Splunk® Asset and Risk Intelligence

Administer Splunk Asset and Risk Intelligence

Splunk Asset and Risk Intelligence is not compatible with Splunk Enterprise 9.1.2 due to known issues SPL-237796, SPL-248319 where search results in "results" have more rows than expected. Upgrade to Splunk Enterprise 9.1.3 to use Splunk Asset and Risk Intelligence.

Customize settings in Splunk Asset and Risk Intelligence

As an admin, you can customize your experience with Splunk Asset and Risk Intelligence by modifying the configuration settings.

Reset the navigation menu

If a user added their own dashboards to the Splunk Asset and Risk Intelligence menu, you can reset the navigation menu to the default setting. You might also want to reset the navigation menu after upgrading the app. To reset the navigation menu, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. Under Navigation, select Reset navigation menus to default.

Set default and common countries

To avoid scrolling through country lists, you can specify countries to appear at the top of any drop-down country list in Splunk Asset and Risk Intelligence. To set default and common countries, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. If you want to set a default country, or one that's automatically selected, use the drop-down list under Default country to select a country.
  3. If you want to set common countries, or countries that appear at the top of lists for users to select from, use the drop-down list under Common countries to select countries, and then select Update.

Add a business name to discovered assets

Splunk Asset and Risk Intelligence automatically includes a field called business to every discovered asset. To update the business name, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. Under Business name, enter a name.
  3. Select Update.

Delete data

You can delete data from Splunk Asset and Risk Intelligence including inventory data, association data, asset notes, and metric exceptions.

To delete data, complete the following steps:

Deleting data permanently deletes it from Splunk Asset and Risk Intelligence.

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. In the Danger zone section, select Delete data for the data you want to delete:
    • Inventory data: includes all discovery data from the network, IP, user, MAC, software, and vulnerability inventories
    • Custom inventory data: includes any custom field values added to inventories
    • Association data: includes first and last name associations between users, hosts, IP addresses, and MAC addresses
    • Other data: includes asset notes and metric exceptions
Last modified on 05 August, 2024
Manage data filters in Splunk Asset and Risk Intelligence   Turn on or turn off discovery searches in Splunk Asset and Risk Intelligence

This documentation applies to the following versions of Splunk® Asset and Risk Intelligence: 1.0.0, 1.0.1, 1.0.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters