Getting Data In

What's wrong with my ITSI logic monitoring running Process?

Skins
Path Finder

I have a base search as such :

index=windows host=specific_hosts* Type=Service Name=servicename | eval Service_Running=if(State="Running",1,0)
every 5 mins
last 5 mins
split by ent = Y
filter to entities in service
entity lookup = host

Then I have created a metric

Title = Service Running
Threshold Field = Service_Running
Entity Calculation  latest
Service Calculation latest

This gives me a 1 charting nicely in the Aggregate Threshold Values and I've set a threshold of 1 normal 0 critical

However, I get N/A in the KPI's for all of these hosts?

gratzi

Tags (3)
0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...