Splunk ITSI

ITSI - Add calculation window options to KPI Base Search

sail4lot
Path Finder

Does anyone know if there is a way to add additional options to the KPI Base Search Calculation window? I need something more than 15m but less than 24h.

1 Solution

esnyder_splunk
Splunk Employee
Splunk Employee

You can customize the calculation window by uploading a KPI base search through $SPLUNK_HOME/etc/apps/SA-ITOA/local/itsi_kpi_base_search.conf.

https://docs.splunk.com/Documentation/ITSI/latest/Configure/itsi_kpi_base_search.conf

Add a stanza for your base search and set the alert_period to whatever you want it to be. For example, "45" for 45 minutes. Save and close the file and then restart Splunk software. The search you added should show up on the base search lister page.

View solution in original post

esnyder_splunk
Splunk Employee
Splunk Employee

You can customize the calculation window by uploading a KPI base search through $SPLUNK_HOME/etc/apps/SA-ITOA/local/itsi_kpi_base_search.conf.

https://docs.splunk.com/Documentation/ITSI/latest/Configure/itsi_kpi_base_search.conf

Add a stanza for your base search and set the alert_period to whatever you want it to be. For example, "45" for 45 minutes. Save and close the file and then restart Splunk software. The search you added should show up on the base search lister page.

Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...