Splunk® Asset and Risk Intelligence

Administer Splunk Asset and Risk Intelligence

Splunk Asset and Risk Intelligence is not compatible with Splunk Enterprise 9.1.2 due to known issues SPL-237796, SPL-248319 where search results in "results" have more rows than expected. Upgrade to Splunk Enterprise 9.1.3 to use Splunk Asset and Risk Intelligence.

Add a custom field in Splunk Asset and Risk Intelligence

Add business-specific custom fields to any of the following inventories in Splunk Asset and Risk Intelligence:

  • Asset
  • IP address
  • Identity
  • MAC address
  • Software
  • Vulnerability

To see a list of the default fields for each inventory, see Field reference for Splunk Asset and Risk Intelligence.

Add a custom field

There are two parts to adding custom data fields in Splunk Asset and Risk Intelligence:

  • Part 1: Define the custom field for an inventory
  • Part 2: Edit the event search for a batched data source

Part 1: Define the custom field for an inventory

To add a custom field to Splunk Asset and Risk Intelligence, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin then Data sources and then Custom data field management.
  2. Select Add field for the inventory you want to add a custom field to.
  3. Enter the field name.
  4. (Optional) Select the check box to hide the field from the investigation view. Hiding the field removes it from the Record panel on the investigation page.
  5. Select Add.

Part 2: Edit the event search for a batched data source

To populate your custom fields, edit the event search for a batched data source. Make sure that the Search for events contains the custom fields you want to add. See Create or modify an event search.

View custom data field values

After you add a custom field, you can find it by selecting Admin then Data sources and then Custom data field management.

To see a list of values for a custom field, select Admin then Data enrichment and then Custom data listing.

Last modified on 28 February, 2025
Data source field mapping reference   Manage asset inventory retention in Splunk Asset and Risk Intelligence

This documentation applies to the following versions of Splunk® Asset and Risk Intelligence: 1.1.1


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters