<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get ITSI Alerts based on KPIs from All Server Search? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-get-ITSI-Alerts-based-on-KPIs-from-All-Server-Search/m-p/337604#M5964</link>
    <description>&lt;P&gt;Yes but if I set up an aggregate policy I just get a notification that the CPU/RAM/Disk has triggered the alarm.  I do not get which of my 1700 servers has triggered this alarm.&lt;/P&gt;

&lt;P&gt;Anyway I can do that within the notification language maybe?&lt;/P&gt;</description>
    <pubDate>Fri, 09 Feb 2018 17:46:18 GMT</pubDate>
    <dc:creator>SeanPLittle</dc:creator>
    <dc:date>2018-02-09T17:46:18Z</dc:date>
    <item>
      <title>How to get ITSI Alerts based on KPIs from All Server Search?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-get-ITSI-Alerts-based-on-KPIs-from-All-Server-Search/m-p/337602#M5962</link>
      <description>&lt;P&gt;I have just been pushed into the deep end of the Splunk pool and I need to figure something out.&lt;/P&gt;

&lt;P&gt;I have ITSI and within it there is a Service that encompases all of my Server Entities.&lt;/P&gt;

&lt;P&gt;Within that Service I have KPIs for Health, CPU, network, RAM, and Disk Utilization.&lt;/P&gt;

&lt;P&gt;I would like to be able to get notifications from this service with a list of affected Entities contained in the email for the alerts.&lt;/P&gt;

&lt;P&gt;Can I do that?  How would I be able to do that?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 14:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-get-ITSI-Alerts-based-on-KPIs-from-All-Server-Search/m-p/337602#M5962</guid>
      <dc:creator>SeanPLittle</dc:creator>
      <dc:date>2018-01-29T14:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to get ITSI Alerts based on KPIs from All Server Search?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-get-ITSI-Alerts-based-on-KPIs-from-All-Server-Search/m-p/337603#M5963</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/91813"&gt;@SeanPLittle&lt;/a&gt; : It is easy,you need to create an aggregation policy under configure-&amp;gt;notable_event_aggregation_policies&lt;/P&gt;

&lt;P&gt;There you can group events and in action you can send mail or tickets or run a script etc...&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/ITSI/3.0.1/User/CreateAggregationPolicies" target="_blank"&gt;https://docs.splunk.com/Documentation/ITSI/3.0.1/User/CreateAggregationPolicies&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:58:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-get-ITSI-Alerts-based-on-KPIs-from-All-Server-Search/m-p/337603#M5963</guid>
      <dc:creator>ansif</dc:creator>
      <dc:date>2020-09-29T17:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to get ITSI Alerts based on KPIs from All Server Search?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-get-ITSI-Alerts-based-on-KPIs-from-All-Server-Search/m-p/337604#M5964</link>
      <description>&lt;P&gt;Yes but if I set up an aggregate policy I just get a notification that the CPU/RAM/Disk has triggered the alarm.  I do not get which of my 1700 servers has triggered this alarm.&lt;/P&gt;

&lt;P&gt;Anyway I can do that within the notification language maybe?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2018 17:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-get-ITSI-Alerts-based-on-KPIs-from-All-Server-Search/m-p/337604#M5964</guid>
      <dc:creator>SeanPLittle</dc:creator>
      <dc:date>2018-02-09T17:46:18Z</dc:date>
    </item>
  </channel>
</rss>

