Splunk® Asset and Risk Intelligence

Administer Splunk Asset and Risk Intelligence

Splunk Asset and Risk Intelligence is not compatible with Splunk Enterprise 9.1.2 due to known issues SPL-237796, SPL-248319 where search results in "results" have more rows than expected. Upgrade to Splunk Enterprise 9.1.3 to use Splunk Asset and Risk Intelligence.
This documentation does not apply to the most recent version of Splunk® Asset and Risk Intelligence. For documentation on the most recent version, go to the latest release.

Add and manage filters in Splunk Asset and Risk Intelligence

You can modify and delete any saved filters from reports on the Filter management page of Splunk Asset and Risk Intelligence. For example, if a user created a filter for particular assets discovered by Splunk Asset and Risk Intelligence in the Network asset discovery dashboard, you can narrow or expand the scope of that filter.

You can also add a new custom filter for a report directly from the Filter management page.

Add a custom filter

To add a custom filter, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Filter management.
  2. Select Add inventory filter.
  3. Select the dashboard or report you want to create a filter for. For example, Software inventory summary.
  4. Create your filter. For more information on how to create a custom filter, see Filter your asset reports in the Investigate Assets and Assess Risk in Splunk Asset and Risk Intelligence manual.
  5. Select Add.

Manage filters

To manage report filters, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Filter management.
  2. Locate the filter you want to modify or delete in the filter table.

    Each filter has a scope with one of two values: user or app. A filter with the app scope can be seen by other users. A filter with the user scope can be seen only by the user who created that filter.

  3. To modify the filter, select the settings icon ( settings ).
    1. Make your changes.
    2. Select Update.
  4. To delete a filter, select the delete icon ( remove ).
Last modified on 23 January, 2025
Turn on or turn off discovery searches in Splunk Asset and Risk Intelligence   Add and manage asset types in Splunk Asset and Risk Intelligence

This documentation applies to the following versions of Splunk® Asset and Risk Intelligence: 1.0.0, 1.0.1, 1.0.2


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters