Getting Data In

Is Splunk planning to offer guidance on naming conventions in the Metrics Index in relation to CIM?

rjthibod
Champion

Splunk 7.0 introduced the Metrics Index feature and a whole new naming scheme.

Is Splunk planning to use or offer something similar to the CIM for metrics index measurements and dimensions? Will data in the Metrics Index be targeted for integration with ITSI and ES based on the naming conventions?

App developers are in the process of migrating things into the Metrics Index, so it would be could to know what to plan for.

1 Solution

mattymo
Splunk Employee
Splunk Employee

As of now Metrics are not designed with CIM in mind. Keep in mind neither is ITSI.

- MattyMo

View solution in original post

0 Karma

lmaclean
Path Finder

From a few searches I have done based upon any type of standard that Statsd or Collectd have, there are a few that make sense:

schema.application_name.namespace.metric_name.metric_type

So for something as simple as OS Metrics l believe for the "metric_name" field going along the lines of:

os.<type>.<sub_type>.<metric>

e.g:
- os.cpu.percent
- os.cpu.interrupts_sec
- os.mem.swap.percent
- os.mem.pages_sec
- os.system.threads
- os.process.mem.used
- os.disk.free.percent
etc...

Refs:
https://matt.aimonetti.net/posts/2013/06/26/practical-guide-to-graphite-monitoring/
https://collectd.org/wiki/index.php/Naming_schema
https://www.slideshare.net/itnig/collecting-metrics-with-graphite-and-statsd

mattymo
Splunk Employee
Splunk Employee

As of now Metrics are not designed with CIM in mind. Keep in mind neither is ITSI.

- MattyMo
0 Karma

rjthibod
Champion

Any updates or input Splunk ppl?

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...