Discovery processing searches in Exposure Analytics

Note: Do not edit the processing searches for exposure analytics in Splunk Enterprise Security.
There are several searches that run regularly to add, update, or remove data from Exposure Analytics. As an admin, you can turn on or turn off the searches listed in the following table:
Type of discovery search Description Default run frequency
Processing searches By running process searches, Exposure Analytics can retrieve and track asset and user data. 5 minutes
Association searches By running association searches, Exposure Analytics tracks the first and last time combinations of detected users, hosts, IP addresses, and MAC addresses. If you turn off association searches, you can't access data on associations between assets and users, such as a host name and an IP address. 15 minutes
Other The other predefined source discovery search is responsible for searching your environment for sourcetypes that match any of the predefined data sources. This helps filter the list of predefined data sources on the source management page to only the sources that have been discovered within your environment. x