All Apps and Add-ons

ITSI entities from modules automatically duplicate when imported

fwawolangi
New Member

Hi all,

I imported entities using the Modules (in this case DA-IT-VIRTUALIZATION), altering the columns import to swap the e.g. hypervisor_id as Entity Alias instead of Entity Title, vice versa with hypervisor_name.
This worked fine.

But then after a while I noticed that ITSI 'discover' / auto-add the same entities, but not swapping the columns as I did previously, resulting in double the number of hypervisors than I have, but half with the hypervisor_id as the Entity Title.

Is there away to mitigate this? Ideally the subsequent searches would follow the same columns alterations, or is there a way to disable this auto-searching altogether?

Regards

Felix

0 Karma

AustinAlbrecht
Engager

As far as I've seen, there isn't an easy way to change the autodiscovery features outside of making sure that the data is already mapped to the model in the sort of way that you seem to be doing after the fact. However, I did find the documentation on how to disable the autodiscovery altogether. It may have already been solved in your environment, but I figure it might be helpful for Splunk posterity. 🙂

http://docs.splunk.com/Documentation/ITSI/latest/IModules/ITSIModuleInstallationandDeployment#ITSI_m...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...