For more information, see Understand entity status and search data in ITSI. You can now use this page to troubleshoot issues with discovery searches, better understand why entities display an inactive or unstable status, and view remediation steps. The Entity Discovery Searches page allows you to gain visibility into the searches that discover your entities and contribute to the entity status calculation. Infrastructure Overview New feature or enhancementĮntity status remediation and root-cause analysis You must incorporate the lookup command into your own SPL queries to obtain the service_name field. Lookup service_kpi_lookup _key AS serviceid OUTPUT title AS service_nameīy executing this SPL command, you can retrieve the service_name from the service_kpi_lookup file. To obtain the service_name for a given serviceid, use the following SPL (Search Processing Language) lookup command: If you rely on the service_name field, this change affects you. This change to service name field mapping protocol in Service and Episode Monitoring Correlation Searches improves data reliability by eliminating the previous requirement for refreshing automatic lookup periodically to ensure that the service_name field populated for all records in the itsi_summary index. Mapping for the service_name field in the itsi_summary index is now driven by SPL command rather than by automatic lookup from the content pack for ITSI Monitoring and AlertingĪutomatic lookup responsible for returning the service_name field for the itsi_summary index is removed when users upgrade to Splunk App for Content Packs 2.0.0. If you're upgrading from a previous version of the Splunk App for Content Packs, be sure to go through the important steps mentioned in Upgrade Splunk App for Content Packs to version 2.0. Saved searches are deactivated by default on upgrade and install of Splunk App for Content Packs 2.0 to avoid negative impact on ITSI performance and to provide more control for users to enable saved searches only for in-use content packs To activate the saved searches, refer to the Install and Configure documentation of the required content pack. This version has these new and changed features.ĭata Integrations New feature or enhancementĭeactivated the saved searches of all content packs New features in Splunk IT Service Intelligence
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |