Splunk IT Service Intelligence

I want my threshold value to change with time and search result Splunk ITSI

New Member

Hi, I am looking for an email in KPI ad-hoc search which is supposed to arrive at -7-15am. if it doesn't arrive at 07:15 i want KPI threshold to go amber and if i don't receive it till 07:45(30 mins later) I want my threshold value to turn red. Only when the email arrives values changes to green.

Any help appreciated. Thanks

Labels (1)
0 Karma

Contributor

you can configure time based KPI thresholds along with base/adhoc search. Please refer this page

https://docs.splunk.com/Documentation/ITSI/4.5.0/SI/TimePolicies

0 Karma