Splunk IT Service Intelligence

Why won't search complete during ITSI Entity import and Service Entity mapping - results show 1 Service and 9K Entities?

Jitu
Engager

I was trying to import Service Entities values through an ad-hoc search, however the import never completes. The search results have 1 Service and 9000 Entities associated to this.

I tried a different way of simply uploading the entities alone, the upload completes and then I try to create the service separately. I try to map entities to that service using conditions and it shows me 9000 entities matched and I save it, but again in the entities listed I am not able to see Service tagged to these entities.  I did check in the itsi_entities lookup file too. The KPIs for this service don't show up as well for some reason.

 

 

Labels (2)
Tags (3)
0 Karma

eduncan
Splunk Employee
Splunk Employee

Are there really 9,000 unique entities that are related to a service?  Make sure that in your adhoc search you are deduping on the host name or entity title name.  If you want to manually add them from a csv, you need to have a field that designates the service they are supposed to be related to.  Best practice is to use something in the actual data of the entity that shows they should be part of a service and NOT a host name because then it is not dynamic.  If you are importing via a search and you have a large number of entities that already exist, it may fail because it is trying to update existing ones.  9K entities is a large number so make sure you are deduping in your ad hoc search.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...