I am using the Sideview App trying to monitor usage by users. There is a Pain field in the User Activity report. Does anyone know what this Pain field is trying to show?
Hello !
Sorry I don't think I ever realized that in the new Answers, app developers don't actually get notified when there is a question about their apps. So I only saw this question because @tscroggins @'ed me directly. (thanks by the way). Going forward I have now "subscribed" to my own app so although that seems weird, perhaps it will help.
The "pain" field is actually calculated from a macro in the app called "estimate_pain", and you are free to try out some modifications. What ships is a somewhat complex thing that depends on total_run_time, the ratio of scan_count to event_count, has_index_term, has_pre_command, various logic around which command is the first_transforming command, (strongly penalizing things like "table"), also avg_pct_memory max_mem_used.
There are also some exceptions poked in the logic, for instance if the first command is metadata or makeresults it kind of short circuits some of the logic. likewise if the first_transforming command is "head" etc.
The INTENTION is that high "pain" correlates strongly with the sort of searches that the Splunk deployment's admins would want to know about, so they could go educate or help that user do something less awful.
I am super curious for what you see, what your reaction is and suggestions are. Answers is fine so we can talk on there. Note however that on the landing page of the sideview_ui app it also exhorts you the user to email anyuthing and everything to sideview_ui@sideviewapps.com or to post your question on the app's channel on the Splunk community slack
I hope that helps, and please send in any and all feedback, in any area and in any quantity. Thanks.
At a glance, it's a score calculated from _audit data based on search run time, the absence of an index predicate, the presence of prestats transforming commands, the position of other transforming commands, memory use, and the presence of an initial makeresults or metadata command. Pain is inversely proportional to efficiency.
@sideview may be lurking. Have you tried contacting them directly?