Splunk ITSI

How are people managing dynamic entities in iTSI?

brent_weaver
Builder

My team is just implementing iTSI and we are struggling to deal with the fact that our entities are very dynamic. I understand that there are REST API stuff that can be called to do cleanup? Other Splunk ninja knowledge would be great from those in the field.

arjunpkishore5
Motivator
0 Karma

kanwu_splunk
Splunk Employee
Splunk Employee

Are you looking to not only importing new entities as it shows up on the index, but also removing unused entities from the ITSI entity store? Currently, ITSI does not provide a native way to remove unused entities from the entity store, but the development team is looking into a mechanism to make the removal of unused entities a bit easier to manage. Yes, you can use rest endpoints to develop an entity clean up script to do so.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...