All Apps and Add-ons

ITSI entities from modules automatically duplicate when imported

fwawolangi
New Member

Hi all,

I imported entities using the Modules (in this case DA-IT-VIRTUALIZATION), altering the columns import to swap the e.g. hypervisor_id as Entity Alias instead of Entity Title, vice versa with hypervisor_name.
This worked fine.

But then after a while I noticed that ITSI 'discover' / auto-add the same entities, but not swapping the columns as I did previously, resulting in double the number of hypervisors than I have, but half with the hypervisor_id as the Entity Title.

Is there away to mitigate this? Ideally the subsequent searches would follow the same columns alterations, or is there a way to disable this auto-searching altogether?

Regards

Felix

0 Karma

AustinAlbrecht
Engager

As far as I've seen, there isn't an easy way to change the autodiscovery features outside of making sure that the data is already mapped to the model in the sort of way that you seem to be doing after the fact. However, I did find the documentation on how to disable the autodiscovery altogether. It may have already been solved in your environment, but I figure it might be helpful for Splunk posterity. 🙂

http://docs.splunk.com/Documentation/ITSI/latest/IModules/ITSIModuleInstallationandDeployment#ITSI_m...

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...