Splunk IT Service Intelligence

Can only a "master" service health score be created?

sallyanntracy
Explorer

I'm hoping this is a simple question. Our servers are set up in a fairly common model: a prod environment and lower environments and within them different tiers (database, app, presentation). Nothing exciting.

I've created services for prod application, database and presentation servers and one service for all the lower environments. Here's the thing: I'd like to just display a master service health score for the entirety of the application for display on a service analyzer and then allow ops teams to drill into it if things go south. We have hundreds of applications and I think having 4 service health scores for each would be overwhelming for the ops teams.

Is the only way to do this by creating custom service analyzers?

0 Karma

esnyder_splunk
Splunk Employee
Splunk Employee

I suggest creating one "parent" service of all of your applications. In other words, create one service and make all of your applications "dependent services" of this parent service: https://docs.splunk.com/Documentation/ITSI/latest/Configure/Addservicedependencies. In the service analyzer tree view, all of these applications would be on one layer, and they'd all be pointing up to the single parent service on the next layer up.

Then you can create a custom service analyzer view that only displays that one parent service: https://docs.splunk.com/Documentation/ITSI/latest/User/Createcustomserviceanalyzers

Get Updates on the Splunk Community!

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...