Splunk ITSI

Why ITSI Content Pack only show limited KPI in each Service ?

rendi7936
New Member

I was trying to test IT Shared content pack, downloaded, restored,
We see glass table deployed, services deployed, but when we look at one of service, such as NTP.

There is no preconfigured base search(es) KPI, only one: Heartbeat,

is this expected? do we miss something ?

If we deploy content pack Monitoring Unix and Linux,
we see preconfigured base search with many KPIs, and we see it looks like it has correct base search,

alt text

alt text

Labels (2)
0 Karma

esnyder_splunk
Splunk Employee
Splunk Employee

Hi Rendi, yes this is intended. The content is supposed to be a starting point for IT infrastructure monitoring, not necessarily the entire solution. It's intended to give users an idea of how to set up their environment, how to structure dependencies, etc. 

The hope is that customers will install it, and then do their own configuration of services and alerts. If you look at the post-install documentation for the content pack you'll see this elaborated on a bit more. 

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...