Splunk ITSI

How to enable Splunk IT Service Intelligence to use earliest=@d modifier to execute search at midnight?

anveshdodda
New Member

When you write earliest=@d, it executes search from midnight in Splunk Cloud. But in Splunk IT Service Intelligence (ITSI), it executes from the last 24 hours. My preference is for ITSI to perform as it does in Splunk Cloud. So is this an issue in Splunk?

0 Karma

rossl_splunk
Splunk Employee
Splunk Employee

Where are you defining that search? Is that in a KPI search? Also are you using a different version of ITSI than is installed on the cloud instance?

0 Karma

anveshdodda
New Member

Hi ..
Thanks for your reply

Yes it's in the kpi base search ...
I use the same one that is installed on the cloud instance ....
Also when i put kpi summary as off then I get the same count as I get in base core splunk but when I change the kpi summary to on that's where I get the kpi count different ...

0 Karma

rossl_splunk
Splunk Employee
Splunk Employee

Are you sure the data is the same? Also, "earliest" and "latest" in a KPI Base Search is not recommended. We recommend that you use the KPI Interval option in the UI if you can.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...