Splunk IT Service Intelligence

Max length of KPI Base Search metric title in ITSI

ewan000
Path Finder

I created some base searches with the API with very long metric names derived from statsd metrics.

When I attempted to add these KPIs to a service via the UI I discovered that although the drop-down of the metrics from the base search populates and allows you select one. when you click 'next' you get an error "Metric field is required"

I attempted to edit the KPI base search with the UI to shorten the metric name, but although no error is thrown the UI will ignore the change.

I added a new metric with the name "test" and was able to select and proceed with adding this KPI to a service.

The documentation* doesn't seem to have a schema for the metric array and what information it has doesnt mention any max lengths of fields that i can see.

Is there a max length that I have exceeded, or is it something else about the way I have created the KPI base search?

*https://docs.splunk.com/Documentation/ITSI/4.4.1/RESTAPI/ITSIRESTAPIschema

Labels (2)
0 Karma
1 Solution

ewan000
Path Finder

I found that this is caused by not filling in the _key field on each metric

View solution in original post

0 Karma

ewan000
Path Finder

I found that this is caused by not filling in the _key field on each metric

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...