Splunk ITSI

Unable to drilldown to individual events in Splunk ITSI Deep Dive

lisheengoh
New Member

Hi, I am working on a deep dive view from ITSI.
I noticed that the splunk examples online allow you to click on any of the KPI swimlanes in the deep dive, and the events for that particular time will be appear below. See attached picture for reference.

alt text

However, i do not see the option to show the events whenever i click on any of the KPI swimlanes in my Deep Dive. Could somebody help to explain to me why? Perhaps my Splunk ITSI version an older one (im using ITSI version 3.1.0)?

Any help would be great. Thanks.

0 Karma

esnyder_splunk
Splunk Employee
Splunk Employee

You need to click Add Lane > Add Event Lane to add an event lane. There's no way to click on an individual KPI lane and have the event lane appear. Follow the docs here: https://docs.splunk.com/Documentation/ITSI/latest/User/Deepdiveswimlanes#Add_a_new_event_lane

lisheengoh
New Member

Looked at the documentation provided for ITSI, but it seems that they dont cover this topic.
https://docs.splunk.com/Documentation/ITSI/4.1.2/User/DeepDives

They make no mention of this particular feature to enable drilldowns in deep dives. Appreciate if anyone could shed some light on this. Thanks.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...