All Apps and Add-ons

ITSI: two KPIS with critical severity not working

jaimelopez
Explorer

Hello all,

I am trying to configure a service in ITSI with two KPIS ("A", "B") with the most severity (11).

When I do the test inside the configuration of the service it works perfectly, if any of these KPIS get critical status, global health score of the service gets 0 (critical).

But in the practice, when the service is running with real data, only when "A" gets critical, global health score of the service changes to critical, but it does not happens with "B". I seems that system gives more importance to "A" than "B".

I would like to ask if someone is facing the same issue, if someone knows that this is a real limitation of ITSI (although in testing mode when setting configuration of service it works well) and if someone has a solution for this.

Thanks very much in advance for the help,

0 Karma

lloydknight
Builder

Hello @jaimelopez

Aside from both A and B's KPI Importance value set to 11, may I know if you've set entities on them and what are the thresholds of A and B KPI?

While the condition on "KPI A" was met while "KPI B" did not, my hunch is that they both have different thresholds set and should you have defined entities for both KPIs, did you split the aggregation of data by entities?

0 Karma

jaimelopez
Explorer

Hello @lloydknight ,
Both KPIS have as entities the different servers and the thresholds are the same:
Base severity: critical
Critical: 0
Normal:1

In a test way with the simulator it works as expected but not when conditions are met with real data.

Best regards,

Thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...