Splunk IT Service Intelligence

ITSI: Why doesn't my entity import from CSV work

davidpaper
Contributor

I'm trying to use ITSI's entity import functionality, and some of them work, others don't.

When I reference a kvstore connection via |inputlookup, it works and I get data. When I reference a CSV via |inputlookup, I get no data.

What's going on?

0 Karma
1 Solution

davidpaper
Contributor

This was a simple one. The CSV lookup has to be visible to the right app. Even though the CSV lookup was in the "itsi" app and shared w/in the app, it appears that there is a different app that must be working behind the scenes as part of this process. Sharing the CSV lookup globally allowed it to work.

View solution in original post

0 Karma

davidpaper
Contributor

This was a simple one. The CSV lookup has to be visible to the right app. Even though the CSV lookup was in the "itsi" app and shared w/in the app, it appears that there is a different app that must be working behind the scenes as part of this process. Sharing the CSV lookup globally allowed it to work.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...