<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ITSI Service health ignores entities defined. in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Service-health-ignores-entities-defined/m-p/327304#M379</link>
    <description>&lt;P&gt;I've defined my entities to have servers named &lt;EM&gt;wdlrp&lt;/EM&gt;.  The system finds 10 such servers. &lt;BR /&gt;
I define the KPI's i'm interested in and create the service (DC Web_Servers_Health):&lt;BR /&gt;
No dependencies. &lt;/P&gt;

&lt;P&gt;The generated search seems to have the entities (servers)I want: &lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/188204-pic4.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;When i view health of the service, The service health dis-regards my entity list (notice the missing &lt;EM&gt;wldrp&lt;/EM&gt; servers) and includes all entities in the server farm that contain the KPI.&lt;BR /&gt;&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/188205-pic6.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;I have a few questions: &lt;BR /&gt;
1) how can I have the service analyzer entities scoped to the entities I defined up front? &lt;BR /&gt;
2) if #1 cant be achieved, is the service health showing the health based on my defined entities?&lt;BR /&gt;
Thanks, &lt;BR /&gt;
Jim &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 13:02:36 GMT</pubDate>
    <dc:creator>t2793js</dc:creator>
    <dc:date>2020-09-29T13:02:36Z</dc:date>
    <item>
      <title>ITSI Service health ignores entities defined.</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Service-health-ignores-entities-defined/m-p/327304#M379</link>
      <description>&lt;P&gt;I've defined my entities to have servers named &lt;EM&gt;wdlrp&lt;/EM&gt;.  The system finds 10 such servers. &lt;BR /&gt;
I define the KPI's i'm interested in and create the service (DC Web_Servers_Health):&lt;BR /&gt;
No dependencies. &lt;/P&gt;

&lt;P&gt;The generated search seems to have the entities (servers)I want: &lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/188204-pic4.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;When i view health of the service, The service health dis-regards my entity list (notice the missing &lt;EM&gt;wldrp&lt;/EM&gt; servers) and includes all entities in the server farm that contain the KPI.&lt;BR /&gt;&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/188205-pic6.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;I have a few questions: &lt;BR /&gt;
1) how can I have the service analyzer entities scoped to the entities I defined up front? &lt;BR /&gt;
2) if #1 cant be achieved, is the service health showing the health based on my defined entities?&lt;BR /&gt;
Thanks, &lt;BR /&gt;
Jim &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:02:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Service-health-ignores-entities-defined/m-p/327304#M379</guid>
      <dc:creator>t2793js</dc:creator>
      <dc:date>2020-09-29T13:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Service health ignores entities defined.</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Service-health-ignores-entities-defined/m-p/327305#M380</link>
      <description>&lt;P&gt;The scope now has "fixed" itself. I suspect that it was a timing issue where waiting 24 hours from changes made yesterday in the core search filtered out the unwanted entities. &lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2017 14:10:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Service-health-ignores-entities-defined/m-p/327305#M380</guid>
      <dc:creator>t2793js</dc:creator>
      <dc:date>2017-02-28T14:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Service health ignores entities defined.</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Service-health-ignores-entities-defined/m-p/327306#M381</link>
      <description>&lt;P&gt;I continue to have a similar issue that corrects itself over 24 hours. The effected Kpis are both base search and cloned. I have put in support tickets against this issue. I will let you know if anything comes of it.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 02:13:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Service-health-ignores-entities-defined/m-p/327306#M381</guid>
      <dc:creator>mfscully</dc:creator>
      <dc:date>2017-03-10T02:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI Service health ignores entities defined.</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Service-health-ignores-entities-defined/m-p/327307#M382</link>
      <description>&lt;P&gt;Thanks, It's a pain because you get one chance a day to see if the thing works, which creates delays.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 12:13:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Service-health-ignores-entities-defined/m-p/327307#M382</guid>
      <dc:creator>t2793js</dc:creator>
      <dc:date>2017-03-10T12:13:17Z</dc:date>
    </item>
  </channel>
</rss>

