Splunk® Asset and Risk Intelligence

Investigate Assets and Assess Risk in Splunk Asset and Risk Intelligence

Splunk Asset and Risk Intelligence is not compatible with Splunk Enterprise 9.1.2 due to known issues SPL-237796, SPL-248319 where search results in "results" have more rows than expected. Upgrade to Splunk Enterprise 9.1.3 to use Splunk Asset and Risk Intelligence.

Customize investigations in Splunk Asset and Risk Intelligence

You can customize your investigation by adding notes to assets and identities.

Create and manage notes for assets and identities

You can save additional data about assets and identities by creating a note associated with the asset or identity. For example, you might add a note that explains when you expect an asset to be decommissioned or why an account was created.

To create a note, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Investigation from the main menu navigation bar.
  2. From the drop-down list, select either Asset investigation or Identity investigation.
  3. Enter the asset or identity you want to add a note to.
  4. Select Submit.
  5. Select the edit icon ( edit ) on the Record panel.
  6. Select Add note.
  7. Enter your note.
  8. Select Add.

You can also manage your existing notes by selecting the edit icon ( edit ) or the delete icon ( remove ).

Last modified on 28 February, 2025
Investigate assets and identities in Splunk Asset and Risk Intelligence   Use Splunk Asset and Risk Intelligence data with Splunk Enterprise Security

This documentation applies to the following versions of Splunk® Asset and Risk Intelligence: 1.1.1


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters