I'm using Splunk IT Service Intelligence and this search:
(index=mtparam mtparam=Fabwide:NON-DELETABLE sourcetype=Realtime30MinPaceByArea) OR sourcetype=*RUN_count* | stats max(RUN_COUNT) as RUNCOUNT, max(Value) as PACE | eval Delta=(PACE - RUNCOUNT)
Using the Splunk search app, I see values for the three, but using ITSI, and what I believe to be the proper threshold field **Delta**, I am receiving no data in the threshold section. Am I doing something incorrectly?
↧