Splunk ITSI

How to use evaluated fields as threshold field in ITSI?

Kendo213
Communicator

Is this possible? I have some searches I use for dashboards where I'm doing various evals. For example, I'm evaluating the storage free percent field, and then attempting to use that as the threshold field in ITSI. It doesn't seem to see the data, can't do a back fill, it's listed as N/A, etc.

0 Karma

lukas_loder
Communicator

Try with the same search, but than use a timechart at the end of your search.
And in ITSI go and choose "last" value of your eval field. This way it worked for me to get the backfill working

0 Karma

Kendo213
Communicator

timechart last(PercentUsed) doesn't seem to show a value, although chart last(PercentUsed) does. If I do that, and set the threshold field as last(PercentUsed) I'm still not populating any data.

Am I doing what you were recommending, just to clarify?

0 Karma

lukas_loder
Communicator

do you get some data with for example | timechart span=15min avg(PercentUsed) ?
if so can you add this search to ITSI and then when you can select there on the next windows.. just choose there "last".

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...