<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is the difference in ITSI thresholds between Preview Aggregate Threshold values compared to the configure thresholds values? in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422628#M1109</link>
    <description>&lt;P&gt;I am seeing a difference in data (see screenshots) between the data previewed in the Preview Aggregate Thresholds and the data previewed below it under the Configure Thresholds for Time Policy. Does anyone know why these values would be different?  Is the top one some kind of average of something?&lt;BR /&gt;
You can see in the screenshots that for Friday, October 15th, 2018 at 12:00:00 PM, the top one shows a value of 2149.83 and the bottom shows a value of 7138.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5909iADCC198E85FAD073/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5910i4EDE27237BCF8186/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Oct 2018 20:18:47 GMT</pubDate>
    <dc:creator>EricLloyd79</dc:creator>
    <dc:date>2018-10-10T20:18:47Z</dc:date>
    <item>
      <title>What is the difference in ITSI thresholds between Preview Aggregate Threshold values compared to the configure thresholds values?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422628#M1109</link>
      <description>&lt;P&gt;I am seeing a difference in data (see screenshots) between the data previewed in the Preview Aggregate Thresholds and the data previewed below it under the Configure Thresholds for Time Policy. Does anyone know why these values would be different?  Is the top one some kind of average of something?&lt;BR /&gt;
You can see in the screenshots that for Friday, October 15th, 2018 at 12:00:00 PM, the top one shows a value of 2149.83 and the bottom shows a value of 7138.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5909iADCC198E85FAD073/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5910i4EDE27237BCF8186/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 20:18:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422628#M1109</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-10-10T20:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference in ITSI thresholds between Preview Aggregate Threshold values compared to the configure thresholds values?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422629#M1110</link>
      <description>&lt;P&gt;It should be whatever you sent the calculation metric to when developing the kpi value. Are you looking over the same time window in both screenshots? &lt;/P&gt;

&lt;P&gt;Rather than measuring a value at a single point in time, it would be better to pick 2 points in time and measure the sum from both time values. You can also look in the &lt;CODE&gt;itsi_summary&lt;/CODE&gt; index and create your own timechart based on the value to determine which screenshot is correct&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 02:15:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422629#M1110</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-10-11T02:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference in ITSI thresholds between Preview Aggregate Threshold values compared to the configure thresholds values?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422630#M1111</link>
      <description>&lt;P&gt;Sorry, what you are saying isn't making sense to me.&lt;BR /&gt;
The first part did. Yes, I set the metric to SUM a particular KPI value. The bottom screenshot seems to display that metric correctly. The top one does not.&lt;/P&gt;

&lt;P&gt;I dont understand your second recommendation. Why would I pick 2 points in time and measure the sum from both time values?  Im trying to compare the data from one chart to another and verify it is the same data.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 18:41:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422630#M1111</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-10-11T18:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference in ITSI thresholds between Preview Aggregate Threshold values compared to the configure thresholds values?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422631#M1112</link>
      <description>&lt;P&gt;What I'm saying is you should measure the values over a span of time rather than a single point in time. You should run a timechart over the itsi_summary index for a set span of time and identify the value then compare it with your charts. You could be looking at different spans of time which may be leading to wrong values &lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 20:15:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422631#M1112</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-10-11T20:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference in ITSI thresholds between Preview Aggregate Threshold values compared to the configure thresholds values?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422632#M1113</link>
      <description>&lt;P&gt;@skoelpin &lt;BR /&gt;
After some investigation, it seems that the value in the Preview Aggregate Threshold takes a kpi value sample. You can see from my search using itsi_summary that I found a value of 16 for 1:00 am on 10/9. and below that you can see that in the Preview Aggregate Threshold window there is a value for 16.17.  I thought perhaps the decimal indicated that it was an average but I added up the values in the last 5 mins before 1:00 am and it didn't come out to 16.17.&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5907i47E1C3939B4C652B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5908i90E62FF58C6E5050/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;You can see also I ran a query and asked for the sum of the last 5 mins and this seems to match the values in the chart below where the actual thresholds are set.  I wont let me add any more attachments but basicallly the numbers matched for a sum of last 5 mins with the bottom preview chart.&lt;/P&gt;

&lt;P&gt;So it seems the Preview Aggregate Threshold is a sampling of a kpi despite what calculation you asked for in the Base search while the lower one near the actual input for the threshold is the calculation of the kpi that you asked for.&lt;/P&gt;

&lt;P&gt;Interestingly enough, these two number seemed very close to each other when I asked for an Average in the KPI base search rather than a sum.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 22:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422632#M1113</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-10-11T22:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference in ITSI thresholds between Preview Aggregate Threshold values compared to the configure thresholds values?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422633#M1114</link>
      <description>&lt;P&gt;Nice research!&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 22:22:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/What-is-the-difference-in-ITSI-thresholds-between-Preview/m-p/422633#M1114</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-10-11T22:22:01Z</dc:date>
    </item>
  </channel>
</rss>

