Splunk IT Service Intelligence

ITSI Modules Problem

stromy
Loves-to-Learn Lots

Dears

Im using ITSI version 4.0 , i followed the documentation for the installation but yet the default modules that comes with ITSI like OS, webserver etc .., is not working probably, when ever i want to do auto discovery for entities using module search like OS one, it give me an error savedsearch is not found tho it is enabled and i can search for it in the ITSI-search,

so i start copying conflagration from the Modules to the ITOA/local/ and it worked .. is this normal case or not??
can anyone advice me!

Thanks already

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hi @stromy,
I don't know whether you are on the right path or not, but I'm giving below steps that worked for me.

For automatic entity discovery:

  • Go to Settings > Data Inputs > ITSI Entity CSV Imports > Enable the services for which you want to enable automatic entity discovery.

For manual entity import:

  • ITSI App > Configure > Entity > Import > Import from Search > Select Module > Select Service Savedsearch > Run Search > Import.

If these steps are not working for you then I think you might have made some mistake in App installation. I'm guessing this because you are saying you are getting the error of savedsearch not found.

Hope this helps!!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...