As far as I've seen, there isn't an easy way to change the autodiscovery features outside of making sure that the data is already mapped to the model in the sort of way that you seem to be doing after the fact. However, I did find the documentation on how to disable the autodiscovery altogether. It may have already been solved in your environment, but I figure it might be helpful for Splunk posterity. 🙂
http://docs.splunk.com/Documentation/ITSI/latest/IModules/ITSIModuleInstallationandDeployment#ITSI_module_entity_discovery
... View more