Fritz is looking at a Deep Dive with a lane showing the average percent of CPU usage across the four web servers in the web farm. Seeing a spike, he wants to add the graphs of each server on the swim lane, and selects the Lane Overlay Options to do so. No entity overlays are available for the KPI.
What is wrong with his KPI configuration?
In Splunk ITSI, swim lane overlays depend on a KPI being split by entity so that each entity's individual time series can be displayed separately in the Deep Dive view. When a KPI is aggregated without an entity split, it produces a single time series value at each timestamp representing the entire group (in this case, the average CPU across all web servers). Because that KPI does not contain per entity values, ITSI has nothing to overlay --- therefore no entity overlays appear in the Lane Overlay Options. This configuration mistake often happens when a KPI is defined to average values across sources without specifying an entity dimension on which to split results. Entity filtering is a separate feature that enables restricting which entities are considered in display or analytics and does not control availability of swim lane overlays; pseudo entities are artificial names that do not reflect actual system identities and are not relevant to this error; and having only three entities versus four would not prevent overlays from appearing if the KPI were correctly split by entity. The correct fix is to edit the KPI definition and configure it to split the metric results by the server entity field, such that each server has its own time series. This then enables Fritz to overlay the individual server CPU graphs on the swim lane as intended.
Which option best are the default ports that must be configured on Splunk to use ITSI?
C is the correct answer because ITSI uses the default ports of Splunk Enterprise for its communication and data collection. SplunkWeb uses port 8000, SplunkD uses port 8089, and HTTP Event Collector uses port 8088. These ports can be changed if needed, but they must match the configuration of Splunk Enterprise. Reference:Ports used by ITSI
When in maintenance mode, which of the following is accurate?
A is the correct answer because when in maintenance mode, KPIs and notable events will begin to be generated again once the window is over. Maintenance mode is a feature of ITSI that allows you to temporarily suspend alerts and health score calculations for a service or an entity during planned maintenance or downtime. During maintenance mode, KPI searches still run, but the results are buffered until the window is over. Once the window is over, the buffered results are processed and alerts and health scores are generated if necessary. Reference: [Overview of maintenance windows in ITSI]
Which of the following describes default deep dives?
In Splunk IT Service Intelligence (ITSI), default deep dives are auto-generated and can be accessed via the Service Analyzer. Deep dives are an essential feature of ITSI that provide an in-depth, granular view into the health and performance of services and their associated KPIs. These default deep dives are automatically created for each service, allowing users to quickly drill down into the detailed operational metrics and performance data of their services. By accessing these deep dives through the Service Analyzer, ITSI users can efficiently investigate issues, understand service dependencies, and make informed decisions to maintain optimal service health. The auto-generated nature of these default deep dives simplifies the monitoring and analysis process, providing immediate insights into service performance without the need for manual setup or configuration.
After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?
By default, notable event metadata is archived after six months to keep the KV store from growing too large.
Michael
6 days agoRomana
13 days agoAnnmarie
21 days agoLezlie
28 days agoCarrol
1 month agoLennie
1 month agoHolley
2 months agoTuyet
2 months agoStefan
2 months agoDaren
2 months agoTeresita
3 months agoHuey
3 months agoAmie
3 months agoDerick
3 months agoDanilo
4 months agoCharlene
4 months agoJoanna
4 months agoRozella
4 months agoParis
5 months agoMarion
5 months agoFatima
5 months agoDona
5 months agoJosefa
6 months agoLai
6 months agoMalcolm
6 months agoJunita
6 months agoStanford
8 months agoRomana
9 months agoHoward
11 months agoLoreta
12 months agoDalene
1 year agoVeronika
1 year agoLemuel
1 year agoCrista
1 year agoRoxanne
1 year agoKing
1 year agoMoon
1 year agoLouis
1 year agoHorace
1 year agoJose
1 year agoDudley
1 year agoBong
1 year agoNicolette
1 year agoValda
1 year agoNorah
1 year agoMatthew
1 year agoKirk
2 years agoFlo
2 years agoSherell
2 years agoSena
2 years agoStephania
2 years agoLenna
2 years agoArlene
2 years agoMaricela
2 years agoYaeko
2 years agoLatrice
2 years ago