Troubleshoot AI Assistant in Splunk Enterprise Security

Following are some issues that you might see when using the agentic chat in Splunk Enterprise Security:

AI sparkle button is unavailable

Issue: AI sparkle button is unavailable.

​​Cause: The feature flag for the agentic chat is not turned on.

Solution:Upgrade to Splunk Cloud version 10.1.x or higher. Ensure that you have the following capabilities: edit_tokens_own, edit_tokens_all, and edit_correlationsearches.

Agentic chat is unable to complete the request.

Issue:The agentic chat is unable to complete the request.​​

Cause: Message cannot be processed.​​

Solution:Send the message again or create a new chat session​.

Agentic chat returns 500 error​

Issue: Chat return 500 error code.

Causes:
  • Splunk Platform version is lower than ​10.1​.0.
  • Deployment is on an on-premise environment.
  • Agentic chat feature was turned on in error.

Solution:Turn off the agentic chat feature and escalate as a provisioning or eligibility issue, if required.

Agentic chat returns 400 error​

Issue: Chat returns 400 error code.

Causes:
  • Token creation for Splunk Enterprise Security failed.​
  • Splunk JWT signing keys cannot be loaded​.
  • Deployment is on an on-premise environment.
  • Feature was turned on in error.

Solution: Turn off the agentic chat feature and escalate as a provisioning or eligibility issue, if required.​