Splunk® IT Service Intelligence

Entity Integrations Manual

Delete entities in ITSI

When you stop data collection for a system, or a system stops sending data to (ITSI) for another reason, the system continues to exist as an entity in ITSI until the entity is deleted.


Requirement Description
ITSI roles You have to have the itoa_admin or itoa_team_admin role, and have write access to the Global team. For more information, see Configure users and roles in ITSI in the Administration Manual.

Manually delete a single entity

Follow these steps to manually delete an entity.

  1. From the ITSI main menu, go to Configuration then Entity Management.
  2. Select each entity you want to delete.
  3. To delete a single entity, click Edit then Delete. To delete entities in bulk, see the next section.

Delete retired entities

Follow these steps to delete retired entities in bulk.

  1. Select Configuration then Entity Management.
  2. From the Retired Entities tab, select the first checkbox in the column header to select all retired entities on the page. A banner displays the number of entities that you've selected. You can also choose to select all retired entities from the banner message.
  3. From the Bulk Action dropdown, select Delete selected to delete all retired entities in bulk.
  4. Deleting entities can't be undone. Select Delete All in the confirmation modal to complete the action. You'll receive a message notification to confirm that all entities were deleted.

You can't delete or restore additional entities when the bulk delete action is running.

Last modified on 04 January, 2024
Create policy to retire entities in ITSI   Overview of entity types in ITSI

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.18.0, 4.18.1, 4.19.0

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters