Splunk® IT Service Intelligence

User Manual

Acrobat logo Download manual as PDF

Splunk IT Service Intelligence version 4.5.x will no longer be supported as of April 29, 2022. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see Before you upgrade IT Service Intelligence.
This documentation does not apply to the most recent version of Splunk® IT Service Intelligence. Click here for the latest version.
Acrobat logo Download topic as PDF

Investigate entity metrics and logs in the ITSI Entity Analysis Dashboard

The Splunk IT Service Intelligence (ITSI) Entity Analysis Dashboard helps you analyze metrics and logs for specific entities. The Entity Analysis Dashboard populates with metrics and logs according to analysis data filters ITSI associates with a given entity. Drill down into events associated with the entity to view each one as a time-series chart. The dashboard gives you an entity-level overview of the performance of your services.

For more information about how ITSI visualizes entity data, see How ITSI visualizes entity data in the Entity Integrations Manual. To manage the data sources you can view for an entity type in the Entity Analysis Dashboard, see Configure entity types to define entity data sources and visualizations in ITSI in the Entity Integrations Manual.

ITSI powers the Entity Analysis Dashboard with the Splunk Metrics Workspace. While the Entity Analysis Dashboard doesn't contain entity alerting functionality the Splunk Metrics Workspace provides, you can set up alerts for KPIs so you receive a notification when a KPI reaches a certain threshold. ITSI generates notable events based on alerting rules you configure for KPIs, allowing you to monitor entities in a service before they affect the related service as a whole. For more information about setting up alerts for KPIs, see Receive alerts when KPI severity changes in ITSI in the Administration

For more information about using the Splunk Metrics Workspace, see About the Splunk Metrics Workspace in the Using the Splunk Metrics Workspace guide.

Find the Entity Analysis Dashboard for an entity

Follow these steps to access the Entity Analysis Dashboard.

  1. From the ITSI main menu, click Configuration > Entities.
  2. Find the entity you want to analyze. Use the basic or advanced filter to narrow down your search, if needed. When you find the entity you want to analyze, click View Health under the Health Column of the entities lister page.
  3. Select the Analysis tab for the entity.
Last modified on 09 June, 2020
Analyze every recent log event for an entity in the ITSI Event Data Search Dashboard

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.5.0 Cloud only, 4.5.1 Cloud only

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters