Splunk® Asset and Risk Intelligence

Administer Splunk Asset and Risk Intelligence

Splunk Asset and Risk Intelligence is not compatible with Splunk Enterprise 9.1.2 due to known issues SPL-237796, SPL-248319 where search results in "results" have more rows than expected. Upgrade to Splunk Enterprise 9.1.3 to use Splunk Asset and Risk Intelligence.

Manage asset inventory retention in Splunk Asset and Risk Intelligence

Splunk Asset and Risk Intelligence automatically stores asset records in its inventories for an indefinite period of time. Over time, your asset inventories can grow significantly in size. You might want to remove assets that haven't been active in a long time or assets that are no longer accurate. For example, imagine Splunk Asset and Risk Intelligence detects an IP address on a host. After over a month with no activity, the IP address still lacks any updates. As a result, some of the field values for this asset might not be accurate anymore, so you might want to remove the values assigned to particular fields within the inventory.

To manage the size of your asset inventories, you can modify the retention period for asset records, and you can also modify the retention period for particular field values.

Modify the retention period for asset inventory records

To modify the retention period for asset inventory records, complete the following steps:

Activating a retention period can result in the permanent deletion of data.

  1. In Splunk Asset and Risk Intelligence, select Admin then Data sources and then Inventory aging management.
  2. Select the settings icon ( settings ) for the inventory you want to modify.
  3. Enter a retention period in seconds. The retention period is based on the last detected date in Splunk Asset and Risk Intelligence. If an asset hasn't been detected in the period of time you specify, Splunk Asset and Risk Intelligence removes it.
  4. Select Update.
  5. Select Admin and then Configuration settings.
  6. In the Inventory record retention searches section, select the toggle switch for the inventory that you modified to activate that retention period.

After you modify the retention period and activate it, you can find the updated data retention time for the inventory on the Inventory aging management page. The status for the inventory displays Active.

Modify the retention period for asset inventory fields

You can create rules to modify the retention period for particular fields within an inventory. To add an inventory rule, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin then Data sources and then Inventory aging management.
  2. Select Add inventory rule.
  3. Using the drop-down list, select an inventory.
  4. Select the field name you want to modify the retention period for.
  5. Select the action you want to perform when the asset reaches the retention period.
    • Select Clear field to delete the field value after the asset reaches the retention period.
    • Select Reduce priority to allow other data sources to overwrite the field value after the asset reaches the retention period.
  6. Enter a retention period in seconds.
  7. Select Add.
  8. Select Admin and then Configuration settings.
  9. In the Inventory field retention searches section, select the toggle switch for the inventory that you modified to activate that retention period.

    Activating a retention period can result in the permanent deletion of data.

After you add an inventory rule, you can find it listed on the Inventory aging management page in the Inventory field retention rules table. You can edit the retention period again by selecting the settings icon ( settings ) for that rule, and you can remove the rule entirely by selecting the delete icon ( remove ).

Last modified on 05 August, 2024
Add a custom field in Splunk Asset and Risk Intelligence   Manage data filters in Splunk Asset and Risk Intelligence

This documentation applies to the following versions of Splunk® Asset and Risk Intelligence: 1.0.0, 1.0.1, 1.0.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters