Splunk ITSI

Bulk change of ITSI service entity rule

satokoji
Explorer

I need to change all entity alias value like this:
abxxxx → acxxxx

This makes all services' entity rules unmatched that include the entities.

Re-importing all services isn't good way because it cut links between services and KPI in glass tables.

Is there any good way to change entity rules of paticular services at once?

Thanks

esnyder_splunk
Splunk Employee
Splunk Employee

If you simply wanted to add an entity rule, I would suggest linking all of the services to a service template that contains this entity rule. Then you could change it whenever you want and it would propagate to all linked services.

Since the entity rule wasn't originally added to the services through a service template, there's no quick way to change it now. I would suggest:

  1. Create a service template containing just the new entity rule (with acxxxx) and link it to all of the services you want to change. (https://docs.splunk.com/Documentation/ITSI/latest/Configure/Linkservicetotemplate)
  2. Go through each service manually and remove the old entity rule (with abxxxx).

That way, in the future if you want to change the entity rule again, you can make that once simple change to the template and it'll propagate to all linked services. It's a best practices to use service templates as much as possible when managing lots of services.

satokoji
Explorer

ITSI Version is 3.1.4

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...