Splunk IT Service Intelligence

How to use evaluated fields as threshold field in ITSI?

Kendo213
Communicator

Is this possible? I have some searches I use for dashboards where I'm doing various evals. For example, I'm evaluating the storage free percent field, and then attempting to use that as the threshold field in ITSI. It doesn't seem to see the data, can't do a back fill, it's listed as N/A, etc.

0 Karma

lukas_loder
Communicator

Try with the same search, but than use a timechart at the end of your search.
And in ITSI go and choose "last" value of your eval field. This way it worked for me to get the backfill working

0 Karma

Kendo213
Communicator

timechart last(PercentUsed) doesn't seem to show a value, although chart last(PercentUsed) does. If I do that, and set the threshold field as last(PercentUsed) I'm still not populating any data.

Am I doing what you were recommending, just to clarify?

0 Karma

lukas_loder
Communicator

do you get some data with for example | timechart span=15min avg(PercentUsed) ?
if so can you add this search to ITSI and then when you can select there on the next windows.. just choose there "last".

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...