Splunk ITSI

Unable to get service analyzer ITSI VERSION 2

naidusadanala
Communicator

Hi ,

I have created KPI'S IN ITSI and have them tested working fine.
Glass tables are displaying count perfectly but the service analyzer unable to display the top 50 services and KPI's i.e., unable to view the service page though I have configured services and KPI related to it.

Some one help me out ... ITSI becoming night mare it seems

appache
Path Finder

Hi, i had the same issue long time ago, so what we did is i have enabled real-time searches in the back end since ITSI is purely works based on Real Time. it should work it worked fine for me. and make sure you have enough cores for ITSI to run.
it shouldnt be an issue after you enable the real-time in your on your search head

0 Karma

sroback_splunk
Splunk Employee
Splunk Employee

You might also try reducing the total number of "every one minute" interval KPI searches that you are running (if you are running a lot). Too many 1 min. searches can have a negative impact on performance. Running KPIs at 5 min. or 15 min. intervals is enough in many cases.

Also, make sure that you have adequate hardware resources (beyond the baseline Splunk reference hardware required for Splunk Enterprise). ITSI is resource intensive and can require additional hardware.

For more info and some tips on ITSI performance, see: Performance considerations in the Installation and Configuration manual.

ChrisG
Splunk Employee
Splunk Employee

Try reducing the number of tiles to see if you get results. They are powered by real-time searches, and if you have too many tiles, the searches that power them might hang.

See the troubleshooting information in the Installation and Configuration Manual.

0 Karma

naidusadanala
Communicator

Its not going well though , I have only 3 tiles

0 Karma

mattymo
Splunk Employee
Splunk Employee

has it ever worked?

- MattyMo
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...