Splunk IT Service Intelligence

How to enable Splunk IT Service Intelligence to use earliest=@d modifier to execute search at midnight?

anveshdodda
New Member

When you write earliest=@d, it executes search from midnight in Splunk Cloud. But in Splunk IT Service Intelligence (ITSI), it executes from the last 24 hours. My preference is for ITSI to perform as it does in Splunk Cloud. So is this an issue in Splunk?

0 Karma

rossl_splunk
Splunk Employee
Splunk Employee

Where are you defining that search? Is that in a KPI search? Also are you using a different version of ITSI than is installed on the cloud instance?

0 Karma

anveshdodda
New Member

Hi ..
Thanks for your reply

Yes it's in the kpi base search ...
I use the same one that is installed on the cloud instance ....
Also when i put kpi summary as off then I get the same count as I get in base core splunk but when I change the kpi summary to on that's where I get the kpi count different ...

0 Karma

rossl_splunk
Splunk Employee
Splunk Employee

Are you sure the data is the same? Also, "earliest" and "latest" in a KPI Base Search is not recommended. We recommend that you use the KPI Interval option in the UI if you can.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...