Splunk ITSI

How to disable ITSI entity import data input in SHC mode?

cdemir
Explorer

Hello all,

The Splunk documentation does not have an answer to this that I can find. I need to turn off recurring inputs for entity creation. We are running a 9 member SHC for our ITSI deployment. I have tried logging into a single node and going to the data input settings screen. Clicking on the object noted in the documentation simply tells me I cannot add any other inputs because I'm currently in a SHC.

So how am I supposed to be able to turn off these re-occurring imports?

Labels (2)
0 Karma

anilchaithu
Builder

@cdemir 

you have to disable the entity imports on the sh deployer and push the bundle assuming you have not touched these inputs and created a local copy of the same.

0 Karma
Get Updates on the Splunk Community!

Splunk ITSI & Correlated Network Visibility

  Now On Demand   Take Your Network Visibility to the Next Level In today’s complex IT environments, ...

Community Content Calendar, August edition

In the dynamic world of cybersecurity, staying ahead means constantly solving new puzzles and optimizing your ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...