Getting Data In

Is Splunk planning to offer guidance on naming conventions in the Metrics Index in relation to CIM?

rjthibod
Champion

Splunk 7.0 introduced the Metrics Index feature and a whole new naming scheme.

Is Splunk planning to use or offer something similar to the CIM for metrics index measurements and dimensions? Will data in the Metrics Index be targeted for integration with ITSI and ES based on the naming conventions?

App developers are in the process of migrating things into the Metrics Index, so it would be could to know what to plan for.

1 Solution

mattymo
Splunk Employee
Splunk Employee

As of now Metrics are not designed with CIM in mind. Keep in mind neither is ITSI.

- MattyMo

View solution in original post

0 Karma

lmaclean
Path Finder

From a few searches I have done based upon any type of standard that Statsd or Collectd have, there are a few that make sense:

schema.application_name.namespace.metric_name.metric_type

So for something as simple as OS Metrics l believe for the "metric_name" field going along the lines of:

os.<type>.<sub_type>.<metric>

e.g:
- os.cpu.percent
- os.cpu.interrupts_sec
- os.mem.swap.percent
- os.mem.pages_sec
- os.system.threads
- os.process.mem.used
- os.disk.free.percent
etc...

Refs:
https://matt.aimonetti.net/posts/2013/06/26/practical-guide-to-graphite-monitoring/
https://collectd.org/wiki/index.php/Naming_schema
https://www.slideshare.net/itnig/collecting-metrics-with-graphite-and-statsd

mattymo
Splunk Employee
Splunk Employee

As of now Metrics are not designed with CIM in mind. Keep in mind neither is ITSI.

- MattyMo
0 Karma

rjthibod
Champion

Any updates or input Splunk ppl?

0 Karma
Get Updates on the Splunk Community!

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...