<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: In Splunk IT Service Intelligence, how come KPI is not showing any data? in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421053#M1068</link>
    <description>&lt;P&gt;I would suggest you forego the &lt;CODE&gt;transaction&lt;/CODE&gt; command entirely. It doesn't scale and you are looking for trouble by running this every 1 minute and searching the last 15 minutes. A better test would be to make this as simple as possible like this &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="arvato_scm_telco_process_time_tracking_jt6_test" CheckpointName="100_TO_01" OR CheckpointName="100_TO_02" | stats count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then use the &lt;CODE&gt;count&lt;/CODE&gt; field that is auto extracted and confirm that ITSI is correctly extracting it to an &lt;CODE&gt;alert_value&lt;/CODE&gt; field. You must use a different kpiid value to see it. I'm very confident the issue is with your query and not ITSI. Once you confirm the alert_value is there, this proves its not an ITSI issue&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jan 2019 18:22:52 GMT</pubDate>
    <dc:creator>skoelpin</dc:creator>
    <dc:date>2019-01-22T18:22:52Z</dc:date>
    <item>
      <title>In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421039#M1054</link>
      <description>&lt;P&gt;My data looks like this:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6432i3A7046DEA159E026/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Now I have written a search, that extracts the duration of the time ("ProcessTimestamp") between "Checkpoint 1" and "Checkpoint 2". The search looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="arvato_scm_telco_process_time_tracking_jt6_test" CheckpointName="Checkpoint 1" OR CheckpointName="Checkpoint 2"
| transaction DeliveryId
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The search combines two events for each DeliveryId (which is the unique Identifier), and each event has a field called "duration", which is the duration between the two "_time" timestamp.&lt;/P&gt;

&lt;P&gt;Now, I want to create a KPI within ITSI that displays the average duration between "Checkpoint 1" and "Checkpoint 2" (which would be the average value of all "duration" values for each DeliveryId).&lt;/P&gt;

&lt;P&gt;Unfortunately, if i setup a KPI in ITSI with the search above, and select "Average" for the calculation and "duration" as the Treshold field, the KPI is always "N/A". &lt;/P&gt;

&lt;P&gt;Any suggestions? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 13:07:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421039#M1054</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2019-01-22T13:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421040#M1055</link>
      <description>&lt;P&gt;How are you getting data into ITSI? Have you checked the &lt;CODE&gt;itsi_summary&lt;/CODE&gt; index to see if theres a value tied to the KPI?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 13:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421040#M1055</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-22T13:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421041#M1056</link>
      <description>&lt;P&gt;Yes, I can definitely see events for the specified KPI, they look like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;01/22/2019 13:39:30 +0000, search_name="Indicator - d934c0bc8df580ed637cd939 - ITSI Search", search_now=1548164400.000, info_min_time=1548163470.000, info_max_time=1548164370.000, info_search_time=1548164400.858, qf="", kpi=test2, kpiid=d934c0bc8df580ed637cd939, urgency=9, serviceid="17dc8fcf-27a2-4ec4-b1d6-38365328dd4a", itsi_service_id="17dc8fcf-27a2-4ec4-b1d6-38365328dd4a", is_service_aggregate=1, is_entity_in_maintenance=0, is_entity_defined=0, entity_key=service_aggregate, is_service_in_maintenance=0, alert_color="#FCB64E", alert_level=4, alert_value="57.111111111111114", itsi_kpi_id=d934c0bc8df580ed637cd939, is_service_max_severity_event=1, alert_severity=medium, alert_period=1, entity_title=service_aggregate, forceCsvResults="auto"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I can't really see any field that relates to the KPI value at that time. But, what I can see is, that the Threshold value I defined is working, because the alert_severity equals "medium", which is exactly what it is right now.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 13:45:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421041#M1056</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2019-01-22T13:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421042#M1057</link>
      <description>&lt;P&gt;And I get data in by defining an "Ad hoc search" in the KPI (which is the one from my question above).&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 14:21:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421042#M1057</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2019-01-22T14:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421043#M1058</link>
      <description>&lt;P&gt;Looks like you're getting a value for your &lt;CODE&gt;alert_value&lt;/CODE&gt; field which is good. How long have you let the KPI sit after defining it? Where is it showing N/A? Is it showing a value in the service analyzer? Did you check the indexer lag after turning it on? Have you checked to see if its enabled?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 14:31:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421043#M1058</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-22T14:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421044#M1059</link>
      <description>&lt;P&gt;I created the KPI around 2,5 hours ago. The N/A is showing in the service analyzer.&lt;BR /&gt;
But I can see some data points when I try to edit the thresholds (in Configure -&amp;gt; Services -&amp;gt; "my service" -&amp;gt; KPIs -&amp;gt; test2). There I can see that ITSI has acknowledged the average duration values, but I cannot see them in the service analyzer.&lt;/P&gt;

&lt;P&gt;Also, the service health score is moving up and down, based on the severity of my "test2" KPI. So the values are definitely recognized by ITSI, but I cannot see them in the service analyzer or in Deep Dives.&lt;/P&gt;

&lt;P&gt;I don't really know what you mean by "checking the indexer lag"? My "monitoring lag" is now at 10 seconds for the defined KPI.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 14:59:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421044#M1059</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2019-01-22T14:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421045#M1060</link>
      <description>&lt;P&gt;What is your KPI frequency and what timespan are you looking over? Can you confirm the kpiid for this service is &lt;CODE&gt;kpiid=d934c0bc8df580ed637cd939&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;You should first try to recreate the KPI via the search, just like ITSI does. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=itsi_summary kpiid=d934c0bc8df580ed637cd939 earliest=-2h@h latest=now
| bin _time span=1m 
| stats avg(alert_value) AS alert_value by _time 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you can see a good looking chart with your data, but ITSI is not showing it, you should try to recreate the service with the KPI. If the above search works, then everything is working on the backend and ITSI is not rendering the values &lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 15:09:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421045#M1060</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-22T15:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421046#M1061</link>
      <description>&lt;P&gt;The KPI search is executed every minute and looks for a timespan of 15 minutes.&lt;BR /&gt;
Yes, the kpiid is the one mentioned. &lt;/P&gt;

&lt;P&gt;Executing that search does not return results for the avg(alert_value). This has to do with that the field "alert_value" is not extracted (it is only shown in the raw format, but not when clicking on an event). All other fields seem to be extracted perfectly fine. Why is the field "alert_value" not extracted? Maybe because of the long decimal place?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:54:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421046#M1061</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2020-09-29T22:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421047#M1062</link>
      <description>&lt;P&gt;Why are you executing it every 1 minute and looking in the last 15 minutes? Lots of redundancy. I'm suspecting the runtimes may not be able to keep up with the search. Perhaps you should create a new service and set the frequency AND lookback period to 1 minute. &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;alert_value&lt;/CODE&gt; is the value that you put into the summary index. It's going to represent your &lt;CODE&gt;duration&lt;/CODE&gt; field. Can you confirm this is a numeric field? If its not numeric, then this explains why its showing N/A . You can find out by looking at the interesting fields on the left, and see if its has a &lt;CODE&gt;#&lt;/CODE&gt; or &lt;CODE&gt;a&lt;/CODE&gt; next to it&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 15:25:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421047#M1062</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-22T15:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421048#M1063</link>
      <description>&lt;P&gt;I think that's exactly my problem, 'alert_value' is not shown on the left side, because it is not extracted from the raw event. Therefore, I cannot find out if it's a numeric field or not.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 15:37:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421048#M1063</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2019-01-22T15:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421049#M1064</link>
      <description>&lt;P&gt;Yep thats it then! I'm fairly confident that the way you're feeding the data to ITSI, it's not recognizing the duration field as a numeric value. You should try manually extracting it via &lt;CODE&gt;rex&lt;/CODE&gt; and plot it on a timechart to confirm. How exactly are you feeding this into ITSI? &lt;/P&gt;

&lt;P&gt;Please feel free to upvote any answers which have been helpful so far &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 15:40:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421049#M1064</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-22T15:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421050#M1065</link>
      <description>&lt;P&gt;I'm feeding it to ITSI via an "Ad hoc search". What I did was:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Create a new Service&lt;/LI&gt;
&lt;LI&gt;Create a new KPI with the following settings:&lt;/LI&gt;
&lt;/OL&gt;

&lt;UL&gt;
&lt;LI&gt;KPI source = Ad hoc search&lt;/LI&gt;
&lt;LI&gt;search = &lt;CODE&gt;index="arvato_scm_telco_process_time_tracking_jt6_test" CheckpointName="Checkpoint 1" OR CheckpointName="Checkpoint 2"
| transaction DeliveryId&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Threshold field = duration&lt;/LI&gt;
&lt;LI&gt;split by entity = no&lt;/LI&gt;
&lt;LI&gt;kpi search schedule = 1 minute&lt;/LI&gt;
&lt;LI&gt;Service/Aggregate Calculation = Average&lt;/LI&gt;
&lt;LI&gt;calculation window = Last 15 minutes&lt;/LI&gt;
&lt;LI&gt;unit = secs&lt;/LI&gt;
&lt;LI&gt;monitoring lag = 10 seconds&lt;/LI&gt;
&lt;LI&gt;enable backfill = no&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I can see data when defining the thresholds, which tells me, that ITSI does recognize the values. But when writing it to the "itsi_summary" index, the field does not get extracted.&lt;BR /&gt;
I don't really know how to fix the problem, that the alert_value is not being extracted. Do you have any suggestions?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421050#M1065</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2020-09-29T22:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421051#M1066</link>
      <description>&lt;P&gt;It's due to the way you're using the &lt;CODE&gt;transaction&lt;/CODE&gt; command. You should pop open a search and run your query over the raw data and make sure &lt;CODE&gt;DeliveryId&lt;/CODE&gt; is working as expected. If there is a &lt;CODE&gt;DeliveryId&lt;/CODE&gt;, you should confirm if its a numeric field by looking for a &lt;CODE&gt;#&lt;/CODE&gt; sign next to it&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 17:55:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421051#M1066</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-22T17:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421052#M1067</link>
      <description>&lt;P&gt;I don't really get why the DeliveryId should be the problem here, because the transaction command seems to work as expected. I also tried to generate my own "duration" field, which looked like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="arvato_scm_telco_process_time_tracking_jt6_test" CheckpointName="100_TO_01" OR CheckpointName="100_TO_02"
| transaction DeliveryId
| eval FirstTime=mvindex(ProcessTimestamp, 0)
| eval LastTime=mvindex(ProcessTimestamp, 1)
| convert timeformat="%Y-%m-%dT%H:%M:%S.%3NZ" mktime("FirstTime") as First mktime("LastTime") as Last
| eval diff=Last-First
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In this case, "diff" is defenitly a numeric field, I can confirm that. If I create a new KPI with this "Ad hoc search" the result is the same. No values are shown in the service analyzer and the "alert_value" field is not extracted.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 18:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421052#M1067</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2019-01-22T18:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421053#M1068</link>
      <description>&lt;P&gt;I would suggest you forego the &lt;CODE&gt;transaction&lt;/CODE&gt; command entirely. It doesn't scale and you are looking for trouble by running this every 1 minute and searching the last 15 minutes. A better test would be to make this as simple as possible like this &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="arvato_scm_telco_process_time_tracking_jt6_test" CheckpointName="100_TO_01" OR CheckpointName="100_TO_02" | stats count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then use the &lt;CODE&gt;count&lt;/CODE&gt; field that is auto extracted and confirm that ITSI is correctly extracting it to an &lt;CODE&gt;alert_value&lt;/CODE&gt; field. You must use a different kpiid value to see it. I'm very confident the issue is with your query and not ITSI. Once you confirm the alert_value is there, this proves its not an ITSI issue&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 18:22:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421053#M1068</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-22T18:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421054#M1069</link>
      <description>&lt;P&gt;I tested your query with the count field and setup a new KPI. I can see events in the "itsi_summary" index, but the alert_value is still not being extracted, but it looks different now:&lt;/P&gt;

&lt;P&gt;01/22/2019 18:42:30 +0000, search_name="Indicator - f7153072c1b928feeb214c56 - ITSI Search", search_now=1548182580.000, info_min_time=1548182250.000, info_max_time=1548182550.000, info_search_time=1548182581.714, qf="", kpi=new_test3, kpiid=f7153072c1b928feeb214c56, urgency=5, serviceid="2fd77b2c-ab52-48eb-9183-9ce7452d8432", itsi_service_id="2fd77b2c-ab52-48eb-9183-9ce7452d8432", is_service_aggregate=1, is_entity_in_maintenance=0, is_entity_defined=0, entity_key=service_aggregate, is_service_in_maintenance=0, alert_color="#99D18B", alert_level=2, alert_value=5, itsi_kpi_id=f7153072c1b928feeb214c56, is_service_max_severity_event=1, alert_severity=normal, alert_period=1, entity_title=service_aggregate, forceCsvResults="auto"&lt;/P&gt;

&lt;P&gt;Therefore, I still can't see any result (can only see N/A) in the service analyzer.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:54:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421054#M1069</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2020-09-29T22:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421055#M1070</link>
      <description>&lt;P&gt;Go open a support case or try upgrading. Should definitely work &lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 18:51:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421055#M1070</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-22T18:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421056#M1071</link>
      <description>&lt;P&gt;Thank you, I will try that out. Another thing I just realized is, that the 'alert_value' field is only extracted for the KPI 'ServiceHealthScore'. If I filter events for this KPI (which is only the value for the whole service), the 'alert_value' field is extracted.&lt;/P&gt;

&lt;P&gt;This explains why I can see the ServiceHealthScore moving up and down in the service analyzer (the score changes based on the KPIs I defined), but the individual KPIs don't show any values.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:54:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421056#M1071</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2020-09-29T22:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421057#M1072</link>
      <description>&lt;P&gt;Hi skoelpin, &lt;BR /&gt;
just to confirm your suggestions. I tried to implement my KPI (with the search above) on ITSI version 4.0.2 and everything works fine. Previously, I implemented the KPI in version 3.1.3. Seems to be a bug in that version or in my installation of ITSI.&lt;BR /&gt;
Thank you for your time and suggestions.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 09:28:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421057#M1072</guid>
      <dc:creator>florianduhme</dc:creator>
      <dc:date>2019-01-23T09:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk IT Service Intelligence, how come KPI is not showing any data?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421058#M1073</link>
      <description>&lt;P&gt;Thanks for following up with this!&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 14:34:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/In-Splunk-IT-Service-Intelligence-how-come-KPI-is-not-showing/m-p/421058#M1073</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-23T14:34:32Z</dc:date>
    </item>
  </channel>
</rss>

