Splunk Enterprise Security

How do I delete reports created by Splunk Enterprise Security?

Erilope
Explorer

Hello, 

I wanted to ask if there was a way I can delete reports created by Enterprise Security? There are reports created by Enterprise Security that we will never use, and i would just like to clean up the reports menu. 

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You'll have to edit the default savedsearches.conf files (never recommended) and restart the ES SH to remove the reports.  Before doing that (not that you should), try disabling the reports to make sure there are no adverse side effects.  Remember that upgrading ES will restore the reports.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You'll have to edit the default savedsearches.conf files (never recommended) and restart the ES SH to remove the reports.  Before doing that (not that you should), try disabling the reports to make sure there are no adverse side effects.  Remember that upgrading ES will restore the reports.

---
If this reply helps you, Karma would be appreciated.

Erilope
Explorer

Thank you for your assistance with this, I will do that!

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...