<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with Service Health Score in ITSI in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302633#M302</link>
    <description>&lt;P&gt;The KPI is running an adhoc search. &lt;/P&gt;</description>
    <pubDate>Thu, 23 Nov 2017 13:08:02 GMT</pubDate>
    <dc:creator>svendby90</dc:creator>
    <dc:date>2017-11-23T13:08:02Z</dc:date>
    <item>
      <title>Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302631#M300</link>
      <description>&lt;P&gt;We are experiencing issues with services' health score alternating between 0 and 100 in the Service Analyzer in ITSI. &lt;BR /&gt;
The health scores shows 0 even though all the underlying KPIs are ok. This happens for all of our defined services. The simplest case is shown below. Here we have a service "Azure Status" with only one defined KPI: "AzureStatus".&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3907iCCFBC513DA60C98D/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;We recently updated to 3.0.0, but experienced the same issue before the upgrade (version 2.4.0).&lt;/P&gt;

&lt;P&gt;Anyone ideas what would cause this or what the issue is?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 13:02:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302631#M300</guid>
      <dc:creator>svendby90</dc:creator>
      <dc:date>2017-11-23T13:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302632#M301</link>
      <description>&lt;P&gt;Is that KPI running a base search or adhoc search?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 13:05:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302632#M301</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-11-23T13:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302633#M302</link>
      <description>&lt;P&gt;The KPI is running an adhoc search. &lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 13:08:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302633#M302</guid>
      <dc:creator>svendby90</dc:creator>
      <dc:date>2017-11-23T13:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302634#M303</link>
      <description>&lt;P&gt;Are you running on a single heard head or in a cluster?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 13:13:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302634#M303</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-11-23T13:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302635#M304</link>
      <description>&lt;P&gt;Single search head. &lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 13:15:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302635#M304</guid>
      <dc:creator>svendby90</dc:creator>
      <dc:date>2017-11-23T13:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302636#M305</link>
      <description>&lt;P&gt;Can you move your "Azure Status" service to a glass table icon and see if your still getting zero? This will tell us if its a Service Analyzer or ITSI issue&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 13:19:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302636#M305</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-11-23T13:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302637#M306</link>
      <description>&lt;P&gt;It looks to be alternating. The KPI's value is constant, but the health is switching from 100 to 0 at random intervals. &lt;/P&gt;

&lt;P&gt;What's interesting, I tried adding some of the other services health scores to the same glass table, and all the scores are alternating between 0 and 100 at the exact same time. And there are no defined dependencies between them. &lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 13:57:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302637#M306</guid>
      <dc:creator>svendby90</dc:creator>
      <dc:date>2017-11-23T13:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302638#M307</link>
      <description>&lt;P&gt;Can you share your adhoc search?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 14:22:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302638#M307</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-11-23T14:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302639#M308</link>
      <description>&lt;P&gt;Yes! Search:&lt;BR /&gt;
index=azure host=azure_rss  sourcetype=azure_status&lt;BR /&gt;
| eval value=if(StatusMessage="An issue has been discovered",0,1)&lt;/P&gt;

&lt;P&gt;Threshold field: value&lt;BR /&gt;
Split by entity: No&lt;BR /&gt;
Calculating Average of aggregate over the last 15 minute(s) every 5 minutes.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:56:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302639#M308</guid>
      <dc:creator>svendby90</dc:creator>
      <dc:date>2020-09-29T16:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302640#M309</link>
      <description>&lt;P&gt;I see the issue.. You are returning a value of 0 if the condition is true and returning a value of 1 if the condition is false. When ITSI is averaging the two values, it will never work out correctly. &lt;/P&gt;

&lt;P&gt;A better approach would be to not average the results but rather sum them over the 5 minute span and if the count goes over a specified threshold, it can change the color of the KPI. &lt;/P&gt;

&lt;P&gt;If you take this approach then your eval should look like this&lt;BR /&gt;
&lt;CODE&gt;| eval value=if(StatusMessage="An issue has been discovered",1,0)&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 15:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302640#M309</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-11-23T15:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302641#M310</link>
      <description>&lt;P&gt;Ok, I see. Thanks. I will try and see how it goes &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;However, as I brieftly mentioned ealier, this happens with &lt;EM&gt;all&lt;/EM&gt; of our defined services. Another example is our AD monitoring where the four KPIs defining the service are green and the overall service health is red at 0. These KPIs are based on counters in standard perfmon logs, have no dependencies and are adhoc searches. An example of one of them is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=perfmon_ad host=&amp;lt;host-prefix&amp;gt;*  source="Perfmon:CPU Load" counter="% Processor Time"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here, the threshold field is the field "Value" and we calculate maximum per entity, average of aggregate over the last 5 minute(s) ever 5 minute(s). The calculated value is typically 4-5% and threshold level "medium" is triggered when it reaches about 80%.&lt;/P&gt;

&lt;P&gt;This is the case with the other counters as well. They are well below the trigger tresholds. So I don't see the reason why the overall service should be red...&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 10:07:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302641#M310</guid>
      <dc:creator>svendby90</dc:creator>
      <dc:date>2017-11-24T10:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302642#M311</link>
      <description>&lt;P&gt;Do you have the correct lag set? This could affect your output. &lt;/P&gt;

&lt;P&gt;Try creating another service and adding a single ad-hoc KPI to it to see if the service reports the KPI score. Start small and add more KPI's to your service and verify its working. You should also create a glass table and add your service and KPI's to the glasstable rather than viewing it in the service analyzer.&lt;/P&gt;

&lt;P&gt;I've noticed its easy to corrupt services when removing KPI's in earlier versions.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 14:24:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302642#M311</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-11-24T14:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302643#M312</link>
      <description>&lt;P&gt;Did this work for you?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 14:57:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302643#M312</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-11-27T14:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302644#M313</link>
      <description>&lt;P&gt;Sorry, haven't been working on this for a few days. However, the problem has now been solved!&lt;/P&gt;

&lt;P&gt;It turned out the dev. SH kept writing to the itsi_summary index.  ITSI is installed and the services are defined, but the inputs are not all in place. The result was two log entries a minute, one with the right service health score and one constantly at zero, causing the health score to be incorrectly calculated. &lt;/P&gt;

&lt;P&gt;Anyway, thanks for your input, skoelpin! Now I know more about how to troubleshoot ITSI issues : )&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302644#M313</guid>
      <dc:creator>svendby90</dc:creator>
      <dc:date>2017-11-28T09:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Service Health Score in ITSI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302645#M314</link>
      <description>&lt;P&gt;It turned out our dev. SH kept writing to the itsi_summary index.  ITSI is installed and the services are defined, but not all of the inputs are in place. The result was two log entries a minute, one with the right service health score and one constantly at zero, causing the health score to be incorrectly calculated.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:10:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Issue-with-Service-Health-Score-in-ITSI/m-p/302645#M314</guid>
      <dc:creator>svendby90</dc:creator>
      <dc:date>2017-11-28T09:10:11Z</dc:date>
    </item>
  </channel>
</rss>

