Uninstalling the Splunk App
Uninstalling the App
- Follow these instructions based on the User environment.
Uninstalling from a Standalone Environment
- Remove $SPLUNK_HOME/etc/apps/TA-precrime-threat-intelligence
- To reflect the cleanup changes in UI, Restart Splunk Enterprise instance
Splunk Knowledge Objects
- Macros
- You can edit the macro using Settings > Advanced Search > Search macros.
- For index name change, update the precrime_index macro.
- For data model acceleration use summariesonly macro. If it set to true data will populate from the summary index else it will populate from the local indexes.
- Data Model
- You can accelerate the data model by clicking Settings > Data Model > precrime > edit.
- Update the settings and the cron job according to your needs
