Getting Data In

Is Splunk planning to offer guidance on naming conventions in the Metrics Index in relation to CIM?

rjthibod
Champion

Splunk 7.0 introduced the Metrics Index feature and a whole new naming scheme.

Is Splunk planning to use or offer something similar to the CIM for metrics index measurements and dimensions? Will data in the Metrics Index be targeted for integration with ITSI and ES based on the naming conventions?

App developers are in the process of migrating things into the Metrics Index, so it would be could to know what to plan for.

1 Solution

mattymo
Splunk Employee
Splunk Employee

As of now Metrics are not designed with CIM in mind. Keep in mind neither is ITSI.

- MattyMo

View solution in original post

0 Karma

lmaclean
Path Finder

From a few searches I have done based upon any type of standard that Statsd or Collectd have, there are a few that make sense:

schema.application_name.namespace.metric_name.metric_type

So for something as simple as OS Metrics l believe for the "metric_name" field going along the lines of:

os.<type>.<sub_type>.<metric>

e.g:
- os.cpu.percent
- os.cpu.interrupts_sec
- os.mem.swap.percent
- os.mem.pages_sec
- os.system.threads
- os.process.mem.used
- os.disk.free.percent
etc...

Refs:
https://matt.aimonetti.net/posts/2013/06/26/practical-guide-to-graphite-monitoring/
https://collectd.org/wiki/index.php/Naming_schema
https://www.slideshare.net/itnig/collecting-metrics-with-graphite-and-statsd

0 Karma

mattymo
Splunk Employee
Splunk Employee

As of now Metrics are not designed with CIM in mind. Keep in mind neither is ITSI.

- MattyMo
0 Karma

rjthibod
Champion

Any updates or input Splunk ppl?

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

<P style=" text-align: center; "><span class="lia-inline-image-display-wrapper lia-image-align-center" ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

<FONT size="5"><FONT size="5" color="#FF00FF">Get the latest news and updates from the Splunk Community ...