Splunk ITSI

getting actual query behind ITSI entity import searches?

jdeep607
New Member

Hi,

From where can i get actual search query behind ITSI entity import searches?

Labels (2)
0 Karma

eduncan
Splunk Employee
Splunk Employee

If you go into settings > searches> choose app ITSI and search for the word entity.  You will see custom entity imports that you have done that you scheduled as recurring.  You can see the actual search that shows entities in Settings>lookups>itsi>itsi_entities.

 

 

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...