Getting Data In

What's wrong with my ITSI logic monitoring running Process?

Skins
Path Finder

I have a base search as such :

index=windows host=specific_hosts* Type=Service Name=servicename | eval Service_Running=if(State="Running",1,0)
every 5 mins
last 5 mins
split by ent = Y
filter to entities in service
entity lookup = host

Then I have created a metric

Title = Service Running
Threshold Field = Service_Running
Entity Calculation  latest
Service Calculation latest

This gives me a 1 charting nicely in the Aggregate Threshold Values and I've set a threshold of 1 normal 0 critical

However, I get N/A in the KPI's for all of these hosts?

gratzi

Tags (3)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...