Splunk ITSI

How are people managing dynamic entities in iTSI?

brent_weaver
Builder

My team is just implementing iTSI and we are struggling to deal with the fact that our entities are very dynamic. I understand that there are REST API stuff that can be called to do cleanup? Other Splunk ninja knowledge would be great from those in the field.

arjunpkishore5
Motivator
0 Karma

kanwu_splunk
Splunk Employee
Splunk Employee

Are you looking to not only importing new entities as it shows up on the index, but also removing unused entities from the ITSI entity store? Currently, ITSI does not provide a native way to remove unused entities from the entity store, but the development team is looking into a mechanism to make the removal of unused entities a bit easier to manage. Yes, you can use rest endpoints to develop an entity clean up script to do so.

0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...