Splunk® Asset and Risk Intelligence

Investigate Assets and Assess Risk in Splunk Asset and Risk Intelligence

Splunk Asset and Risk Intelligence is not compatible with Splunk Enterprise 9.1.2 due to known issues SPL-237796, SPL-248319 where search results in "results" have more rows than expected. Upgrade to Splunk Enterprise 9.1.3 to use Splunk Asset and Risk Intelligence.

Review discovery reports on assets and identities in Splunk Asset and Risk Intelligence

In Splunk Asset and Risk Intelligence, you can review summary reports on discovered assets, identities, software, and vulnerabilities. Discovery reports include data such as geographic locations and trends over time.

Access discovery reports

To find discovery reports in Splunk Asset and Risk Intelligence, complete the following steps:

  1. Select Discovery in the main menu navigation bar.
  2. Select the type of discovery report you want to view, such as Identity discovery or Asset discovery.

Filter discovery reports

You can filter discovery reports by particular fields or by a Search Processing Language (SPL) search. Then, you can save that filter and return to the same view at a later time. To create a report filter, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Discovery from the main menu navigation bar, and then select the discovery report you want to view. For example, Asset discovery.
  2. Select Show filters.
  3. For only the asset discovery, use the drop-down list to select a filter type, such as Asset or IP address.
  4. Enter a name for your filter.
  5. Using the drop-down list, select the time frame you want to search within.
  6. Choose how you want to use and share the filter by selecting the appropriate Sharing check boxes.
    1. Select the App check box to make the filter app-specific and available for other users to use for discovery.
    2. If you turn on App sharing, you can also make the filter a risk scoring filter by selecting the Risk check box. See Add a risk scoring filter.
  7. If you want to filter by fields, select Field filtering and then configure your filter using the drop-down lists. Select the add icon ( add ) to add an additional field.
  8. If you want to filter by a search, select SPL search and then enter the SPL into the Search box.

    You can filter by fields or by SPL search, but not by both. If you enter a search to filter by, then switching to field filtering clears any SPL data you've input.

  9. Select Search to see the results.
  10. Select Save as new filter.
  11. (Optional) To erase your configured filter, select Reset filter.

After you save a filter, you can return to that view by selecting it from the Filter drop-down list.

Add or remove fields in the details table

In the Asset details table of each discovery report, you can add or remove fields that appear in the table. To add or remove fields, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Discovery from the main menu navigation bar, and then select the discovery report you want to view. For example, Asset discovery.
  2. In the Asset details table, select the settings icon ( settings ).
  3. To add a field, use the drop-down list to select a new field. You can add more by selecting the add icon ( add ).
  4. To remove a field, select the remove icon ( remove ) next to the field name in the Selected fields box.
  5. (Optional) To erase any changes you made, select Reset fields.
  6. Select Update.

Export a report

To export a report from Splunk Asset and Risk Intelligence, complete the following steps:

  1. Select Discovery from the main menu navigation bar, and then select the discovery report you want to view. For example, Asset discovery.
  2. In the details table, select the download icon ( download ).
  3. Enter a name for the file.
  4. Select an Output format, such as JSON.
  5. Select Download.

Use insight dashboards to review reports on systems and accounts associated with discovered assets

You can use Splunk Asset and Risk Intelligence insight dashboards to review data on other discoveries, such as operating systems, IoT devices, and default accounts. To find insight dashboards, select Discovery in the main menu navigation bar. Then, select the insight dashboard you want to view. To learn more about what each dashboard reports on, see the following table:

Dashboard Description
Operating system insights Displays visualizations with data on operating systems, including operating systems that are out-of-date or no longer supported, detected with assets discovered by Splunk Asset and Risk Intelligence. The dashboard reports on different aspects of operating systems, such as asset type and operating system version.
Cloud asset insights

Displays visualizations with data on active cloud-provisioned assets discovered by Splunk Asset and Risk Intelligence.

IoT asset insights

Displays visualizations with data on active IoT devices discovered by Splunk Asset and Risk Intelligence. The dashboard reports on different aspects of IoT devices, such as device class, vendor, subnets, and overall activity.

OT asset insights Displays visualizations with data on active OT devices discovered by Splunk Asset and Risk Intelligence. The dashboard reports on different aspects of OT devices, such as device class, vendor, subnets and overall activity.
Default account insights Displays visualizations with data on default accounts discovered by Splunk Asset and Risk Intelligence. The dashboard reports on various counts and metrics about activity by detected default accounts.

You can select a row in the asset listing table to open the investigation for that particular user ID.
Last modified on 28 February, 2025
Customize the home page in Splunk Asset and Risk Intelligence   Investigate assets and identities in Splunk Asset and Risk Intelligence

This documentation applies to the following versions of Splunk® Asset and Risk Intelligence: 1.1.1


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters