Back to Floor
Entities & Modules • Room 2
Entity Discovery & Import
Entities can be created manually, imported from CSV files, or discovered automatically from Splunk searches. The most scalable approach is search-based entity discovery, where a saved search periodically queries your data to find new infrastructure components.
When importing entities, you map source fields to ITSI entity fields. The entity "key" (usually host or ip) is the unique identifier. If an import finds an entity with a matching key, it updates the existing record rather than creating a duplicate.
Schedule entity discovery searches to run daily or weekly. This ensures new servers or containers are automatically picked up without manual intervention.
Knowledge Check
Prove your understanding to clear the room (Rewards XP)
Drag items to their correct zone (or tap item then tap zone on mobile)
Manual UI creation
CSV file import
Search-based discovery
Least Scalable
Moderately Scalable
Most Scalable