Configure exposure analytics to use with Splunk Asset and Risk Intelligence

If you have additional search head capacity and want a more integrated experience within Splunk Enterprise Security (ES), configure exposure analytics to work with Splunk Asset and Risk Intelligence (ARI).
  1. In exposure analytics in Splunk ES 8.5, navigate to Configure and then Exposure analytics and then Entity discovery sources and add the following four data sources:
    • Splunk Asset and Risk Intelligence - Asset
    • Splunk Asset and Risk Intelligence - IP
    • Splunk Asset and Risk Intelligence - Mac
    • Splunk Asset and Risk Intelligence - User
      Note: Do not add any other data sources to Entity discovery.
  2. In Splunk ARI, turn off the Splunk ES integration. Exposure analytics now handles populating the asset and identity lookups.