Use the redaction library to remove information from reports
Splunk Intelligence Management offers the ability to redact, or remove, information from a report using the Redaction feature.
For a look at the technology behind this feature, see Redaction Library.
You must be an Administrator to edit the Redaction Map.
Edit the redaction library
The Redaction setting is where you can add or remove terms for the Redaction Library.
- Click the User Settings icon in Splunk Intelligence Management station, then click Settings on the menu.
- Click Redaction to display the types of terms you can edit.
- To add a term, select the type of term you want to add, then type the term into the text box on the right side. To delete a term, click the X next to it in the list. All changes are saved immediately in the redaction library.
Import terms into the redaction library
You can add a list of terms to the redaction library by importing a file in either JSON or .csv format.
- Click the User Settings icon in Splunk Intelligence Management station, then click Settings on the menu.
- Click Bulk Import above the terms list. This displays the a dialog box.
- Check that the file you want to import meets the formats shown at the top of the dialog box.
- Drag and drop the file you want to import to the dialog box.
- If there are issues with the information or format, such as duplicate terms or a misspelled type of information, Splunk Intelligence Management displays the error messages after importing the file.
Export terms from the redaction library
You can export the list of terms used for redaction, which may make it easier to review long or complex lists of terms.
- Click the User Settings icon in Splunk Intelligence Management station, then click Settings on the menu.
- Click Redaction to display the types of terms you can edit.
- Click Export Library and choose the file format (JSON or .csv) that you want to use.
The file is immediately downloaded to your local workstation.
Configure the company safelist to ignore certain indicators | Set up multi-factor authentication to secure access to your Splunk Intelligence Management environment |
This documentation applies to the following versions of Splunk® Intelligence Management (Legacy): current
Feedback submitted, thanks!