Splunk ITSI

Why ITSI Content Pack only show limited KPI in each Service ?

rendi7936
New Member

I was trying to test IT Shared content pack, downloaded, restored,
We see glass table deployed, services deployed, but when we look at one of service, such as NTP.

There is no preconfigured base search(es) KPI, only one: Heartbeat,

is this expected? do we miss something ?

If we deploy content pack Monitoring Unix and Linux,
we see preconfigured base search with many KPIs, and we see it looks like it has correct base search,

alt text

alt text

Labels (2)
0 Karma

esnyder_splunk
Splunk Employee
Splunk Employee

Hi Rendi, yes this is intended. The content is supposed to be a starting point for IT infrastructure monitoring, not necessarily the entire solution. It's intended to give users an idea of how to set up their environment, how to structure dependencies, etc. 

The hope is that customers will install it, and then do their own configuration of services and alerts. If you look at the post-install documentation for the content pack you'll see this elaborated on a bit more. 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...