Splunk ITSI

ITSI : Services are not DISPLAYED (- No results found) and Health score not CALCULATED

sunilpanda023
Path Finder

Hi,
I am having ITSI 4_1_1.
and have Configure multiple ITSI deployments to use the same indexing layer.
https://docs.splunk.com/Documentation/ITSI/4.1.1/Configure/DeploymentPlanning

Initially, I had not enabled backfill on KPIs , the services row in the service analyzer was empty. After enabling backfill at service level the service started appearing. that meant enabling backfill populated kpiid=SHKPI-XXX and with attribute is_backfilled_event=1.
backfill at service level is newly introduced in 4_1_1
https://docs.splunk.com/Documentation/ITSI/4.1.1/Configure/BackfillSHS

What I understand in general is that servicehealth scores should be computed, why its not computed in 4_1_1 which should be of attribute is_backfilled_event=0.

And the behavior of not displaying any services (- No results found) and Health scores ( kpiid=SHKPI-XXX) not computed to summary indexes even for one working before suddenly without any clues in internal logs is worrisome.

Thanks,
Sunil Panda

0 Karma
1 Solution

sunilpanda023
Path Finder

enable the service_health_monitor (report/savedsearch), service health scores should start getting calculate.

View solution in original post

0 Karma

sunilpanda023
Path Finder

enable the service_health_monitor (report/savedsearch), service health scores should start getting calculate.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...