![]() ![]() Backfill service KPIs: Optionally backfill your ITSI environment with the previous seven days of KPI data.This option can help you locate and manage the objects after installation. ![]() For example, you might prefix your objects with CP- to indicate they came from a content pack. Add a prefix to your new objects: Optionally, append a custom prefix to each object installed from the content pack.All other objects such as KPI base searches and saved searches are installed in their original state regardless of the option you choose. This setting only applies to services, correlation searches, and aggregation policies. We recommend that you import objects as disabled to ensure your environment doesn't break from the addition of new content. Import as enabled: Select whether to install objects as enabled or leave them in their original state.Any changes you previously made to these objects are overwritten. Replace existing: Existing identical objects are replaced with those from the new installation.Install as new: Any existing identical objects in your environment remain intact.Choose a conflict resolution rule for the objects you install: For upgrades or subsequent installs, decide what happens to duplicate objects introduced from the content pack.You can selectively choose which objects to install from the new version or install all objects. For an upgrade, the installer identifies which objects from the content pack are new and which ones already exist in your environment from a previous installation. Choose which objects to install: For a first-time installation, select the items you want to install and deselect any you're not interested in.Review what's included in the content pack and then click Proceed.Select the ITSI Monitoring and Alerting content pack.Select Add content packs or Add structure to your data depending on your version of ITSI.From the ITSI main menu, click Configuration > Data Integrations.Install the content pack on ITSI v4.9.0 or laterįollow these steps to install the Content Pack for ITSI Monitoring and Alerting from the Data Integrations page on ITSI v4.9.0 or later: ![]() If you are using ITSI version 4.8.x or earlier, you install the content pack using backup and restore functionality provided by ITSI, see Install the content pack in ITSI v4.8 or earlier. The Content Pack for ITSI Monitoring and Alerting is automatically available for installation once you have installed the Splunk App for Content Packs on the search head with ITSI 4.9.0 or later. If you use the dashboards within this Content Pack, this visualization is recommended. The ITSI Alert and Episode Field Values Analysis dashboard within the Content Pack uses the Wordcloud visualization to better visualize concentrations of related alerts. The ITSI Alert and Episode Field Values Analysis dashboard within the Content Pack uses the Treemap visualization to better visualize concentrations of related alerts. The ITSI Alert and Episode Field Values Analysis dashboard within the Content Pack uses the Circlepack visualization to better visualize concentrations of related alerts. Several dashboards within the Content Pack depend on the punchcard visualization to better visualize concentrations of data over hours of the day or days of the week. After installing this app, you must immediately restart Splunk software. The Lookup File Editor lets you create and maintain this information in your ITSI environment. The files enrich notable events with the information necessary to group related events, drive alert actions, and engage the correct stakeholders. The Content Pack for ITSI Monitoring and Alerting uses several new lookup files. It's a best practice to install each of the following apps: While not required, this content pack leverages several Splunkbase apps to help you manage and visualize alerting data. (Optional) Install third-party apps from Splunkbase
0 Comments
Leave a Reply. |
Details
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |