Define KPI unit and monitoring lag in ITSI

In this step of the KPI setup workflow, define an optional unit of measurement to display for the KPI within glass table visualizations and other dashboards in IT Service Intelligence (ITSI). Configure the monitoring lag to offset indexing lag and improve performance. For an overview of the entire KPI creation workflow, see Overview of creating KPIs in ITSI.

Unit

Define the unit of measurement to display in KPI visualizations within service analyzers, deep dive lanes, glass tables, and other dashboards in ITSI populated by the summary index. For example, depending on the statistic you're calculating, you could use GB, Mbps, secs, %, and so on. This setting is optional.

KPIUnit.png

Monitoring Lag

The monitoring lag time, in seconds, is used to offset the indexing lag. Monitoring lag is an estimate of the number of seconds it takes for new events to move from the source to the index. When indexing large quantities of data, an indexing lag can occur, which can cause performance issues. Delay the search time window to ensure that events are actually in the index before running the search.

Monitoringlag.png

If you're working with a new data source, click Determine Recommended Lag to sample a 60-minute time period and find out what the minimum, maximum, and recommended monitoring lag setting for your data source is. As a best practice, don't set the monitoring lag to less than 30 seconds.

If the recommended monitoring lag is greater than the KPI frequency, it means there's a difference between the the _time of the event and the _indextime when it was written to the indexing tier. For example, you might get a recommended monitoring lag of 350 seconds while the KPI runs every 5 minutes, or 300 seconds. If this difference is large, KPI calculations might be off because the underlying data for that time period might not have been indexed yet. It's best to investigate the cause of the indexing lag and remediate it if possible before proceeding with one of the options below to mitigate issues associated with a high recommended monitoring lag.