<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to remove asset data? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200245#M1045</link>
    <description>&lt;P&gt;I know in version 4.1.0 assets get merged into two files. You can search both of those using the following:&lt;/P&gt;

&lt;P&gt;|inputlookup append=T asset_lookup_by_str | inputlookup append=t asset_lookup_by_cidr_raw&lt;/P&gt;

&lt;P&gt;This will confirm if your demo assets are still in the merged file. I would recommend backing up the file first, but you could empty this file and it would rebuild upon next merge. &lt;/P&gt;

&lt;P&gt;I know a similar set of files (possibly the same ones) exists in earlier versions of ES. &lt;/P&gt;

&lt;P&gt;Ryan&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 10:26:10 GMT</pubDate>
    <dc:creator>ryanoconnor</dc:creator>
    <dc:date>2020-09-29T10:26:10Z</dc:date>
    <item>
      <title>How to remove asset data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200241#M1041</link>
      <description>&lt;P&gt;I've configured my own asset list, and now I want to stop asset information from the "demo assets" lookup from showing up in Dashboards, searches, etc. I've disabled the asset in the ES configuration, but it hasn't had any effect. How can I get rid of this junk data?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 10:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200241#M1041</guid>
      <dc:creator>khagan</dc:creator>
      <dc:date>2016-07-29T10:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove asset data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200242#M1042</link>
      <description>&lt;P&gt;Have you tried disabling the demo assets and waiting for the merge process to run? &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/ES/4.2.0/User/Identitymanagement#Verify_the_merging_process"&gt;http://docs.splunk.com/Documentation/ES/4.2.0/User/Identitymanagement#Verify_the_merging_process&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 11:44:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200242#M1042</guid>
      <dc:creator>ryanoconnor</dc:creator>
      <dc:date>2016-07-29T11:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove asset data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200243#M1043</link>
      <description>&lt;P&gt;Yes, as mentioned I've disabled the demo assets. I've also forced the merge, and nothing has happened.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 11:45:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200243#M1043</guid>
      <dc:creator>khagan</dc:creator>
      <dc:date>2016-07-29T11:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove asset data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200244#M1044</link>
      <description>&lt;P&gt;What version of ES are you running? &lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 11:54:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200244#M1044</guid>
      <dc:creator>ryanoconnor</dc:creator>
      <dc:date>2016-07-29T11:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove asset data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200245#M1045</link>
      <description>&lt;P&gt;I know in version 4.1.0 assets get merged into two files. You can search both of those using the following:&lt;/P&gt;

&lt;P&gt;|inputlookup append=T asset_lookup_by_str | inputlookup append=t asset_lookup_by_cidr_raw&lt;/P&gt;

&lt;P&gt;This will confirm if your demo assets are still in the merged file. I would recommend backing up the file first, but you could empty this file and it would rebuild upon next merge. &lt;/P&gt;

&lt;P&gt;I know a similar set of files (possibly the same ones) exists in earlier versions of ES. &lt;/P&gt;

&lt;P&gt;Ryan&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200245#M1045</guid>
      <dc:creator>ryanoconnor</dc:creator>
      <dc:date>2020-09-29T10:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove asset data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200246#M1046</link>
      <description>&lt;P&gt;I aggree with rynoconnor's second answer. &lt;/P&gt;

&lt;P&gt;The asset and identities are in a lookup file. Whatever new lookups are added as identity or asset, ES  will merged data into the existing lookup file rather than overwriting.  &lt;/P&gt;

&lt;P&gt;For this purpose, if you want to remove  demo assets, you should empty asset_lookup_by_str.csv  and asset_lookup_by_cidr.csv files. These files can be found in SA-IdentityManagement/lookups folder.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:25:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200246#M1046</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2020-09-29T10:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove asset data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200247#M1047</link>
      <description>&lt;P&gt;So this worked, but now my own asset lists aren't merging back in - the files are just empty. I've tried to force the merge:&lt;BR /&gt;
&lt;EM&gt;$SPLUNK_HOME/bin/splunk cmd splunkd print-modinput-config identity_manager | $SPLUNK_HOME/bin/python $SPLUNK_HOME/etc/apps/SA-IdentityManagement/bin/identity_manager.py --username=admin&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Still when I search for assets, it now returns 0 results. Am I missing a step?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200247#M1047</guid>
      <dc:creator>khagan</dc:creator>
      <dc:date>2020-09-29T10:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove asset data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200248#M1048</link>
      <description>&lt;P&gt;Do you have empty file ? Keep the files with header lines.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 16:28:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200248#M1048</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2016-07-29T16:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove asset data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200249#M1049</link>
      <description>&lt;P&gt;The file still has the headers:&lt;BR /&gt;
key,asset_id,asset_tag,bunit,category,city,country,dns,ip,is_expected,lat,long,mac,nt_host,owner,pci_domain,priority,requires_av,should_timesync,should_update&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:26:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-remove-asset-data/m-p/200249#M1049</guid>
      <dc:creator>khagan</dc:creator>
      <dc:date>2020-09-29T10:26:25Z</dc:date>
    </item>
  </channel>
</rss>

