Alert Triage Agent
Agentic triage begins at the Alerts tier of the SOC Operations workflow. By default, alerts generated by an alert rule are automatically evaluated by the Alert Triage Agent when Auto Triage with AURA is enabled for the rule. See Creating Alert Rules for details.
The Alert Triage Agent evaluates each alert along with relevant context, including enrichment data, entity risk, historical activity, threat intelligence, and relationships with other alerts. The Agent can also recognize when several alerts that may not warrant escalation individually become significant when considered together.
Based on its analysis, the Alert Triage Agent can recommend one of the following outcomes:
Promote—alert warrants creation of an incident on its own.
Investigate—additional analysis is needed before reaching a verdict.
Monitor—activity is not yet actionable but should remain under observation.
Dismiss as a false positive—no further action is required.
You can review the agent recommendation, reasoning, supporting evidence, and agent trace from the alert details pages in the Approval Queue. See Using Approval Queue for details.
If you select Promote and approve the recommendation, the agent automatically:
-
Creates an incident.
-
Associates the source alert or alerts with the incident.
-
Updates the source alerts to indicate that they are linked to an incident.
-
Assigns the appropriate incident type.
-
Automatically assigns the Incident & Investigation Agent to perform investigation. See Incident & Investigation Agent for more information.
For details on monitoring and managing activity of the Alert Triage Agent, refer to Monitoring Status and Activity of Individual Agents.