Content Pack for Splunk AppDynamics

Content Pack for Splunk AppDynamics

Configure the Content Pack for Splunk AppDynamics

Perform the following high-level steps to configure the Content Pack for Splunk AppDynamics:

  1. Ensure the content pack uses the correct index.
  2. Import Splunk AppDynamics applications as ITSI services.
  3. Publish Splunk AppDynamics services.
  4. Enable Splunk AppDynamics entity searches.
  5. Configure KPI thresholds.
  6. Configure KPI alerting.

Step 1: Ensure the content pack uses the correct index

The Content Pack for Splunk AppDynamics uses a search macro to ensure all searches use the same index. The search macro must be configured to use the same index that the Splunk Add-on for AppDynamics uses to ingest data.

When the Splunk Add-on for AppDynamics is installed on indexers, it automatically creates an events index named appdynamics. By default, both the Splunk Add-on for AppDynamics and Content Pack for Splunk AppDynamics are configured to use this index.

If you installed the Splunk Add-on for AppDynamics on your indexers and did not change the index configuration for the add-on, this step is optional.

Prerequisite

You must have the admin role to perform this step.

Steps

  1. (Optional) If you need to create an events index, see Create events indexes.
  2. Identify the index that the Splunk Add-on for AppDynamics uses:
    1. From the Splunk Enterprise main menu, select Apps, then select Splunk Add-on for AppDynamics.
    2. The Inputs tab is selected by default. In the table, use the Index column to identify the index used by the add-on.
  3. Update the content pack search macro to use the same index as the add-on:
    1. From the Splunk Enterprise main menu, select Settings, then Advanced Search.
    2. Select Search Macros.
    3. In the App drop-down menu, select Splunk AppDynamics (DA-ITSI-CP-APPDYNAMICS).
    4. Select itsi_cp_appdynamics_index. The default macro definition is index="appdynamics". In the Definition field, change the index value to the name of the index used by the Splunk Add-on for AppDynamics.
    5. Select Save.

Step 2: Import Splunk AppDynamics applications as ITSI services

Prerequisite

You must have the itoa_admin role to perform this step.

Steps

  1. From the ITSI main menu, select Dashboards, then Dashboards.
  2. In the Filter field, search for Splunk AppDynamics.
  3. Select Splunk AppDynamics Import Applications.
  4. Follow the on-screen instructions to import Splunk AppDynamics applications as ITSI services.

Step 3: Publish Splunk AppDynamics services

See Publish services from the sandbox.

Step 4: Enable Splunk AppDynamics entity searches

If you enabled entity saved searches when you installed the content pack, skip this step.

To enable entity searches:

  1. From the ITSI main menu, select Configuration, then Entity Management.
  2. Select Entity Discovery Searches.
  3. Search for Splunk AppDynamics.
  4. For each entity search that you want to enable:
    1. Select the entity search.
    2. For Search active?, toggle the selection to Yes.
    3. Select Save.

Step 5: Configure KPI thresholds

Some KPIs in this content pack have predetermined aggregate and per-entity thresholds configured. Review the KPIs in each service and configure the aggregate and per-entity threshold values to reasonable defaults based on your use case. For steps to configure KPI thresholds, see Configure KPI thresholds in ITSI.

To view the full list of the KPIs in this content pack, see View KPIs.

Step 6: Configure KPI alerting

Because acceptable application performance varies widely per use case, KPI alerting isn't enabled by default in this content pack. To receive alerts for KPIs when aggregate KPI threshold values change, see Receive alerts when KPI severity changes in ITSI. ITSI generates notable events on the Episode Review page based on the alerting rules you configure.

Next steps

After you configure the content pack, you can begin monitoring your Splunk AppDynamics services and entities. See Monitor Splunk AppDynamics services and Monitor Splunk AppDynamics entities.

Last modified on 25 February, 2025
Install the Content Pack for Splunk AppDynamics   Monitor Splunk AppDynamics services

This documentation applies to the following versions of Content Pack for Splunk AppDynamics: 1.0.0


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters