Splunk IT Service Intelligence

Using the Splunk IT Service Intelligence service analyzer feature, how do you separate views of services/entities?

luke222010
Engager

I can see in the Service Analyzer that you can create individual Service Analyzer views.

However, when creating a new one, I inherit all services and entities from my default Service Analyzer view.

Is this intended behavior, and if so, how can we create a blank Service Analyzer view where we can populate it with other services and entities?

0 Karma

hjauch_splunk
Splunk Employee
Splunk Employee

When you create a new service analyzer, you start with a standard service analyzer view, then you customize it and save it. See https://docs.splunk.com/Documentation/ITSI/4.0.2/User/Createcustomserviceanalyzers

For example, it you only want to show the "Active Directory" service, then you would filter it to this service and click Save.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...