Use the Automation Builder Agent to build and understand playbooks
describes how to build and work with SOAR playbooks using the agent
Use the Splunk SOAR Automation Builder Agent to build and explain playbooks and their associated information. The Automation Builder Agent is available for new and existing playbooks, including playbooks you are in the middle of creating.
Before you begin
Your stack must be running Splunk Cloud Platform 10.1 or higher
Splunk SOAR (Cloud) must be paired with Splunk Enterprise Security version 8.6.0 or higher. For pairing details, see the following documentation and consult your Splunk administrator:
-
From the Splunk SOAR side: Pair Splunk SOAR (Cloud) with Splunk Enterprise Security
-
From the Splunk Enterprise Security side: Pair Splunk Enterprise Security with Splunk SOAR
Users must use their Splunk user account in one of these ways:
-
Log into Splunk SOAR with their Splunk user account
-
Log into Splunk Enterprise Security and navigate to Splunk SOAR.
The Automation Builder Agent works with the following playbook types:
-
SOAR playbooks: References SOAR container information
-
Enterprise Security playbooks: References Enterprise Security investigations and findings.
Capabilities and prompt suggestions
The Automation Builder Agent includes the following capabilities to help you with your organization's automation. After each capability are examples of how you might prompt the agent for specific actions and information.
Create and configure playbooks.
-
Ask the agent to create a playbook with specific functionalities.
-
Ask the agent to configure a specific playbook block with a specific datapath.
Explain and describe playbooks.
-
Ask what a certain playbook or playbook block does and how it works, especially under specific conditions.
-
Ask how a certain playbook would respond to a specific incident or type of incident.
Run and troubleshoot playbooks.
-
Ask the agent to run a specific playbook. If the playbook fails, the agent can then point out where the failure occurred and provide potential fixes.
-
Ask the agent if it can find issues with items outside of the playbook, like permissions on an asset, and suggest fixes. If the agent has control over that item, you can ask the agent to fix the item.
-
Explain SOAR concepts interactively.
-
Ask about the purpose of a specific playbook block type.
-
Ask what a datapath signifies in a specific playbook block.
Make targeted, in-place edits to existing blocks (datapaths, filter conditions, parameters) without rewriting the rest of the playbook.
-
Ask the agent to change conditions of a filter block within a playbook.
-
Ask the agent to use a different datapath in a specific action block.
-
Recommend and identify best practices.
-
Ask if a specific playbook is following best practices.
-
Ask the agent to update a specific playbook to follow best practices.
-
Ask about common automation use cases that you might want to use.
Understand the environment beyond the playbooks to find and make recommendations.
-
Ask which apps are available for a certain topic, like enrichment.
-
Ask for suggestions for which app to use for a certain activity, like quarantining hosts.
-
Ask to find an incident that you recently worked on, then work to automate it.
-
Describe an internal SOC workflow that you want to automate and ask to make a playbook for it.
Locate the Automation Builder Agent in the Visual Playbook Editor
Reach the Automation Builder Agent within the Splunk SOAR Visual Playbook Editor (VPE).
To open the Visual Playbook Editor, follow these steps:
-
Open the Playbooks page:
-
Within Splunk SOAR: From the Home menu, select Playbooks. Open an existing playbook or select +Playbook.
-
Within Splunk Enterprise Security: From the Security content menu, select SOAR Playbooks.
-
-
Select an existing playbook or select +Playbook to create a new playbook.
Interact with the Automation Builder Agent
-
To start a chat with the Automation Builder Agent, select the circle sparkle icon
.
-
In the prompt field, ask a question or select one of the suggested prompts. Continue to use the same chat to ask related questions and refine your prompt.
If you ask the agent to create or configure a playbook or playbook block, the agent makes suggestions on the playbook editor canvas. Review the suggestions carefully. When ready, accept the suggestions in the chat.
-
To start a new chat, abandoning your current thread, select the new chat icon
.
-
Copy or download the agent response to use or save it somewhere else. Select the copy
or download
icon.
-
Provide feedback to the agent's response by selecting the thumbs up or thumbs down icon within the chat panel.
See also
For details on playbooks and the Visual Playbook Editor, review other portions of this guide, including: