Getting Data In

What's wrong with my ITSI logic monitoring running Process?

Path Finder

I have a base search as such :

index=windows host=specific_hosts* Type=Service Name=servicename | eval Service_Running=if(State="Running",1,0)
every 5 mins
last 5 mins
split by ent = Y
filter to entities in service
entity lookup = host

Then I have created a metric

Title = Service Running
Threshold Field = Service_Running
Entity Calculation  latest
Service Calculation latest

This gives me a 1 charting nicely in the Aggregate Threshold Values and I've set a threshold of 1 normal 0 critical

However, I get N/A in the KPI's for all of these hosts?


Tags (3)
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!