Watch On-Demand. This thread is for the Community Office Hours session on Splunk IT Service Intelligence (ITSI) on Tues, July 15, 2025 at 1pm PT / 4pm ET.
Ask the experts at Community Office Hours! An ongoing series where technical Splunk experts answer questions and provide how-to guidance on various Splunk product and use case topics.
What can I ask in this AMA?
- How can I use ITSI to analyze IT service health?
- What are some tips to reduce alert noise?
- How can I isolate and prioritize actionable events?
- What kinds of Executive Dashboards can I build to visualize the health of the business?
- Anything else you’d like to learn!
We look forward to seeing you there!
Please submit your questions at registration. You can also head to the #office-hours user Slack channel to ask questions (request access here).
Pre-submitted questions will be prioritized. After that, we will open the floor up to live Q&A with meeting participants.
Look forward to connecting!
You can view the On-Demand recording at the link above and slide deck here, but here is a sampling of questions covered in the event.
Q1: Can you help me understand the two different types of anomaly detection in ITSI?
A: Anomaly Detection within Splunk ITSI uses machine learning to detect trend & event level anomalies, and alert teams. ITSI analyzes when data deviates from expected patterns, thresholds, and historical behavior to provide insights into detected patterns & uncover new patterns across multiple events that could indicate a potential issue.
Documentation:
Q2: What is adaptive thresholding and why is it important?
A: In Splunk ITSI, adaptive thresholding is a feature that uses machine learning to dynamically adjust alert thresholds based on historical data patterns, rather than relying on static, unchanging values. This allows for more accurate anomaly detection in environments where data behavior fluctuates over time. By analyzing trends and normal variations, adaptive thresholds reduce false positives and missed alerts, ensuring that operational teams are notified of genuine issues even as the baseline behavior changes.
Documentation:
Q3: How do I configure and enable the Notable Event Aggregation Policy? (NEAP)
A: What is a NEAP?
How to configure & enable NEAPs?
Documentation:
Q4: What are some tips to reduce alert noise?
A:
Documentation:
Q5: Can we learn more about ITSI integrations with Teams and Slack?
A: Splunk ITSI’s Teams and Slack integrations are Splunk-supported & maintained, available on the Splunkbase website. The integrations (content packs) do way more than help notify teams:
Documentation:
(Check here for troubleshooting Teams)