Splunk® Intelligence Management (Legacy)

User Guide

Use the redaction library to remove information from reports

Splunk Intelligence Management offers the ability to redact, or remove, information from a report using the Redaction feature.

For a look at the technology behind this feature, see Redaction Library.

You must be an Administrator to edit the Redaction Map.

Edit the redaction library

The Redaction setting is where you can add or remove terms for the Redaction Library.

  1. Click the User Settings icon in Splunk Intelligence Management station, then click Settings on the menu.
  2. Click Redaction to display the types of terms you can edit.
  3. To add a term, select the type of term you want to add, then type the term into the text box on the right side. To delete a term, click the X next to it in the list. All changes are saved immediately in the redaction library.

Import terms into the redaction library

You can add a list of terms to the redaction library by importing a file in either JSON or .csv format.

  1. Click the User Settings icon in Splunk Intelligence Management station, then click Settings on the menu.
  2. Click Bulk Import above the terms list. This displays the a dialog box.
  3. Check that the file you want to import meets the formats shown at the top of the dialog box.
  4. Drag and drop the file you want to import to the dialog box.
  5. If there are issues with the information or format, such as duplicate terms or a misspelled type of information, Splunk Intelligence Management displays the error messages after importing the file.

Export terms from the redaction library

You can export the list of terms used for redaction, which may make it easier to review long or complex lists of terms.

  1. Click the User Settings icon in Splunk Intelligence Management station, then click Settings on the menu.
  2. Click Redaction to display the types of terms you can edit.
  3. Click Export Library and choose the file format (JSON or .csv) that you want to use.

The file is immediately downloaded to your local workstation.

Last modified on 21 April, 2022
Configure the company safelist to ignore certain indicators   Set up multi-factor authentication to secure access to your Splunk Intelligence Management environment

This documentation applies to the following versions of Splunk® Intelligence Management (Legacy): current


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters