Content Pack for ITSI Monitoring and Alerting

Content Pack for ITSI Monitoring and Alerting

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Enable or disable service monitoring for certain services and KPIs

Service Monitoring Correlation Searches can be disabled on a per-KPI and per-Service Health Score basis by setting the itsiInclude field in the itsi_kpi_attributes lookup file. The ITSI KPI Attributes Lookup Generator search, which creates a row for each KPI and Service Health Score, automatically generates and populates the itsiInclude column.

You can set the value of the itsiInclude column to either true or false depending on whether you want that Service or KPI to be included in the Service Monitoring Correlation Searches (using the value of true for inclusion). When a KPI or Service Health row in the lookup has itsiInclude set to false, the Service Monitoring Correlation Searches ignore that row. This functionality can be useful if you are using alternative methods of monitoring and alerting for certain Services and KPIs.

The ITSI KPI Attributes Lookup Generator search defaults the itsiInclude field to either true or false depending on the following logic:

  • If the row is a KPI and the KPI name also exists in other Services, itsiInclude "inherits" the already configured itsiInclude value of the other KPIs if they are all set the same.
  • If the row is a KPI, itsiInclude "inherits" the already configured itsiInclude value of the Service Health Score row.
  • The itsiInclude value will be configured to whatever is specified in the service_monitoring_itsi_include_default macro.
Last modified on 29 August, 2022
PREVIOUS
Upgrade from a previous version of the Content Pack for ITSI Monitoring and Alerting to v2.2.0
  NEXT
Configure alerts in the Content Pack for ITSI Monitoring and Alerting

This documentation applies to the following versions of Content Pack for ITSI Monitoring and Alerting: 2.1.0, 2.2.0, 2.3.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters