Splunk ITSI

Episode review not Displaying Impacted Entities details

shwetas
Explorer

Hi All,

We have brought up Azure monitoring on ITSI and configured KPI alerts to display alerts under Episode review.At present the issue which we have is when we select Episodes in right sides it wont display Impacted entities details.

Did any one faced same issue or any direction on how it can be fix?alt text

0 Karma

proyleJDS
Path Finder

I found a couple of things you can do here

1. Add the Entity Lookup Field from your correlation search here:

proyleJDS_0-1722892631031.png

That will give you whatever you evaluate entity_title too in your search as the impacted entity in your KPI

2. Just add the entity_key field to your lookup, this automatically adds any entities to the impacted entities for the KPI, though it won't add pseudo entities such as a combined field like host:disk

0 Karma

merrelr
Path Finder

My Episodes didn't have any "Impacted entities" until I enabled the correlation search "Service Monitoring - Entity Degraded"

0 Karma

gballanti
Explorer

Hello, I have the same issue ... anyone solved ?

0 Karma

pauliushcl
New Member

I'm facing the similar issue. Entities are defined in the service and enabled in the base search.
Entity is found in the KPI base search, but when the notable event is triggered it says no entity impacted.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I'll ask the obvious question.. Did you enable entities when creating the service/base search? Did you define the entities in your service?

0 Karma

pauliushcl
New Member

I face the same issue:
entities defined in the service and enabled in base search. When looking in the KPI threshold settings entity is presented there. But notable event is triggered it says "No impacted entities"

0 Karma

iatwal
Path Finder

did you ever get an answer to this or figure this out?

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...