |
| Disable a specific user everywhere <username> | The agent disables the user across all identity providers and reports on the success or failure for each system. |
| Send a Slack message to the <#Slack channel> about a finding | The agent drafts a contextually relevant message and sends it to the specified channel. |
| Open a JIRA ticket for a finding | The agent provides the summary and description from the context of the finding and requests a priority level from the analyst. |