Analyze entity performance metrics in ITSI
Analyze performance metrics for a single entity on the entity's Analytics dashboard within IT Service Intelligence (ITSI). Determine poor performing entities for a set of metrics, or determine a point in time when multiple entities began performing in a similar way. Use the visualizations to perform root cause analysis and understand why your infrastructure is performing the way it is. The insights can help you quickly identify and respond to issues or anomalies in your data.
You can select different data sources to create interactive charts. Then apply filters and aggregations to gain insight into your system's metrics and performance. The following image shows an entity's Analytics view:
Access the Analytics dashboard
Follow these steps to access the Analytics dashboard for an entity:
- From the ITSI main menu, click Infrastructure Overview.
- Find and open the entity you want to analyze, filtering by dimensions if needed.
- Select the Analytics tab for the entity.
The entity Analytics view leverages the Splunk Analytics Workspace, which provides a user interface to monitor and analyze metrics and other time series without using SPL. The workspace comes with a set of analytic functions and operations to help you make sense of your data. For more information about the Analytics Workspace, see About the Analytics Workspace in the Splunk Enterprise Analytics Workspace manual.
See the following resources to perform different tasks within the Analytics Workspace:
|Charts in the Analytics Workspace||Create charts to see your data represented as a time series.|
|Time range in the Analytics Workspace||Set the workspace time range and zoom in to a custom time range.|
|Analytics in the Analytics Workspace||Configure analytic functions and operations to gain insight from your charts.|
|Dashboards in the Analytics Workspace||Use dashboards to monitor real-time trends in your data or to share visualizations with your colleagues.|
Entity Analytics and alerting
While the Analytics dashboard doesn't contain the entity alerting functionality that the Splunk Analytics Workspace provides, you can still set up alerts for KPIs so you receive a notification when a KPI reaches a certain threshold. For more information, see Receive alerts when KPI severity changes in ITSI in the Service Insights manual.
Overview of the Infrastructure Overview in ITSI
View log events for entities in ITSI
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.7.0, 4.7.1, 4.7.2, 4.7.3, 4.7.4