What is Splunk Asset and Risk Intelligence?
Splunk Asset and Risk Intelligence offers proactive risk mitigation through continuous asset discovery and compliance monitoring. It is used to continuously discover assets, enrich and accelerate investigations and uncover compliance gaps.
Features include:
Splunk Asset and Risk Intelligence provides a unified, continuously updated inventory of assets and identities by correlating data across multiple sources—including network, endpoint, cloud, and scanning tools. The solution provides asset and identity context to focus and shorten investigations so security teams can quickly identify who is associated with what assets and when. This helps cybersecurity and IT experts to identify and close gaps in security controls and validate compliance status with out-of-the-box and customizable dashboards and metrics.
Features include:
- Comprehensive, continuously updated asset inventory - Leverages rich data in the Splunk platform to continuously discover, monitor and build an accurate inventory of assets and identities — including endpoints, servers, users, cloud, and OT/IoT.
- Accelerate investigative processes - Reduces the time spent pivoting to other systems to understand the assets involved in the attack and the potential risk to the organization.
- Enrich and enhance asset records and associations - Creates more context to assets discovered by correlating data from vulnerability and software scanning tools to uncover what software and vulnerabilities exist on enterprise systems.
- Real-time compliance against security controls - Includes out of the box or custom compliance metrics such as laptop encryption, vulnerability scanning coverage, application enforcement, malware protection, and more to report on real-time compliance against security controls.
- Integrates with Splunk Enterprise Security - Continuously updates and populates the Splunk Enterprise Security Assets & Identities framework with the latest asset information, and provide comprehensive asset context for notable event enrichment.
- Enhance asset visibility across IT and SecOps with bi-directional ServiceNow CMDB integration - Updates ServiceNow asset records with what is being actively discovered by Splunk Asset and Risk Intelligence. Identify unmanaged devices that are not in ServiceNow and populate the CMDB to ensure they are managed.
Categories & Use Cases
Videos
Technical Details
| Mobile Application | No |
|---|
FAQs
What is Splunk Asset and Risk Intelligence?
Splunk Asset and Risk Intelligence offers proactive risk mitigation through continuous asset discovery and compliance monitoring. It is used to continuously discover assets, enrich and accelerate investigations and uncover compliance gaps.
