Splunk ITSI

Splunk IT Service Intelligence 2.4.1: How to add pre-built Virtualization Module KPIs?

wcooper003
Communicator

We just upgraded Splunk IT Service Intelligence from 2.2.0 to 2.4.1 and want to add in pre-built KPIs for VMWare. Our VMWare is collecting the data - the verification search is populated ( index=vmware* tag=virtualization).

However, when we create a new service or try to add KPIs to an existing service, there aren't any pre-built KPIs available to add in from the lists. Is there a trick to add in the Virtualization Module KPIs?

0 Karma
1 Solution

wcooper003
Communicator

Figured this out on my own - the DA-ITSI-VIRTUALIZATION add-on is Disabled by default. So after I enabled it the KPIs are populating.

That little tidbit is either missing from the Virtualization Module documentation, else I accidentally skipped over it the couple of times I read through.

View solution in original post

0 Karma

Jarohnimo
Builder

Did you have to tag all of your servers "virtualization" and if so how did you know to tag them that? Can you provide a link for the initial setup, I've been looking but cannot find.

I suspect the reason mine isn't working is because I haven't tagged my server with the predefined ITSI tags but I cannot find any documentation anywhere that explains how to setup ITSI with it's tags for non generic search.

0 Karma

wcooper003
Communicator

No we didn't tag anything - i'm guessing the DA-ITSI-VIRTUALIZATION add-on does that for you. We just had to enable it, it was disabled by default.

0 Karma

wcooper003
Communicator

Figured this out on my own - the DA-ITSI-VIRTUALIZATION add-on is Disabled by default. So after I enabled it the KPIs are populating.

That little tidbit is either missing from the Virtualization Module documentation, else I accidentally skipped over it the couple of times I read through.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...