Splunk ITSI

Why is my Splunk IT Service Intelligence (ITSI) service health score not being reflected correctly?

EricLloyd79
Builder

If I understand correctly, a Service Health Score is an aggregation of all the KPI health scores in that service.

As you can see in the screenshot, something is off with my Service Health Score. It seems to be down despite all the other KPI health scores being in the green range.

Has anyone else experienced this before?

Note, I did create a new KPI around this time. Does that cause a dip in Service Health Score?
Thanks.

alt text

1 Solution

skoelpin
SplunkTrust
SplunkTrust

Do you have any dependent services which would affect the ServiceHealthScore? What's your timerange set to? Have you tried changing from average to max?

View solution in original post

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Do you have any dependent services which would affect the ServiceHealthScore? What's your timerange set to? Have you tried changing from average to max?

0 Karma

EricLloyd79
Builder

I do not have any dependent services.
My time range is set to 12 hours.
I have tried changing from average to max and I do see some variation in the other KPIs now that would possibly affect the health score.
I guess I misunderstand the concept behind the change between Average and Max. Arent the values displayed in the Sparklines of the KPIs the actual values specified in the metrics when the service is created? What is Max, the max of for a particular point in time for a kpi if we already specified what value we are seeking when we create the KPI?
Thanks for clarity.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Try reducing the timerange to one hour. Sometimes the affected KPI's will show themselves which is driving down the ServiceHealthScore value.

As for Average, Min, and Max.. The timerange has multiple values and as you expand out the timerange, your expanding out to multiple values

0 Karma

EricLloyd79
Builder

Thanks skoelpin. You can to the rescue again.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...