Splunk IT Service Intelligence

ITSI Base Search - Metrics and How they are Generated

makelovenotwar
Path Finder

I am using the nix TA to report on Unix and Linux server health. I'm trying to learn how things work by using the "Monitoring Unix and Linux" content pack and looking at how KPIs and the itsi_summary_metrics work together. I am analyzing the NIX:OS:Performance.NIX-df base search and see that it is using a "metrics search" and can't find what field that base search is looking for in my data to generate any of the metrics - for example "Free MB /". When I look at my events index (in my case the index is "os"), I have the sourcetype of df but it does not have a "Free MB /" field. Is there a saved search generating the field that the base search will be using for that metric? I looked in saved searches, Fields, All configurations, but can't find anything. Perhaps I'm looking for the wrong thing? Am I thinking about this all wrong? I am new to ITSI and am going to take the ITSI course soon.

Labels (2)
0 Karma

makelovenotwar
Path Finder

Not sure if this was the right solution, but on the base search, I changed it from "metrics search" to "ad-hoc" and the prepopulated search has eval statements that create the "Free MB /" and other fields, making my KPIs populate.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...