Splunk® IT Service Intelligence

Service Insights Manual

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Update a service template in ITSI

When you update a service template in IT Service Intelligence (ITSI), it updates all services linked to the template. You can choose to push updates immediately or schedule a specific date and time to push the updates. For more information about service templates, see Overview of service templates in ITSI.

Prerequisite

You must have the write_itsi_base_service_template capability and write access to the Global team to update a service template. Users with the itoa_admin role have this capability by default.

Steps

  1. From the ITSI main menu, click Configuration > Service Templates.
  2. Open a service template.
  3. Modify the service template settings on the following tabs:
    Tab Description
    Entities Add, modify, or delete entity rules.


    Optionally, use the following options to specify the value of of an entity in each service rather than in the template:

    • matches a value to be defined in the service
    • does not match a value to be defined in the service

    These settings are useful if each service linked to the template monitors different entities.

    If you use the configurable entity rules described above and choose Overwrite Entity Rules when you save the service template, any entity rules already defined in the linked services are replaced with the entity rules from the template and have blank values (matching all entities).

    KPIs Add, modify, or delete the template's KPIs. Any KPIs you add to the template must use a base search. Template KPIs cannot use ad hoc, metrics, or data model searches. You can't enable anomaly detection within a service template. You must enable anomaly detection for a KPI directly within the individual service.
    Settings Set importance values for the KPIs and see how they affect the health score of linked services.
  4. When you finish making modifications to the service template, click Save.
  5. Indicate what information to update and select when to push the changes to the linked services.
    Setting Description
    Overwrite entity rules Replaces the entity rules in the linked services with the entity rules in the template.
    Overwrite KPI thresholds and alerting rules on How to update KPI thresholds and KPI alerting rules in linked services.
    • Select All KPIs to overwrite all KPIs in all linked services, including any that you've customized since you last saved the template.
    • Select All Unchanged KPIs if you customized some of the KPI thresholds or alerting rules in the linked services and you don't want to override those changes.
    • Select No KPIs if you don't want to update any KPIs in the linked services.

    This setting doesn't affect thresholds or alerting rules for KPIs that are unique to a service and not linked to the template.

    Overwrite health score calculation Replaces the KPI importance values used to calculate the health score in the linked services with the values from the template. KPI importance values for any additional KPIs in the service that are not present in the template are not affected. Importance values for dependent services are also not affected.
    Push changes to services When to push the changes to the linked services. Either push the changes immediately, or select Later to choose a date and time to update the linked services. It is considered a best practice to push changes outside of regular business hours to avoid disruption.
  6. Click Save. The changes in the template are immediately propagated to the linked services if you chose to push the changes now, or scheduled for the date and time you selected.
  7. Click the Linked Services tab to see the sync status of the services linked to the template.

After the linked services are synced with the template, the status says "Synced". If you elected to push the changes now, you might need to refresh your browser to see the status change. You will also receive a message in Splunk Web with the status of the sync.

Service template syncs

You can only schedule one sync for a service template at a time. If you make additional updates to a template that's already scheduled for a sync, you can keep the scheduled time or choose to sync now or at a different time. All updates to the template are pushed at the time you choose. If the sync is scheduled for Now, it should only take several seconds before you see Sync in progress The total time of the sync depends on environment-specific factors such as the number of services and KPIs.

You can find out when a service template is scheduled to sync by checking the services lister page for the synced services that will be updated, or the service template lister page. If you need to force a service template sync, just make a dummy change to the template and push the changes. If the status says Pending it means the refresh queue is backed up.

The following cases are common causes of service templates not syncing properly:

  • The sync is scheduled for a later time
  • The sync is scheduled for a time in the past
  • There are conflicts or mismatches in linked services
  • A migration or restore is in effect

To check the logs for errors, you can run the following search:

index=_internal error "*sync failed*"

Last modified on 25 February, 2021
PREVIOUS
Link and unlink services from service templates in ITSI
  NEXT
Overview of Predictive Analytics in ITSI

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.5.0 Cloud only, 4.5.1 Cloud only, 4.6.0 Cloud only, 4.6.1 Cloud only, 4.6.2 Cloud only, 4.7.0, 4.7.1, 4.7.2, 4.8.0 Cloud only, 4.8.1 Cloud only, 4.9.0, 4.9.1, 4.9.2, 4.9.3, 4.9.4, 4.10.0 Cloud only, 4.10.1 Cloud only, 4.10.2 Cloud only


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters