Splunk ITSI

Unable to find kpi_value in itsi_summary index

krutika_ag
Path Finder

Hello,

 

I want to create a dataset for Machine Learning,

I want kpi name and Service Health Score as field name and their value as value for last 14 days,

how do i retrieve kpi_value and health_score value, is it stored somewhere in itsi index?

I cannot find kpi_value field in index=itsi_summary

#predictive analaytics #machine learning, splunk it


#predictive analytic 
Splunk Machine Learning Toolkit 
#Splunk ITSI

Also, if you have done Machine Learning / Predictive ANalytics in your environment, please suggest a approach 

Labels (1)
Tags (1)
0 Karma

proyleJDS
Path Finder

Are you looking for something like this?

 

index=itsi_summary 
| eval kpiid = mvappend(kpiid, itsi_kpi_id) 
| stats latest(alert_value) as alert_value latest(alert_severity) as health_score by kpiid kpi 
| join type=left kpiid 
    [| inputlookup service_kpi_lookup 
| stats latest(title) as title by kpis._key 
    | rename kpis._key as kpiid
        ] 
| search title IN ("<Service Names>") kpi!="ServiceHealthScore"

 

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...