Splunk ITSI

Unable to get service analyzer ITSI VERSION 2

naidusadanala
Communicator

Hi ,

I have created KPI'S IN ITSI and have them tested working fine.
Glass tables are displaying count perfectly but the service analyzer unable to display the top 50 services and KPI's i.e., unable to view the service page though I have configured services and KPI related to it.

Some one help me out ... ITSI becoming night mare it seems

appache
Path Finder

Hi, i had the same issue long time ago, so what we did is i have enabled real-time searches in the back end since ITSI is purely works based on Real Time. it should work it worked fine for me. and make sure you have enough cores for ITSI to run.
it shouldnt be an issue after you enable the real-time in your on your search head

0 Karma

sroback_splunk
Splunk Employee
Splunk Employee

You might also try reducing the total number of "every one minute" interval KPI searches that you are running (if you are running a lot). Too many 1 min. searches can have a negative impact on performance. Running KPIs at 5 min. or 15 min. intervals is enough in many cases.

Also, make sure that you have adequate hardware resources (beyond the baseline Splunk reference hardware required for Splunk Enterprise). ITSI is resource intensive and can require additional hardware.

For more info and some tips on ITSI performance, see: Performance considerations in the Installation and Configuration manual.

ChrisG
Splunk Employee
Splunk Employee

Try reducing the number of tiles to see if you get results. They are powered by real-time searches, and if you have too many tiles, the searches that power them might hang.

See the troubleshooting information in the Installation and Configuration Manual.

0 Karma

naidusadanala
Communicator

Its not going well though , I have only 3 tiles

0 Karma

mattymo
Splunk Employee
Splunk Employee

has it ever worked?

- MattyMo
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...