Splunk IT Service Intelligence

ITSI Modules Problem

stromy
Loves-to-Learn Lots

Dears

Im using ITSI version 4.0 , i followed the documentation for the installation but yet the default modules that comes with ITSI like OS, webserver etc .., is not working probably, when ever i want to do auto discovery for entities using module search like OS one, it give me an error savedsearch is not found tho it is enabled and i can search for it in the ITSI-search,

so i start copying conflagration from the Modules to the ITOA/local/ and it worked .. is this normal case or not??
can anyone advice me!

Thanks already

0 Karma

VatsalJagani
Super Champion

Hi @stromy,
I don't know whether you are on the right path or not, but I'm giving below steps that worked for me.

For automatic entity discovery:

  • Go to Settings > Data Inputs > ITSI Entity CSV Imports > Enable the services for which you want to enable automatic entity discovery.

For manual entity import:

  • ITSI App > Configure > Entity > Import > Import from Search > Select Module > Select Service Savedsearch > Run Search > Import.

If these steps are not working for you then I think you might have made some mistake in App installation. I'm guessing this because you are saying you are getting the error of savedsearch not found.

Hope this helps!!

0 Karma
Get Updates on the Splunk Community!

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...