Splunk® Asset and Risk Intelligence

Administer Splunk Asset and Risk Intelligence

Splunk Asset and Risk Intelligence is not compatible with Splunk Enterprise 9.1.2 due to known issues SPL-237796, SPL-248319 where search results in "results" have more rows than expected. Upgrade to Splunk Enterprise 9.1.3 to use Splunk Asset and Risk Intelligence.

Add and manage filters in Splunk Asset and Risk Intelligence

You can modify and delete any saved filters from reports on the Filter management page of Splunk Asset and Risk Intelligence. For example, if a user created a filter for particular assets discovered by Splunk Asset and Risk Intelligence in the Network asset discovery dashboard, you can narrow or expand the scope of that filter.

You can also add a new custom filter for a report directly from the Filter management page.

Add a custom filter

To add a custom filter, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Filter management.
  2. Select Add inventory filter.
  3. Select the dashboard or report you want to create a filter for. For example, Software inventory summary.
  4. Create your filter. For more information on how to create a custom filter, see Filter your asset reports in the Investigate Assets and Assess Risk in Splunk Asset and Risk Intelligence manual.
  5. Select Add.

Manage filters

To manage report filters, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Filter management.
  2. Locate the filter you want to modify or delete in the filter table.

    Each filter has a scope with one of two values: user or app. A filter with the app scope can be seen by other users. A filter with the user scope can be seen only by the user who created that filter.

  3. To modify the filter, select the settings icon ( settings ).
    1. Make your changes.
    2. Select Update.
  4. To delete a filter, select the delete icon ( remove ).
Last modified on 05 August, 2024
Turn on or turn off discovery searches in Splunk Asset and Risk Intelligence   Add and manage asset types in Splunk Asset and Risk Intelligence

This documentation applies to the following versions of Splunk® Asset and Risk Intelligence: 1.0.0, 1.0.1, 1.0.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters