Splunk ITSI

ITSI: Why doesn't my entity import from CSV work

davidpaper
Contributor

I'm trying to use ITSI's entity import functionality, and some of them work, others don't.

When I reference a kvstore connection via |inputlookup, it works and I get data. When I reference a CSV via |inputlookup, I get no data.

What's going on?

0 Karma
1 Solution

davidpaper
Contributor

This was a simple one. The CSV lookup has to be visible to the right app. Even though the CSV lookup was in the "itsi" app and shared w/in the app, it appears that there is a different app that must be working behind the scenes as part of this process. Sharing the CSV lookup globally allowed it to work.

View solution in original post

0 Karma

davidpaper
Contributor

This was a simple one. The CSV lookup has to be visible to the right app. Even though the CSV lookup was in the "itsi" app and shared w/in the app, it appears that there is a different app that must be working behind the scenes as part of this process. Sharing the CSV lookup globally allowed it to work.

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...