Customize settings in Splunk Asset and Risk Intelligence

Note: Splunk Asset and Risk Intelligence is not compatible with Splunk Enterprise 9.1.2 due to known issues SPL-237796, SPL-248319 where search results in "results" have more rows than expected. Upgrade to Splunk Enterprise 9.1.3 to use Splunk Asset and Risk Intelligence.

As an admin, you can customize your experience with Splunk Asset and Risk Intelligence by modifying the configuration settings.

Reset the navigation menu

If a user added their own dashboards to the Splunk Asset and Risk Intelligence menu, you can reset the navigation menu to the default setting. You might also want to reset the navigation menu after upgrading the app. To reset the navigation menu, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. Under Navigation, select Reset navigation menus to default.

Set default and common countries

To avoid scrolling through country lists, you can specify countries to appear at the top of any drop-down country list in Splunk Asset and Risk Intelligence. To set default and common countries, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. If you want to set a default country, or one that's automatically selected, use the drop-down list under Default country to select a country.
  3. If you want to set common countries, or countries that appear at the top of lists for users to select from, use the drop-down list under Common countries to select countries, and then select Update.

Add a business name to discovered assets

Splunk Asset and Risk Intelligence automatically includes a field called business to every discovered asset. To update the business name, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. Under Business name, enter a name.
  3. Select Update.

Delete data

You can delete data from Splunk Asset and Risk Intelligence including inventory data, association data, asset notes, and metric exceptions.

To delete data, complete the following steps:

CAUTION: Deleting data permanently deletes it from Splunk Asset and Risk Intelligence.
  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. In the Danger zone section, select Delete data for the data you want to delete:
    • Inventory data: includes all discovery data from the network, IP, user, MAC, software, and vulnerability inventories
    • Custom inventory data: includes any custom field values added to inventories
    • Association data: includes first and last name associations between users, hosts, IP addresses, and MAC addresses
    • Other data: includes asset notes and metric exceptions