Splunk® IT Service Intelligence

Modules

Splunk IT Service Intelligence (ITSI) version 4.11.x reached its End of Life on December 6, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see Before you upgrade IT Service Intelligence.
This documentation does not apply to the most recent version of Splunk® IT Service Intelligence. For documentation on the most recent version, go to the latest release.

Load Balancer Module data model reference table

Use the below tables as a reference for the data models of this module. The tables contain a breakdown of the required tags for the event objects or searches in that model, and a listing of all extracted and calculated fields included in the model. Data models can be edited by navigating to Settings > Data models

For information on how to map your data to the data models available in the Splunk IT Service Intelligence Modules, see the below links:

Tags used with event objects

The following tags act as constraints to identify your events as being relevant to this data model.

Object name Tag name
Inventory loadbalancer, inventory
Performance loadbalancer, performance
|____ Platform
cpu OR memory OR storage
|____ Statistics
statistics
|____ Connections
network

Fields for Load Balancer event objects

The following table lists the extracted and calculated fields for the event objects in the model. Note that it does not include any inherited fields.

Object name Field name Data type Description
Inventory chassis string The type of hardware employed by the ITSI LB user.
Inventory cpu_count number The number of CPUs reported by the resource.
Inventory cpu_mhz number The maximum speed of the CPU reported by the resource (in megahertz).
Inventory mem number The total amount of memory installed in or allocated to the resource, in megabytes.
Inventory protocol_version string The version of the inventory protocol.
Inventory storage number The amount of storage capacity allocated to the resource, in megabytes.
Inventory vendor string The vendor name of the resource.
Inventory vendor_product string The vendor and product name of the resource
Inventory version string The version of a computer resource, such as 3.0.0.
Inventory role string Static field added by the Splunk platform to link the loadbalancer data model to loadbalancer KPIs.
Performance role string Static field added by the Splunk platform to link the loadbalancer data model to loadbalancer KPIs.
Platform cpu_load_percent number The percentage of cpu load being used.
Platform storage_used_percent number The percentage of storage being used.
Platform mem_used_percent number The percentage of memory being used.
Statistics failover_status number Load Balancer failover status
Statistics avl_status number AVL status information
Connections 5XX_codes number Count of 5XX response codes.
Connections interface_connections number Connections returned from servers to the load balancer.
Connections interface_throughput number Throughput returned from servers to the load balancer.
Connections rtt number Round trip times
Connections sessions number Number of sessions connected to the load balancer at the time collected.
Connections ssl_tps number Number of SSL transactions per Second.
Connections vip_connections number Virtual IP connections returned from servers to the load balancer.
Connections vip_throughput number Virtual IP throughput returned from servers to the load balancer.
Last modified on 28 April, 2023
Load Balancer module entities   Load Balancer module troubleshooting

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.11.0, 4.11.1, 4.11.2, 4.11.3, 4.11.4, 4.11.5, 4.11.6, 4.12.0 Cloud only, 4.12.1 Cloud only, 4.12.2 Cloud only, 4.13.0, 4.13.1, 4.13.2, 4.13.3, 4.14.0 Cloud only, 4.14.1 Cloud only, 4.14.2 Cloud only, 4.15.0, 4.15.1, 4.15.2, 4.15.3, 4.16.0 Cloud only, 4.17.0, 4.17.1, 4.18.0, 4.18.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters