Splunk ITSI

How are people managing dynamic entities in iTSI?

brent_weaver
Builder

My team is just implementing iTSI and we are struggling to deal with the fact that our entities are very dynamic. I understand that there are REST API stuff that can be called to do cleanup? Other Splunk ninja knowledge would be great from those in the field.

arjunpkishore5
Motivator
0 Karma

kanwu_splunk
Splunk Employee
Splunk Employee

Are you looking to not only importing new entities as it shows up on the index, but also removing unused entities from the ITSI entity store? Currently, ITSI does not provide a native way to remove unused entities from the entity store, but the development team is looking into a mechanism to make the removal of unused entities a bit easier to manage. Yes, you can use rest endpoints to develop an entity clean up script to do so.

0 Karma
Get Updates on the Splunk Community!

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...