Add and manage filters in Splunk Asset and Risk Intelligence
You can modify and delete any saved filters from reports on the Filter management page of Splunk Asset and Risk Intelligence. For example, if a user created a filter for particular assets discovered by Splunk Asset and Risk Intelligence in the Network asset discovery dashboard, you can narrow or expand the scope of that filter.
You can also add a new custom filter for a report directly from the Filter management page.
Add a custom filter
To add a custom filter, complete the following steps:
- In Splunk Asset and Risk Intelligence, select Admin and then Filter management.
- Select Add inventory filter.
- Select the dashboard or report you want to create a filter for. For example, Software inventory summary.
- Create your filter. For more information on how to create a custom filter, see Filter your asset reports in the Investigate Assets and Assess Risk in Splunk Asset and Risk Intelligence manual.
- Select Add.
Manage filters
To manage report filters, complete the following steps:
- In Splunk Asset and Risk Intelligence, select Admin and then Filter management.
- Locate the filter you want to modify or delete in the filter table.
Each filter has a scope with one of two values:
user
orapp
. A filter with the app scope can be seen by other users. A filter with the user scope can be seen only by the user who created that filter. - To modify the filter, select the settings icon ( ).
- Make your changes.
- Select Update.
- To delete a filter, select the delete icon ( ).
Turn on or turn off discovery searches in Splunk Asset and Risk Intelligence | Add and manage asset types in Splunk Asset and Risk Intelligence |
This documentation applies to the following versions of Splunk® Asset and Risk Intelligence: 1.0.0, 1.0.1, 1.0.2
Feedback submitted, thanks!