Deleting a Splunk server from the Advanced Threat Protection appliance
Last Updated December 12, 2018
You seek instructions on how to delete a Splunk server instance from the ATP web interface so the data no longer exists in the software.
There is currently no way to delete a Splunk server's information from the Advanced Threat Protection software unless you replace the existing entry with new data. The only option available is to disable the feature so ATP no longer communicates with the Splunk server.
While the feature is disabled, you can edit the entry and provide fake information (e.g. 126.96.36.199 for the server IP, and a random string of numbers and letters for the token) to expunge proprietary data.
Subscribing will provide email updates when this Article is updated. Login is required to Subscribe