Splunk ITSI

How can I get the failure count value in Glass table?

Mayanakhan
Explorer

I have created one base search and multiple services with entities and also created KPI using the base search.
I try to drag the KPI to glass table to get a count of particular service. In search, I get the alert value as 6 but in glass table, it shows as 0 or 10(sum of errors of all servers).

The same search is working if add a ad-hoc search in service.

Base search

index=os sourcetype=port_availability  | dedup HostName |search Status!="Connection successful"| table _time HostName port Status| eval Priority="P3"

PFA screenshots for your reference,
alt text
alt text 2: /storage/temp/228771-base-search.jpg
alt text

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You should open your KPI search and expand the macro out cmd + shift + e . Then strip everything off below the first stats command and see what it's using to create the search. You are most likely not summing the value

0 Karma

Mayanakhan
Explorer

In KPI search it showing the correct value. But not in glass table.

Also there is no option for count in Service/Aggregate calculation.
alt text

https://ibb.co/ekCpAn

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...