Splunk ITSI

How to Create sub Services in Splunk ITSI

nasrinmulani
New Member

Hi All,

I need to know how to create sub services, for example "Laptop" will be main service and then "Laptop-CPU" "Laptop-Performance" , these will be sub services under "Laptop" Service.
When we will drag and drop the service health of Laptop service on Glass table then we should get the overall health of all the services.

Anyone knows about how to create sub service, please let me know.

Thanks in Advance!!

0 Karma
1 Solution

PowerPacked
Builder

Hi @nasrinmulani

In the above case, Laptop-CPU & Laptop-Performance should be considered as entities of Laptop.

in either bulk import or single creation, you will have option of service dependency tree. from where you can configure whih entities are treated as sub services under main service.

& coming to service health of main service always depends on service health of sub services.

------ service health score of sub services are considered as kpis of importance of 11 in main service. ---- if any of the sub services fails the main service automatically turns into critical.

Have a look at these docs.
https://docs.splunk.com/Documentation/ITSI/3.1.1/Configure/Addservicedependencies

Thanks

View solution in original post

0 Karma

nasrinmulani
New Member

Thanks you!!

It's really helpful

0 Karma

PowerPacked
Builder

Hi @nasrinmulani

In the above case, Laptop-CPU & Laptop-Performance should be considered as entities of Laptop.

in either bulk import or single creation, you will have option of service dependency tree. from where you can configure whih entities are treated as sub services under main service.

& coming to service health of main service always depends on service health of sub services.

------ service health score of sub services are considered as kpis of importance of 11 in main service. ---- if any of the sub services fails the main service automatically turns into critical.

Have a look at these docs.
https://docs.splunk.com/Documentation/ITSI/3.1.1/Configure/Addservicedependencies

Thanks

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...