Splunk IT Service Intelligence

How to use evaluated fields as threshold field in ITSI?

Kendo213
Communicator

Is this possible? I have some searches I use for dashboards where I'm doing various evals. For example, I'm evaluating the storage free percent field, and then attempting to use that as the threshold field in ITSI. It doesn't seem to see the data, can't do a back fill, it's listed as N/A, etc.

0 Karma

lukas_loder
Communicator

Try with the same search, but than use a timechart at the end of your search.
And in ITSI go and choose "last" value of your eval field. This way it worked for me to get the backfill working

0 Karma

Kendo213
Communicator

timechart last(PercentUsed) doesn't seem to show a value, although chart last(PercentUsed) does. If I do that, and set the threshold field as last(PercentUsed) I'm still not populating any data.

Am I doing what you were recommending, just to clarify?

0 Karma

lukas_loder
Communicator

do you get some data with for example | timechart span=15min avg(PercentUsed) ?
if so can you add this search to ITSI and then when you can select there on the next windows.. just choose there "last".

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...