Revert to using Splunk Asset and Risk Intelligence without exposure analytics

If you previously configured exposure analytics in Splunk Enterprise Security (ES), you can revert to using Splunk Asset and Risk Intelligence (ARI) without it at any time.
  1. In exposure analytics in Splunk ES 8.5, navigate to Configure and then Exposure analytics and then Entity discovery sources and remove the following four data sources:
    • Splunk Asset and Risk Intelligence - Asset
    • Splunk Asset and Risk Intelligence - IP
    • Splunk Asset and Risk Intelligence - Mac
    • Splunk Asset and Risk Intelligence - User
  2. In Splunk ES, go to Exposure analytics then Asset and identity lookups and then Lookup settings. Turn off entity discovery population for Assets and Identities.
  3. In Splunk ARI, turn on the Splunk ES integration.