Splunk IT Service Intelligence

How to enable Splunk IT Service Intelligence to use earliest=@d modifier to execute search at midnight?

anveshdodda
New Member

When you write earliest=@d, it executes search from midnight in Splunk Cloud. But in Splunk IT Service Intelligence (ITSI), it executes from the last 24 hours. My preference is for ITSI to perform as it does in Splunk Cloud. So is this an issue in Splunk?

0 Karma

rossl_splunk
Splunk Employee
Splunk Employee

Where are you defining that search? Is that in a KPI search? Also are you using a different version of ITSI than is installed on the cloud instance?

0 Karma

anveshdodda
New Member

Hi ..
Thanks for your reply

Yes it's in the kpi base search ...
I use the same one that is installed on the cloud instance ....
Also when i put kpi summary as off then I get the same count as I get in base core splunk but when I change the kpi summary to on that's where I get the kpi count different ...

0 Karma

rossl_splunk
Splunk Employee
Splunk Employee

Are you sure the data is the same? Also, "earliest" and "latest" in a KPI Base Search is not recommended. We recommend that you use the KPI Interval option in the UI if you can.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...