All Apps and Add-ons

ITSI entities from modules automatically duplicate when imported

fwawolangi
New Member

Hi all,

I imported entities using the Modules (in this case DA-IT-VIRTUALIZATION), altering the columns import to swap the e.g. hypervisor_id as Entity Alias instead of Entity Title, vice versa with hypervisor_name.
This worked fine.

But then after a while I noticed that ITSI 'discover' / auto-add the same entities, but not swapping the columns as I did previously, resulting in double the number of hypervisors than I have, but half with the hypervisor_id as the Entity Title.

Is there away to mitigate this? Ideally the subsequent searches would follow the same columns alterations, or is there a way to disable this auto-searching altogether?

Regards

Felix

0 Karma

AustinAlbrecht
Engager

As far as I've seen, there isn't an easy way to change the autodiscovery features outside of making sure that the data is already mapped to the model in the sort of way that you seem to be doing after the fact. However, I did find the documentation on how to disable the autodiscovery altogether. It may have already been solved in your environment, but I figure it might be helpful for Splunk posterity. 🙂

http://docs.splunk.com/Documentation/ITSI/latest/IModules/ITSIModuleInstallationandDeployment#ITSI_m...

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...