Splunk ITSI

ITSI: How to create services from search results in N/A services?

YoungDaniel
Path Finder

Hi,
We are running ITSI on a dedicated Search head running 16 cores cpu , 23 gb RAM and about 150 gb disk. It's searching an Index Cluster serving a SH Cluster and two stand alone search heads.

We have about 400 services with 3-5 kpis each. The majority of these services have been created by import through search and mass produced. They have all worked fine. However, when we try to add more services, from a specific search, we are getting NaN for each KPI and ServiceHealthScore. We have removed backfilling on the service KPIs and set static thresholds. The skipped search rate is very low,( 1,34%, 66 searches) But the new services (138) all are missing values. When the service is opened up in deep dive and summary index turned off, we get data for the entirety of kpis. The Kpis use stats sum and count.
We turned up the
[kvstore]
max_size_per_batch_save_mb = 100

In limits.conf
Our ITSI_backfill is at 49 mb. we are not using Backfill on these services/kpis so that should not be the problem.

So I am wondering two things,
How does ITSI create the services and Kpis from search?
How do I reload a service and its kpis?

BR / Daniel

Labels (3)
0 Karma

Raja
Engager

Hello Daniel,

Can you help me with search query to create services with dependencies with service template assign.

 

0 Karma

ansif
Motivator

We had same issue ,when data fetches from summary index it shows no data but when disabling Summary Index it works.

Our problem resolved by adding more roles to admin.Try to play around roles and check if the serach works with Summary.

try to add all app_admin and user.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...