All Apps and Add-ons

ITSI entities from modules automatically duplicate when imported

fwawolangi
New Member

Hi all,

I imported entities using the Modules (in this case DA-IT-VIRTUALIZATION), altering the columns import to swap the e.g. hypervisor_id as Entity Alias instead of Entity Title, vice versa with hypervisor_name.
This worked fine.

But then after a while I noticed that ITSI 'discover' / auto-add the same entities, but not swapping the columns as I did previously, resulting in double the number of hypervisors than I have, but half with the hypervisor_id as the Entity Title.

Is there away to mitigate this? Ideally the subsequent searches would follow the same columns alterations, or is there a way to disable this auto-searching altogether?

Regards

Felix

0 Karma

AustinAlbrecht
Engager

As far as I've seen, there isn't an easy way to change the autodiscovery features outside of making sure that the data is already mapped to the model in the sort of way that you seem to be doing after the fact. However, I did find the documentation on how to disable the autodiscovery altogether. It may have already been solved in your environment, but I figure it might be helpful for Splunk posterity. 🙂

http://docs.splunk.com/Documentation/ITSI/latest/IModules/ITSIModuleInstallationandDeployment#ITSI_m...

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...