Splunk ITSI

ITSI: How to create services from search results in N/A services?

YoungDaniel
Path Finder

Hi,
We are running ITSI on a dedicated Search head running 16 cores cpu , 23 gb RAM and about 150 gb disk. It's searching an Index Cluster serving a SH Cluster and two stand alone search heads.

We have about 400 services with 3-5 kpis each. The majority of these services have been created by import through search and mass produced. They have all worked fine. However, when we try to add more services, from a specific search, we are getting NaN for each KPI and ServiceHealthScore. We have removed backfilling on the service KPIs and set static thresholds. The skipped search rate is very low,( 1,34%, 66 searches) But the new services (138) all are missing values. When the service is opened up in deep dive and summary index turned off, we get data for the entirety of kpis. The Kpis use stats sum and count.
We turned up the
[kvstore]
max_size_per_batch_save_mb = 100

In limits.conf
Our ITSI_backfill is at 49 mb. we are not using Backfill on these services/kpis so that should not be the problem.

So I am wondering two things,
How does ITSI create the services and Kpis from search?
How do I reload a service and its kpis?

BR / Daniel

Labels (3)
0 Karma

Raja
Engager

Hello Daniel,

Can you help me with search query to create services with dependencies with service template assign.

 

0 Karma

ansif
Motivator

We had same issue ,when data fetches from summary index it shows no data but when disabling Summary Index it works.

Our problem resolved by adding more roles to admin.Try to play around roles and check if the serach works with Summary.

try to add all app_admin and user.

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...