Splunk IT Service Intelligence

How to use evaluated fields as threshold field in ITSI?

Kendo213
Communicator

Is this possible? I have some searches I use for dashboards where I'm doing various evals. For example, I'm evaluating the storage free percent field, and then attempting to use that as the threshold field in ITSI. It doesn't seem to see the data, can't do a back fill, it's listed as N/A, etc.

0 Karma

lukas_loder
Communicator

Try with the same search, but than use a timechart at the end of your search.
And in ITSI go and choose "last" value of your eval field. This way it worked for me to get the backfill working

0 Karma

Kendo213
Communicator

timechart last(PercentUsed) doesn't seem to show a value, although chart last(PercentUsed) does. If I do that, and set the threshold field as last(PercentUsed) I'm still not populating any data.

Am I doing what you were recommending, just to clarify?

0 Karma

lukas_loder
Communicator

do you get some data with for example | timechart span=15min avg(PercentUsed) ?
if so can you add this search to ITSI and then when you can select there on the next windows.. just choose there "last".

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...