Splunk ITSI

How to disable ITSI entity import data input in SHC mode?

cdemir
Explorer

Hello all,

The Splunk documentation does not have an answer to this that I can find. I need to turn off recurring inputs for entity creation. We are running a 9 member SHC for our ITSI deployment. I have tried logging into a single node and going to the data input settings screen. Clicking on the object noted in the documentation simply tells me I cannot add any other inputs because I'm currently in a SHC.

So how am I supposed to be able to turn off these re-occurring imports?

Labels (2)
0 Karma

anilchaithu
Builder

@cdemir 

you have to disable the entity imports on the sh deployer and push the bundle assuming you have not touched these inputs and created a local copy of the same.

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...