Entities can be created manually, imported from CSV files, or discovered automatically from Splunk searches. The most scalable approach is search-based entity discovery, where a saved search periodically queries your data to find new infrastructure components.
When importing entities, you map source fields to ITSI entity fields. The entity "key" (usually host or ip) is the unique identifier. If an import finds an entity with a matching key, it updates the existing record rather than creating a duplicate.