Turn on or turn off the Triage agent

Start setting up the Triage agent to autonomously investigate findings as they show up in queues.
Note: Only frontier models for the Triage agent are supported. Selecting support for the Splunk hosted option does not apply. If this is incompatible with your deployment, you must not turn on the agent.
  1. In Splunk Enterprise Security, select Configure and then All configurations.
  2. Select Triage agent.
  3. In the AI agent activation box, turn on or turn off Allow the AI agent to review findings in your queue.
Turn on or turn off the triage agent for certain detections