Splunk ITSI

Why won't search complete during ITSI Entity import and Service Entity mapping - results show 1 Service and 9K Entities?

Jitu
Engager

I was trying to import Service Entities values through an ad-hoc search, however the import never completes. The search results have 1 Service and 9000 Entities associated to this.

I tried a different way of simply uploading the entities alone, the upload completes and then I try to create the service separately. I try to map entities to that service using conditions and it shows me 9000 entities matched and I save it, but again in the entities listed I am not able to see Service tagged to these entities.  I did check in the itsi_entities lookup file too. The KPIs for this service don't show up as well for some reason.

 

 

Labels (2)
Tags (3)
0 Karma

eduncan
Splunk Employee
Splunk Employee

Are there really 9,000 unique entities that are related to a service?  Make sure that in your adhoc search you are deduping on the host name or entity title name.  If you want to manually add them from a csv, you need to have a field that designates the service they are supposed to be related to.  Best practice is to use something in the actual data of the entity that shows they should be part of a service and NOT a host name because then it is not dynamic.  If you are importing via a search and you have a large number of entities that already exist, it may fail because it is trying to update existing ones.  9K entities is a large number so make sure you are deduping in your ad hoc search.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...