Getting Data In

Is Splunk planning to offer guidance on naming conventions in the Metrics Index in relation to CIM?

rjthibod
Champion

Splunk 7.0 introduced the Metrics Index feature and a whole new naming scheme.

Is Splunk planning to use or offer something similar to the CIM for metrics index measurements and dimensions? Will data in the Metrics Index be targeted for integration with ITSI and ES based on the naming conventions?

App developers are in the process of migrating things into the Metrics Index, so it would be could to know what to plan for.

1 Solution

mattymo
Splunk Employee
Splunk Employee

As of now Metrics are not designed with CIM in mind. Keep in mind neither is ITSI.

- MattyMo

View solution in original post

0 Karma

lmaclean
Path Finder

From a few searches I have done based upon any type of standard that Statsd or Collectd have, there are a few that make sense:

schema.application_name.namespace.metric_name.metric_type

So for something as simple as OS Metrics l believe for the "metric_name" field going along the lines of:

os.<type>.<sub_type>.<metric>

e.g:
- os.cpu.percent
- os.cpu.interrupts_sec
- os.mem.swap.percent
- os.mem.pages_sec
- os.system.threads
- os.process.mem.used
- os.disk.free.percent
etc...

Refs:
https://matt.aimonetti.net/posts/2013/06/26/practical-guide-to-graphite-monitoring/
https://collectd.org/wiki/index.php/Naming_schema
https://www.slideshare.net/itnig/collecting-metrics-with-graphite-and-statsd

mattymo
Splunk Employee
Splunk Employee

As of now Metrics are not designed with CIM in mind. Keep in mind neither is ITSI.

- MattyMo
0 Karma

rjthibod
Champion

Any updates or input Splunk ppl?

0 Karma
Get Updates on the Splunk Community!

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...