<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ITSI Entity import - Add your own saved search in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302089#M296</link>
    <description>&lt;P&gt;So it worked fine for me in a single instance.&lt;/P&gt;

&lt;P&gt;I edited the Splunk\etc\apps\SA-ITOA\default\savedsearches.conf, copy and pasted an existing search, and slightly modified it.  Then i restarted and it shows up under saved searches:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[IT Service Intelligence - asdfGet Windows hosts]
description             = Retrieves a list of hosts generating Windows host data
search                  = | asdfdatamodel Compute_Inventory OS search | search 
All_Inventory.tag=windows | dedup All_Inventory.dest | rename All_Inventory.dest AS dest | table dest
request.ui_dispatch_app = itsi
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 10 Jul 2017 21:54:48 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2017-07-10T21:54:48Z</dc:date>
    <item>
      <title>ITSI Entity import - Add your own saved search</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302084#M291</link>
      <description>&lt;P&gt;I'm trying to import entities using a search.  The docs say that I can use a saved search from a predefined list.  I want to save my own.  I've created a saved search that suits.  It doesn't appear in the drop down.  I've made it global, and even added it to the SA-IOTA app (Where the predefined ones live).  I've tried cloning a predefined one, and amending it.  I can never get to use my search in the Entity import.&lt;/P&gt;

&lt;P&gt;I'm working in a SHC environment, so I can't save my work as a modular input, so I thought saving my search would at least cut down on the amount of work each time I have to update Entities.&lt;/P&gt;

&lt;P&gt;Anyone any ideas how I can add my saved searche to the list of predefined ones ?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 09:29:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302084#M291</guid>
      <dc:creator>JovanMilosevic</dc:creator>
      <dc:date>2017-07-10T09:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Entity import - Add your own saved search</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302085#M292</link>
      <description>&lt;P&gt;Did you follow "import from search" directions here?:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/ITSI/2.6.0/Configure/DefineEntities"&gt;http://docs.splunk.com/Documentation/ITSI/2.6.0/Configure/DefineEntities&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 13:54:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302085#M292</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-10T13:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Entity import - Add your own saved search</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302086#M293</link>
      <description>&lt;P&gt;I did.&lt;/P&gt;

&lt;P&gt;From the docs...&lt;BR /&gt;
Saved Searches  Lets you choose from a list of pre-defined ITSI saved searches.&lt;/P&gt;

&lt;P&gt;My question is "How do I put one of my searches into the list of pre-defined ITSI saved searches", as the current ones don't meet my needs.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 14:03:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302086#M293</guid>
      <dc:creator>JovanMilosevic</dc:creator>
      <dc:date>2017-07-10T14:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Entity import - Add your own saved search</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302087#M294</link>
      <description>&lt;P&gt;Is the saved search shared in the app or private to just your user?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 21:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302087#M294</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-10T21:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Entity import - Add your own saved search</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302088#M295</link>
      <description>&lt;P&gt;Oh I see what you're saying now.  I'm not sure how to do that but I'll ask around.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 21:21:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302088#M295</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-10T21:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Entity import - Add your own saved search</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302089#M296</link>
      <description>&lt;P&gt;So it worked fine for me in a single instance.&lt;/P&gt;

&lt;P&gt;I edited the Splunk\etc\apps\SA-ITOA\default\savedsearches.conf, copy and pasted an existing search, and slightly modified it.  Then i restarted and it shows up under saved searches:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[IT Service Intelligence - asdfGet Windows hosts]
description             = Retrieves a list of hosts generating Windows host data
search                  = | asdfdatamodel Compute_Inventory OS search | search 
All_Inventory.tag=windows | dedup All_Inventory.dest | rename All_Inventory.dest AS dest | table dest
request.ui_dispatch_app = itsi
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 10 Jul 2017 21:54:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302089#M296</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-10T21:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Entity import - Add your own saved search</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302090#M297</link>
      <description>&lt;P&gt;Thanks for the steer.&lt;/P&gt;

&lt;P&gt;I created a local directory in the SA-IOTA app on the Search Head Deployer (in $SPLUNK_HOME/etc/shcluster/apps/SA-IOTA), and placed my search savedsearches.conf in the local directory just created.  This keeps our searches separate from the Splunk supplied ones, and ensures mine don't get obliterated by an upgrade.  When the bundle is deployed, Splunk merges it into default on each Search Head.  Job done.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 09:36:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302090#M297</guid>
      <dc:creator>JovanMilosevic</dc:creator>
      <dc:date>2017-07-11T09:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Entity import - Add your own saved search</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302091#M298</link>
      <description>&lt;P&gt;I'm curious what the difference was between when you cloned it etc versus when you got it to work.  Yes you should put it in local for sure.  Sorry I didn't mention that.  I just tested default because it was easy.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 09:54:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302091#M298</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-11T09:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Entity import - Add your own saved search</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302092#M299</link>
      <description>&lt;P&gt;Wondering how this would behave with a macro in place of the search in savedsearches.conf. Would allow itsi admins without CLI access to update searches.&lt;/P&gt;

&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 13:49:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Entity-import-Add-your-own-saved-search/m-p/302092#M299</guid>
      <dc:creator>ian_thomas</dc:creator>
      <dc:date>2017-11-06T13:49:41Z</dc:date>
    </item>
  </channel>
</rss>

