Modify the default configurations

You can modify default settings as an admin in Exposure Analytics.

Set the data source compliance window

The Operational health dashboard uses the data source compliance window for each data source. The window is set to one day (86400 seconds) by default, but you can change the default window or customize it for each data source.

To set the default data source compliance window, complete the following steps:

  1. In Exposure Analytics, select Configure and then All configurations.
  2. In the Exposure analytics section, select Configuration settings and then Default configurations.

  3. Enter a time in seconds for Data source compliance window.
  4. Select Update.

Turn on or turn off enrichment rules

To turn on or turn off the enrichment rules for all inventories, follow these steps:
  1. In Exposure Analytics, select Configure and then All configurations.

  2. In the Exposure analytics section, select Configuration settings and then Default configurations.

  3. Turn on or turn off Enrichment rules.

Allow or disallow editing field priorities

To allow or disallow users to edit field priorities, follow these steps:
  1. In Exposure Analytics, select Configure and then All configurations.

  2. In the Exposure analytics section, select Configuration settings and then Default configurations.

  3. Turn on or turn off Edit field priorities.

Edit asset and identity type defaults

Add or remove allowable asset and identity types. See Add and manage asset types in Exposure Analytics or Add and manage identity types in Exposure Analytics.

Turn on or turn off ephemeral asset or identity discovery

Ephemeral assets and identities are short-lived entities that appear briefly in your environment and might not persist beyond a set period of time.

When you turn on ephemeral detection in Exposure Analytics, the app labels any newly discovered assets or identities as ephemeral for the time window you define.

For example, if you turn on ephemeral assets and set the discovery time window to less than 5 days, then an asset discovered for the first time on day 1 is considered an ephemeral asset until it's discovered again past day 5.

To update ephemeral asset and identity settings, follow these steps:

  1. In Exposure Analytics, select Configure and then All configurations.
  2. In the Exposure analytics section, select Configuration settings and then Default configurations.

  3. Select Edit for Ephemeral asset and identity.
  4. Turn on or turn off the options for Asset and Identity.

  5. Enter a number of days for Discovered for less than.

  6. (Optional) Deselect the check box for Apply to all assets and Appy to all identities to make particular asset and identity types ephemeral.

  7. (Optional) Select Run configuration to apply the ephemeral logic to asset or identity records over a chosen time frame. This can help you update your current inventories if you've just turned on ephemeral logic or changed its settings.

  8. Select Update.

Turn on compatibility with FIPS mode

Turn on Exposure Analytics compatibility with federated search provider transparent mode. For more details on FIPS mode in the Splunk platform, see Secure Splunk Enterprise with FIPS.
Note: Only turn on this setting if you've already configured Federated Search in the Splunk platform.
To turn on the setting, follow these steps:
  1. In Exposure Analytics, select Configure and then All configurations.
  2. In the Exposure analytics section, select Configuration settings and then Default configurations.

  3. Select the toggle switch for Federated transparent mode compatibility to turn it on.