Analyze the findings using the Triage agent
Use the Triage agent to automatically analyze and triage findings by assigning a disposition to them based on evidence.
Analyze the findings using the Triage agent
Prerequisite: You must turn on the Triage agent. For more information, see Turn on or turn off the triage agent.
Follow these steps to analyze the findings using the Triage agent:
- In Splunk Enterprise Security, go to the Analyst queue and access the finding details.
- Go to the Analysis panel.
The Analysis panel contains the following fields:
- Summary:Describes the incident and the disposition outcome.
- Justification:Provides details on how the disposition was reached.
- Tools: Provides a record of all the tools used to gather additional information.
- Evidence: Provides hypothesis analysis and supporting data.
- Analysis Details: Provides details of the finding and the precise steps that are run for the investigation, analysis, reasoning details, and how the evidence was weighed to reach the final disposition.
Note: The daily finding limit is approximately 200 findings for each tenant per day.