Add metric exceptions in Splunk Asset and Risk Intelligence

Note: Splunk Asset and Risk Intelligence is not compatible with Splunk Enterprise 9.1.2 due to known issues SPL-237796, SPL-248319 where search results in "results" have more rows than expected. Upgrade to Splunk Enterprise 9.1.3 to use Splunk Asset and Risk Intelligence.

Exclude particular assets from a metric calculation by adding a metric exception. When you add a metric exception, any assets that are in scope for the metric, but also meet your exception criteria, are excluded in the metric calculation. However, you can still see the omitted assets listed in the metric dashboard.

Adding a metric exception is helpful when there are assets that are typically compliant with the metric, but there is an exceptional reason why those assets are not compliant. For example, if there are servers running a legacy operating system, you might want to exclude them from your metric calculation because Splunk Asset and Risk Intelligence labels those servers as defects.

To filter the scope of your metric, such as filtering out workstations, rather than adding an exception, see Edit metric settings.

Add a metric exception

There are two ways you can add a metric exception:

  • Manually enter assets to exclude from a metric on the Metric exceptions page
  • Select particular assets to exclude from a metric dashboard

To add a metric exception on the Metric exceptions page, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Risk and then Metric exceptions.
  2. Select Add exception.
  3. Using the drop-down list, select the Metric that you want to add an exception for.
  4. Enter the Exception value. For example, if you select NT Host for the field, enter the hostname for the exception value.
  5. (Optional) Enter a reason for adding the exception.
  6. Select Add.

After you add an exception, you can find it in the Exception listing table. You can filter and search for particular exceptions by reason and by value.

To add a metric exception from a particular metric dashboard, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Risk and then Metrics.
  2. Select the metric you want to add exceptions to.
  3. In the Metric details table, select the check boxes for the assets you want to exclude.
  4. Select Exceptions and then Add selected exceptions.

For more details on adding and managing metric exceptions, see Add and manage metric exceptions in the Investigate Assets and Assess Risk in Splunk Asset and Risk Intelligence manual.

Add a metric exception with an exception search