Hello,
I'm currently having an issue with a new Splunk ITSI installation with entities not showing up in the service after KPI's are added. I recently completed the Implementing Splunk ITSI class they offer and set everything up according to how we did it in that class. Here's what I've gone through so far:
I've gone through all of the troubleshooting steps on the Splunk Wiki, verified that all of the Splunk for Linux/Unix options I need are enabled, sysstat is available on the servers, and so on. As far as I can see, everything looks correct. However, I cannot get past this issue and while I've reached out to Splunk Support on it they refuse to assist with even basic troubleshooting and want to charge me administrative fees. So, in my desperation I'm reaching out here to the community in the hope of getting some assistance with this issue.
Thanks in advance. If you need any other information please don't hesitate to let me know.
2 remarks : 348 seconds of indexing delay, this is not great. you want to be under a minute. Maybe your servers clocks are drifting ...
When you run the KPI searches do you get results, this will be a good test.
Are your KPIs linked to Shared bases searches (SBS)?
Do you use a split by entity, how many entities total would be indirectly linked to a single SBS ? (10000 is usually the cadinality limit by default)
Try to convert to a hadhoc KPI in a single service to compare.