Splunk ITSI

Who created Services in ITSI

Reddi694325
Path Finder

In my ITSI environment already some Services and KPIs are configured. Wanted to know by whom created those Services and KPIs.

Thanks in Advance

0 Karma

PowerPacked
Builder

Hi Reddi694325

ITSI default installation comes with modules like Application server module, database module, operating system module, etc.

These modules have the services, entities, KPIS created for generic use so that you can use or duplicate them according to your use case.

You can always delete these Services, entities, kpis, from Configure section in ITSI UI app, or completely removing these modules from service side.

Thanks

0 Karma

Reddi694325
Path Finder

Thanks for the reply. I don't have access to _internal index. Is there any other way to find it?

0 Karma

Azeemering
Builder

Good question...hard to answer as they aren't exactly like knowledge objects.
What I did find is that when I create a service and then check in Splunk own's internal logging I see a match:

index = _internal sourcetype=itsi_internal_log component="itsi.services" objecttype=service method=create

0 Karma

Reddi694325
Path Finder

Thanks for your answer. But I don't have access to _internal index. Is there any other way?

0 Karma

Azeemering
Builder

The only other thing you can look at is the kvstore / lookups that might give you and indication who created them. But I cannot see a 1 to 1 relation between those and a created service.

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...