Splunk ITSI

Splunk ITSI : How to configure CPU and Memory Utilization and disk usage KPI's?

Dinesh_Raja
Path Finder

I m new to ITSI, I would like to configure CPU & Memory Utilization, Disk usage KPI's on ITSI. Kindly let me know the steps from scratch/document which will help to achieve the same.

Thanks.

0 Karma
1 Solution

skoelpin
SplunkTrust
SplunkTrust

You should try to use the least amount of searches as possible to get the values, you can use base searches to achieve this. If you're new to ITSI then perhaps you should experiment with adhoc searches first sense they are easier and will give faster time to value. First you create a new service Configure > Services then you need to create the 3 KPI's to that service. You need the searches for this. Then you can set thresholds.

View solution in original post

skoelpin
SplunkTrust
SplunkTrust

You should try to use the least amount of searches as possible to get the values, you can use base searches to achieve this. If you're new to ITSI then perhaps you should experiment with adhoc searches first sense they are easier and will give faster time to value. First you create a new service Configure > Services then you need to create the 3 KPI's to that service. You need the searches for this. Then you can set thresholds.

Dinesh_Raja
Path Finder

Thank you @skoelpin , it really helps.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Glad to help. Did this answer your question? If so can you accept it to close it out? If not then feel free to ask additional questions and Id be happy to help

0 Karma

sapanda
Path Finder

hello @skoelpin ,

I also have the same situation.

I have configured a new service( Name : Test Service) and associated a Windows and a Linux CI as entities to the same. Then I created 2 KPIs( CPU for Windows and Memory for Linux) using Ad hoc searches. But after then when i check the Service Analyzer , I am expecting to see my service in the same, but I am not able to see it. Any suggestions?

Thanks,
Sapan

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Open a new question and I will answer it

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...