<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I add and use ad hoc search KPI without entities? in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/Can-I-add-and-use-ad-hoc-search-KPI-without-entities/m-p/382535#M596</link>
    <description>&lt;P&gt;Can I add and use ad hoc search KPI without entities?&lt;/P&gt;

&lt;P&gt;I have a service where I want to add a generic KPI and use ad hoc search, says like attached pic below,&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6793i1003EF9BDC165B16/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I see that in Service Analyzer, the SSH Gateway KPI for SSH connection value is N/A, and it says 0 entities also.&lt;BR /&gt;
I also tried to add host field at Split by Entity, Entity Filter Field, and Entity Alias Filtering, but no luck also,&lt;/P&gt;

&lt;P&gt;Am I missing something? Thank you!&lt;/P&gt;</description>
    <pubDate>Thu, 28 Mar 2019 06:02:58 GMT</pubDate>
    <dc:creator>deodion</dc:creator>
    <dc:date>2019-03-28T06:02:58Z</dc:date>
    <item>
      <title>Can I add and use ad hoc search KPI without entities?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Can-I-add-and-use-ad-hoc-search-KPI-without-entities/m-p/382535#M596</link>
      <description>&lt;P&gt;Can I add and use ad hoc search KPI without entities?&lt;/P&gt;

&lt;P&gt;I have a service where I want to add a generic KPI and use ad hoc search, says like attached pic below,&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6793i1003EF9BDC165B16/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I see that in Service Analyzer, the SSH Gateway KPI for SSH connection value is N/A, and it says 0 entities also.&lt;BR /&gt;
I also tried to add host field at Split by Entity, Entity Filter Field, and Entity Alias Filtering, but no luck also,&lt;/P&gt;

&lt;P&gt;Am I missing something? Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 06:02:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Can-I-add-and-use-ad-hoc-search-KPI-without-entities/m-p/382535#M596</guid>
      <dc:creator>deodion</dc:creator>
      <dc:date>2019-03-28T06:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can I add and use ad hoc search KPI without entities?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Can-I-add-and-use-ad-hoc-search-KPI-without-entities/m-p/382536#M597</link>
      <description>&lt;P&gt;It is not necessary to use entities with a KPI. You shouldn't need to worry about any of the Split by Entity, Entity Filter Field, and Entity Alias Filtering conditions.&lt;/P&gt;

&lt;P&gt;I notice that your search uses &lt;CODE&gt;stats&lt;/CODE&gt;, which is generally frowned upon when creating KPI searches. I believe that is what is causing your issue. Try the following search instead.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index=connectivity sourcetype=connect_ping | eval kpi_msg=if(action="connection succeeded", 100, 0)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Then use the latest &lt;CODE&gt;kpi_msg&lt;/CODE&gt; as the aggregate value for the service.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 10:21:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Can-I-add-and-use-ad-hoc-search-KPI-without-entities/m-p/382536#M597</guid>
      <dc:creator>sduff_splunk</dc:creator>
      <dc:date>2019-03-28T10:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can I add and use ad hoc search KPI without entities?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Can-I-add-and-use-ad-hoc-search-KPI-without-entities/m-p/382537#M598</link>
      <description>&lt;P&gt;yes you are correct I found the answer after I post question anyway thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 02:04:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Can-I-add-and-use-ad-hoc-search-KPI-without-entities/m-p/382537#M598</guid>
      <dc:creator>deodion</dc:creator>
      <dc:date>2019-04-02T02:04:57Z</dc:date>
    </item>
  </channel>
</rss>

