<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is meant by entity in Splunk ITSI, which field need to add as Entity split by while cresting KPI? in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-meant-by-entity-in-Splunk-ITSI-which-field-need-to-add/m-p/390671#M717</link>
    <description>&lt;P&gt;An &lt;STRONG&gt;entity&lt;/STRONG&gt; is an IT infrastructure component, such as:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;A physical or virtual server&lt;/LI&gt;
&lt;LI&gt;A network device (switch, router)&lt;/LI&gt;
&lt;LI&gt;A user (AD/LDAP)&lt;/LI&gt;
&lt;LI&gt;A storage system or volume&lt;/LI&gt;
&lt;LI&gt;An operating system process&lt;/LI&gt;
&lt;LI&gt;A software application (database, web server, business app)&lt;/LI&gt;
&lt;LI&gt;An application process instance (for example, 2 instances of the same web server application is 2 separate entities)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Each entity has specific attributes and relationships to other IT processes that uniquely identify it. For example, a server that you define as an entity can have multiple IP addresses, MAC addresses, DNS names, and so on.&lt;/P&gt;

&lt;P&gt;Meanwhile, &lt;STRONG&gt;KPIs&lt;/STRONG&gt; help you monitor the status of these various IT components by monitoring performance metrics, such as CPU load percentage, memory used percentage, response time, and so on.&lt;/P&gt;

&lt;P&gt;For information about key ITSI concept, like entities and KPIs, see: &lt;A href="https://docs.splunk.com/Documentation/ITSI/latest/Configure/KeyConcepts"&gt;https://docs.splunk.com/Documentation/ITSI/latest/Configure/KeyConcepts&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;For information about the entity split field, see: &lt;A href="https://docs.splunk.com/Documentation/ITSI/latest/Configure/AddKPIs#Step_3:_Filter_entities"&gt;https://docs.splunk.com/Documentation/ITSI/latest/Configure/AddKPIs#Step_3:_Filter_entities&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Oct 2019 19:35:03 GMT</pubDate>
    <dc:creator>esnyder_splunk</dc:creator>
    <dc:date>2019-10-25T19:35:03Z</dc:date>
    <item>
      <title>What is meant by entity in Splunk ITSI, which field need to add as Entity split by while cresting KPI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-meant-by-entity-in-Splunk-ITSI-which-field-need-to-add/m-p/390670#M716</link>
      <description>&lt;P&gt;What is meant by entity in Splunk ITSI,&lt;BR /&gt;
 Which field need to add as Entity split by while cresting KPI?&lt;BR /&gt;
I want to display the traffic of host in on e KPI,&lt;BR /&gt;
What is the need of the Entity, while creating KPI.&lt;BR /&gt;
Why to add metrics?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 05:59:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/What-is-meant-by-entity-in-Splunk-ITSI-which-field-need-to-add/m-p/390670#M716</guid>
      <dc:creator>nasrinmulani</dc:creator>
      <dc:date>2018-06-21T05:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: What is meant by entity in Splunk ITSI, which field need to add as Entity split by while cresting KPI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-meant-by-entity-in-Splunk-ITSI-which-field-need-to-add/m-p/390671#M717</link>
      <description>&lt;P&gt;An &lt;STRONG&gt;entity&lt;/STRONG&gt; is an IT infrastructure component, such as:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;A physical or virtual server&lt;/LI&gt;
&lt;LI&gt;A network device (switch, router)&lt;/LI&gt;
&lt;LI&gt;A user (AD/LDAP)&lt;/LI&gt;
&lt;LI&gt;A storage system or volume&lt;/LI&gt;
&lt;LI&gt;An operating system process&lt;/LI&gt;
&lt;LI&gt;A software application (database, web server, business app)&lt;/LI&gt;
&lt;LI&gt;An application process instance (for example, 2 instances of the same web server application is 2 separate entities)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Each entity has specific attributes and relationships to other IT processes that uniquely identify it. For example, a server that you define as an entity can have multiple IP addresses, MAC addresses, DNS names, and so on.&lt;/P&gt;

&lt;P&gt;Meanwhile, &lt;STRONG&gt;KPIs&lt;/STRONG&gt; help you monitor the status of these various IT components by monitoring performance metrics, such as CPU load percentage, memory used percentage, response time, and so on.&lt;/P&gt;

&lt;P&gt;For information about key ITSI concept, like entities and KPIs, see: &lt;A href="https://docs.splunk.com/Documentation/ITSI/latest/Configure/KeyConcepts"&gt;https://docs.splunk.com/Documentation/ITSI/latest/Configure/KeyConcepts&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;For information about the entity split field, see: &lt;A href="https://docs.splunk.com/Documentation/ITSI/latest/Configure/AddKPIs#Step_3:_Filter_entities"&gt;https://docs.splunk.com/Documentation/ITSI/latest/Configure/AddKPIs#Step_3:_Filter_entities&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 19:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/What-is-meant-by-entity-in-Splunk-ITSI-which-field-need-to-add/m-p/390671#M717</guid>
      <dc:creator>esnyder_splunk</dc:creator>
      <dc:date>2019-10-25T19:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: What is meant by entity in Splunk ITSI, which field need to add as Entity split by while cresting KPI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/What-is-meant-by-entity-in-Splunk-ITSI-which-field-need-to-add/m-p/390672#M718</link>
      <description>&lt;P&gt;Entities are an abstract layer to identify an asset.&lt;BR /&gt;
By example an entity could be as basic as a host, but could also be used for a cpu core#, or an application on a server ...&lt;BR /&gt;
An entity is defined by &lt;STRONG&gt;alias fields&lt;/STRONG&gt; (unique fields values, like a host or a vm id), or &lt;STRONG&gt;info fields&lt;/STRONG&gt; (can be the same for several entities, like a datacenter location, a service role ...)&lt;/P&gt;

&lt;P&gt;in ITSI the entities are used for 2 things :&lt;BR /&gt;
- group entities in a service, using a filter, or a direct link.&lt;BR /&gt;
- for the KPIs in a service&lt;/P&gt;

&lt;P&gt;in KPI :&lt;BR /&gt;
- you can ask to filter to only the entities in the service, or not (optional)&lt;BR /&gt;
- you can also ask do to a split by of the metrics, to get the detail per entity. (optional)&lt;/P&gt;

&lt;P&gt;For the split by&lt;BR /&gt;
- if you are use a field (alias/info) to do the entity split by, then it will refer to a &lt;STRONG&gt;real entity&lt;/STRONG&gt;&lt;BR /&gt;
- but you could also use a split by field that is not specific to a real entity, we will then say that you are creating "&lt;STRONG&gt;pseudo entities&lt;/STRONG&gt;", that only exits in the KPI metrics results (by example do a split by process when you do not use this field for entities)&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 19:48:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/What-is-meant-by-entity-in-Splunk-ITSI-which-field-need-to-add/m-p/390672#M718</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2019-10-25T19:48:02Z</dc:date>
    </item>
  </channel>
</rss>

