Splunk IT Service Intelligence

Why is the aggregated threshold for the KPIs only showing the values of the top entity?


We set up a service measuring datastore free space usage, overprovisioning , read and write activity.

Large amount of entities  are shown and per entity thresholds are working fine.

However the aggregated threshold for the KPIs show only the values of the top entity. 

According to manual the aggregated threshold should present an average of all entities result.

Is there a setting I am not using correct?

Labels (1)
0 Karma


It's possible that the aggregated threshold is set to only display the top entity due to a configuration setting.

You can check the settings and configuration documentation for the service to see if there is an option to display an average of all entities' results for the aggregated threshold. If not, you may need to modify the code or seek help from the vendor or support team for the service.

It's also possible that there is a bug in the service that's causing this behavior. In that case, you may want to report the issue to the vendor or support team for further investigation.

I hope it will help you. 

0 Karma
Get Updates on the Splunk Community!

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...