Splunk ITSI

Unable to find kpi_value in itsi_summary index

krutika_ag
Path Finder

Hello,

 

I want to create a dataset for Machine Learning,

I want kpi name and Service Health Score as field name and their value as value for last 14 days,

how do i retrieve kpi_value and health_score value, is it stored somewhere in itsi index?

I cannot find kpi_value field in index=itsi_summary

#predictive analaytics #machine learning, splunk it


#predictive analytic 
Splunk Machine Learning Toolkit 
#Splunk ITSI

Also, if you have done Machine Learning / Predictive ANalytics in your environment, please suggest a approach 

Labels (1)
Tags (1)
0 Karma

proyleJDS
Path Finder

Are you looking for something like this?

 

index=itsi_summary 
| eval kpiid = mvappend(kpiid, itsi_kpi_id) 
| stats latest(alert_value) as alert_value latest(alert_severity) as health_score by kpiid kpi 
| join type=left kpiid 
    [| inputlookup service_kpi_lookup 
| stats latest(title) as title by kpis._key 
    | rename kpis._key as kpiid
        ] 
| search title IN ("<Service Names>") kpi!="ServiceHealthScore"

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...