Analyze the findings using the Triage agent

Use the Triage agent to automatically analyze and triage findings by assigning a disposition to them based on evidence.

Note: For every detection that is run, only the first 10 findings can be triaged by the Triage agent, even if more than 10 findings are created for a detection.

Analyze the findings using the Triage agent

Prerequisite: You must turn on the Triage agent. For more information, see Turn on or turn off the triage agent.

Follow these steps to analyze the findings using the Triage agent:

  1. In Splunk Enterprise Security, go to the Analyst queue and access the finding details.
  2. Go to the Analysis panel.
    The Analysis panel contains the following fields:
    • Summary:Describes the incident and the disposition outcome.
    • Justification:Provides details on how the disposition was reached.
    • Tools: Provides a record of all the tools used to gather additional information.
    • Evidence: Provides hypothesis analysis and supporting data.
    • Analysis Details: Provides details of the finding and the precise steps that are run for the investigation, analysis, reasoning details, and how the evidence was weighed to reach the final disposition.
    Note: The daily finding limit is approximately 200 findings for each tenant per day.