Splunk IT Service Intelligence

Unable to get service analyzer ITSI VERSION 2

naidusadanala
Communicator

Hi ,

I have created KPI'S IN ITSI and have them tested working fine.
Glass tables are displaying count perfectly but the service analyzer unable to display the top 50 services and KPI's i.e., unable to view the service page though I have configured services and KPI related to it.

Some one help me out ... ITSI becoming night mare it seems

appache
Path Finder

Hi, i had the same issue long time ago, so what we did is i have enabled real-time searches in the back end since ITSI is purely works based on Real Time. it should work it worked fine for me. and make sure you have enough cores for ITSI to run.
it shouldnt be an issue after you enable the real-time in your on your search head

0 Karma

sroback_splunk
Splunk Employee
Splunk Employee

You might also try reducing the total number of "every one minute" interval KPI searches that you are running (if you are running a lot). Too many 1 min. searches can have a negative impact on performance. Running KPIs at 5 min. or 15 min. intervals is enough in many cases.

Also, make sure that you have adequate hardware resources (beyond the baseline Splunk reference hardware required for Splunk Enterprise). ITSI is resource intensive and can require additional hardware.

For more info and some tips on ITSI performance, see: Performance considerations in the Installation and Configuration manual.

ChrisG
Splunk Employee
Splunk Employee

Try reducing the number of tiles to see if you get results. They are powered by real-time searches, and if you have too many tiles, the searches that power them might hang.

See the troubleshooting information in the Installation and Configuration Manual.

0 Karma

naidusadanala
Communicator

Its not going well though , I have only 3 tiles

0 Karma

mattymo
Splunk Employee
Splunk Employee

has it ever worked?

- MattyMo
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...