Splunk ITSI

Is it possible that Splunk cannot collect certain values even though others are being collected?

bas28
Loves-to-Learn Lots

Hello,

I have installed Splunk ITSI several times on various types of infrastructure, and I am observing this behavior for the first time. The latencies all have zero values as if they are not being reported. I have adjusted the collection interval, but it hasn't made any difference. What I don't understand is that this issue concerns latencies of virtual machines, ESXi servers, and datastores, while all other KPIs are okay. Is it possible that Splunk cannot collect certain values even though others are being collected? Do you have any idea about the root cause of this error? 

IT Service Intelligence
Version :
4.17.0

Splunk Enterprise
Version :
9.0.5

Capture d’écran 2023-09-20 152854.png

Labels (2)
Tags (1)
0 Karma

srauhala_splunk
Splunk Employee
Splunk Employee

HI @bas28!

"Is it possible that Splunk cannot collect certain values even though others are being collected?" No. In my experience it is aways something missing between the entity filtering per service,  entity definition in the KPI searches and or some issue with the field normalisation (metric) of the KPI base search. 

Double check that those things are alright. Last thing to check could be ingest delay and that data is arriving in time for the KPI search to pick it up. 

/Seb 

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...