How to use the AI Assistant to summarize findings during triage or investigation
Note: The AI Assistant for Splunk Enterprise Security is not automatically available by default. An administrator must reach out to their account team to get started.
Use the AI Assistant to help triage findings efficiently and reduce the time to escalate critical issues. You can ask the assistant for plain-language explanations of findings to share with stakeholders and request SPL searches to investigate further.
In Splunk Enterprise Security, select Mission Control.
Select an investigation from the analyst queue.
Select View details to open the investigation Overview page.
Select the AI Assistant icon ()to open the chat box and get started.
Splunk Enterprise Security provides a few default requests to ask the AI Assistant. Select Summarize the findings.
Note: If the AI Assistant is generating too long of a response, you can select the stop icon () to stop the AI Assistant.