1. Help Center
  2. Integrations
  3. PreCrime® Intelligence Splunk App

Uninstalling the Splunk App

Uninstalling the App

  1. Follow these instructions based on the User environment.  

Uninstalling from a Standalone Environment

  1. Remove $SPLUNK_HOME/etc/apps/TA-precrime-threat-intelligence 
  2. To reflect the cleanup changes in UI, Restart Splunk Enterprise instance

Splunk Knowledge Objects

  1. Macros
    1. You can edit the macro using Settings > Advanced Search > Search macros.
      1. For index name change, update the precrime_index macro.
      2. For data model acceleration use summariesonly macro. If it set to true data will populate from the summary index else it will populate from the local indexes.
  2. Data Model
    1. You can accelerate the data model by clicking Settings > Data Model > precrime > edit.
    2. Update the settings and the cron job according to your needs