Splunk IT Service Intelligence

Splunk IT Service Intelligence: Why do I see Services and KPIs in the entity detail page that the entity is not configured in?

r34220
Explorer

This entity only belongs to one service called "WFM". Why do I see another service? How do I only show KPIs/Services related to the entity?

alt text

0 Karma

dpearl
Explorer

Hi,

Was this issue resolved? I got this issue with version 4.1.0, but 4.3.0 works fine. Is it some bug with the version? How can it be corrected in 4.1.0?

0 Karma

dpearl
Explorer

Hi,

I am not sure whether it helps anyone. I was trying to create a KPI using an adhoc search. The host as per this KPI was not entered as Entity rather it can be seen only in the Analyzer view for status. When I checked in the itsi_entities kvstore, I found that these search based KPI result(host) was entered in it. It should not be happening. I remember trying to update some entities, one of its info field had this new KPI result host. I am not sure what caused that to happen. For now I deleted all those entities and created them again, which removed and added those entities from the itsi_entities kvstore. Also I had to recreate the KPI as it was showing the past results. Now everything works fine. Looks like some issue with 4.1.0 version of ITSI or I did something wrong while updating the Entity list.

Thanks

0 Karma

thejeffreystone
Path Finder

It looks like that entity is assigned to another service. I would check the ADPOC service and see if that host is being included in one of the rules.

0 Karma

r34220
Explorer

I checked the ADPOC service and that host is not one of the Entities configured.

0 Karma

thejeffreystone
Path Finder

Interesting. That is the only place it would be set that I know of. I am not sure how you can have an entity linked to a service without with being included in the entities rules. I suspected there was some rule in the service grabbing it.

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...