Splunk IT Service Intelligence

Splunk IT Service Intelligence 2.2: Using base searches to pull back data for several KPIs, why are all returned KPI values identical?

New Member

I have created a base search to pull back data for several KPIs. The base search is set to split & filter by entity. It appears that the KPI value is the same across all services in which it is used even though the entities are completely different. When editing the KPI and viewing the generated search, the search looks correct and returns different values based on the service in which I edit the KPI. When looking at the savedsearches.conf for the shared search, it looks correct as well, but all values for the KPI results for each service in the UI are all identical. I can reproduce this with other searches as well. The happens when I clone the KPI or when I manually create the KPI.

Is anyone else successfully using the base search functionality in 2.2?

0 Karma

Path Finder

While creating base search, enable this setting "Filter to Entities in Service" and set Entity alias filtering.

Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...