Hello,
I want to create a dataset for Machine Learning,
I want kpi name and Service Health Score as field name and their value as value for last 14 days,
how do i retrieve kpi_value and health_score value, is it stored somewhere in itsi index?
I cannot find kpi_value field in index=itsi_summary
#predictive analaytics #machine learning, splunk it
#predictive analytic
Splunk Machine Learning Toolkit
#Splunk ITSI
Also, if you have done Machine Learning / Predictive ANalytics in your environment, please suggest a approach
Are you looking for something like this?
index=itsi_summary
| eval kpiid = mvappend(kpiid, itsi_kpi_id)
| stats latest(alert_value) as alert_value latest(alert_severity) as health_score by kpiid kpi
| join type=left kpiid
[| inputlookup service_kpi_lookup
| stats latest(title) as title by kpis._key
| rename kpis._key as kpiid
]
| search title IN ("<Service Names>") kpi!="ServiceHealthScore"