I noticed in the hardening standards it states,
"Disable automatic chart recovery in the analytics workspace. See Charts in the Splunk Analytics Workspace in the Splunk Analytics Workspace Using the Splunk Analytics Workspace manual."
I looked at the link, but did not find any explanation on what exactly risk it poses to keep that feature enabled. Hence, seeking some clarification.
I see that it is quite some time since you posted this question. Just wanted to "second it", as I am working with hardening a Splunk platform myself at the moment and am wondering about the same thing.
By chance, have you found any answers?