Stop monitoring Splunk Infrastructure Monitoring entities in ITSI

To stop monitoring Splunk Infrastructure Monitoring entities in Splunk IT Service Intelligence (ITSI), disable the entity discovery saved searches provided in the Content Pack for Splunk Infrastructure Monitoring.

Prerequisites

Prerequisite Description
Administrator role
  • In Splunk Enterprise, you have to be a user with the admin role.
  • In Splunk Cloud Platform, you have to be a user with the sc_admin role.

Steps

To disable the discovery searches and stop monitoring Splunk Infrastructure Monitoring entities, perform the following steps:

  1. In ITSI, go to Settings > Searches, reports, and alerts.
  2. In the App dropdown, select Splunk Infrastructure Monitoring Add-on.
  3. Disable the following entity discovery searches:
    • IT Service Intelligence - SIM AWS EC2 entities
    • IT Service Intelligence - SIM AWS Lambda entities
    • IT Service Intelligence - SIM Azure Functions entities
    • IT Service Intelligence - SIM Azure VM entities
    • IT Service Intelligence - SIM Google Cloud Functions entities
    • IT Service Intelligence - SIM Google Compute Engine entities
  4. After you disable the searches, manually remove the entities from ITSI. For instructions, see Manually delete inactive entities in ITSI.