Splunk ITSI

ERROR: KeyError at itoa_bulk_import_entity.py while loading entities from a search

goonie
Explorer

When I am trying to create entities using search in Splunk ITSI, it is throwing the below error and the entity load is failing. 

ERROR: KeyError at "/opt/splunk/etc/apps/SA-ITOA/lib/itsi/csv_import/itoa_bulk_import_entity.py", line 172 : 'abcde servers : os'

abcde servers : os  --> this happens to be the old title of an existing service. The Service was initially named as "abcde servers : os ". Now the service has a different name.
I am not sure if this service is somewhat related to the error thrown by ITSI while importing entities. 

Can anyone help in fixing this error.

 

Labels (2)
0 Karma

codebuilder
Influencer

It's likely from a previous config that you had in place.
Try checking the content of files under /opt/splunk/etc/apps/SA-ITOA/local/

Remove any entries that are no longer valid and cycle Splunk or SHC.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

goonie
Explorer

we checked the mentioned locations, however, the configuaration files were not updated recently. And we performed an entity import one month ago. 

Any other suggestions on what could be the issue? 

Any clue on how a service name is linked with importing entities? 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...