Splunk ITSI

How are people managing dynamic entities in iTSI?

brent_weaver
Builder

My team is just implementing iTSI and we are struggling to deal with the fact that our entities are very dynamic. I understand that there are REST API stuff that can be called to do cleanup? Other Splunk ninja knowledge would be great from those in the field.

arjunpkishore5
Motivator
0 Karma

kanwu_splunk
Splunk Employee
Splunk Employee

Are you looking to not only importing new entities as it shows up on the index, but also removing unused entities from the ITSI entity store? Currently, ITSI does not provide a native way to remove unused entities from the entity store, but the development team is looking into a mechanism to make the removal of unused entities a bit easier to manage. Yes, you can use rest endpoints to develop an entity clean up script to do so.

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...