Splunk ITSI

Splunk IT Service Intelligence: Is using inputlookup as a base search for KPI appropriate?

TheJagoff
Communicator

Hello,

I am attempting to use a CSV file as an inputlookup as a base search in Splunk IT Service Intelligence (ITSI). The search runs fine in the Base Search Editor:

|inputlookup lookup_assets.csv |fields public_table

and I get around 100 returns such as:

public_table
Asset1
Asset2
Asset3
...
Asset93

For the next step: I go to add the public_table as a metric for a distinct count, but I don't get any results when I attempt to set the thresholds.

Question - is using an inputlookup table in this manner valid? If so, what am I doing incorrectly?

Many thanks.

0 Karma
1 Solution

TheJagoff
Communicator

I will answer my own question...
The following will actually work as a search for a KPI...

|inputlookup lookup_assets.csv |stats dc(public_table) AS CriticalApps| eval _time = now()

But - after getting some more information from the client; this is not an efficient method for a KPI that will be executed every 5 minutes. This input lookup table is used for further calculations for a KPI that gathers more information so the best way to display this information is as an adhoc widget in a glass table.

So yes, it can be done - no it's not the best way of doing things if it is only going to be used for visual information via Glass Table in ITSI.

View solution in original post

0 Karma

TheJagoff
Communicator

I will answer my own question...
The following will actually work as a search for a KPI...

|inputlookup lookup_assets.csv |stats dc(public_table) AS CriticalApps| eval _time = now()

But - after getting some more information from the client; this is not an efficient method for a KPI that will be executed every 5 minutes. This input lookup table is used for further calculations for a KPI that gathers more information so the best way to display this information is as an adhoc widget in a glass table.

So yes, it can be done - no it's not the best way of doing things if it is only going to be used for visual information via Glass Table in ITSI.

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...