Splunk ITSI

Splunk ITSI : How to configure CPU and Memory Utilization and disk usage KPI's?

Dinesh_Raja
Path Finder

I m new to ITSI, I would like to configure CPU & Memory Utilization, Disk usage KPI's on ITSI. Kindly let me know the steps from scratch/document which will help to achieve the same.

Thanks.

0 Karma
1 Solution

skoelpin
SplunkTrust
SplunkTrust

You should try to use the least amount of searches as possible to get the values, you can use base searches to achieve this. If you're new to ITSI then perhaps you should experiment with adhoc searches first sense they are easier and will give faster time to value. First you create a new service Configure > Services then you need to create the 3 KPI's to that service. You need the searches for this. Then you can set thresholds.

View solution in original post

skoelpin
SplunkTrust
SplunkTrust

You should try to use the least amount of searches as possible to get the values, you can use base searches to achieve this. If you're new to ITSI then perhaps you should experiment with adhoc searches first sense they are easier and will give faster time to value. First you create a new service Configure > Services then you need to create the 3 KPI's to that service. You need the searches for this. Then you can set thresholds.

Dinesh_Raja
Path Finder

Thank you @skoelpin , it really helps.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Glad to help. Did this answer your question? If so can you accept it to close it out? If not then feel free to ask additional questions and Id be happy to help

0 Karma

sapanda
Path Finder

hello @skoelpin ,

I also have the same situation.

I have configured a new service( Name : Test Service) and associated a Windows and a Linux CI as entities to the same. Then I created 2 KPIs( CPU for Windows and Memory for Linux) using Ad hoc searches. But after then when i check the Service Analyzer , I am expecting to see my service in the same, but I am not able to see it. Any suggestions?

Thanks,
Sapan

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Open a new question and I will answer it

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...