Splunk ITSI

ITSI Adaptive thresholding per entity

sapanda
Path Finder

Hello all,

I am exploring ways to enable adaptive thresholds for entities in ITSI. As per Splunk Documentation, Adaptive thresholds are not allowed to be configured per entity. I would like to know if anybody has explored to do this with any customizations?

thanks,
Sapan

yannK
Splunk Employee
Splunk Employee

True, the thresholds per entity are not yet possible.
If you have a support contract, do not hesitate to open an Enhancement Request.

Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...