Uninstalling the Splunk App
Uninstalling the App
- Follow these instructions based on the User environment.
 
Uninstalling from a Standalone Environment
- Remove $SPLUNK_HOME/etc/apps/TA-precrime-threat-intelligence
 - To reflect the cleanup changes in UI, Restart Splunk Enterprise instance
 
Splunk Knowledge Objects
- Macros
- You can edit the macro using Settings > Advanced Search > Search macros.
- For index name change, update the precrime_index macro.
 - For data model acceleration use summariesonly macro. If it set to true data will populate from the summary index else it will populate from the local indexes.
 
 
 - You can edit the macro using Settings > Advanced Search > Search macros.
 - Data Model
- You can accelerate the data model by clicking Settings > Data Model > precrime > edit.
 - Update the settings and the cron job according to your needs