Getting Data In

What's wrong with my ITSI logic monitoring running Process?

Skins
Path Finder

I have a base search as such :

index=windows host=specific_hosts* Type=Service Name=servicename | eval Service_Running=if(State="Running",1,0)
every 5 mins
last 5 mins
split by ent = Y
filter to entities in service
entity lookup = host

Then I have created a metric

Title = Service Running
Threshold Field = Service_Running
Entity Calculation  latest
Service Calculation latest

This gives me a 1 charting nicely in the Aggregate Threshold Values and I've set a threshold of 1 normal 0 critical

However, I get N/A in the KPI's for all of these hosts?

gratzi

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...