Splunk IT Service Intelligence

How to use evaluated fields as threshold field in ITSI?

Kendo213
Communicator

Is this possible? I have some searches I use for dashboards where I'm doing various evals. For example, I'm evaluating the storage free percent field, and then attempting to use that as the threshold field in ITSI. It doesn't seem to see the data, can't do a back fill, it's listed as N/A, etc.

0 Karma

lukas_loder
Communicator

Try with the same search, but than use a timechart at the end of your search.
And in ITSI go and choose "last" value of your eval field. This way it worked for me to get the backfill working

0 Karma

Kendo213
Communicator

timechart last(PercentUsed) doesn't seem to show a value, although chart last(PercentUsed) does. If I do that, and set the threshold field as last(PercentUsed) I'm still not populating any data.

Am I doing what you were recommending, just to clarify?

0 Karma

lukas_loder
Communicator

do you get some data with for example | timechart span=15min avg(PercentUsed) ?
if so can you add this search to ITSI and then when you can select there on the next windows.. just choose there "last".

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...