Register here. This thread is for the Community Office Hours session on Splunk ITSI on Wednesday, November 19, 2025 at 11am PT / 2pm ET.
Ask the experts at Community Office Hours! An ongoing series where technical Splunk experts answer questions and provide how-to guidance on various Splunk product and use case topics.
What can I ask in this AMA about ITSI?
Please submit your questions at registration. You can also head to the #office-hours Community Slack channel to ask questions (sign-in with SSO here).
Pre-submitted questions will be prioritized. After that, we will open the floor up to live Q&A with meeting participants.
We look forward to connecting with you!
Hi everyone! Here are a few questions from the session, as well as the link to the on-demand recording (get the full Q&A deck and recording in the #office-hours Slack channel as well)
Q1:
a) Can you show us some best in-class examples of executive dashboards made in ITSI?
b) Interested in examples of Executive Dashboards for visualizing/comparing the health of a set of critical services.
Answer
This approach empowers executives with a clear, actionable view of critical service health for informed decision-making and rapid response.
Documentation:
Q2: Can you give an overview of Event Analytics and demonstrate how Event IQ adds value here?
Answer:
Documentation:
Event Analytics: https://docs.splunk.com/Documentation/ITSI/4.20.1/EA/AboutEA
Event IQ: https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/detect-and-act-on-notable-events/4.21/event-correlation/automate-event-correlation-with-event-iq-in-itsi
Q3: How do you create a KPI without using a content pack, such as AppDynamics?
Answer
KPI creation and configuration is done via the Service configuration UI as well as the Service Template configuration UI. High level config steps:
|
Step |
Task |
Description |
Optional/Required |
|
1 |
A search string that you define as the basis for your KPI, using a data model, an ad hoc search, a metrics search, or a base search. |
Required |
|
|
2 |
Break down the KPI to apply the search to multiple entities, enabling comparative analysis of search results on a per-entity basis. Filter entities in or out of the KPI search. |
Optional |
|
|
3 |
The recurring KPI search schedule and the statistical operations performed on the search results, including service health score calculations. |
Required |
|
|
4 |
Define the unit of measurement to display for the KPI. Configure the monitoring lag to offset indexing lag. |
Optional |
|
|
5 |
Fills the summary index with historical raw service health score data. |
Optional |
|
|
6 |
Severity-level thresholds that you apply to KPI search results. Thresholds let you monitor KPI status (normal, low, medium, high, and critical) and set trigger conditions for alerts. |
Required |
|
|
7 |
Use machine learning to analyze your KPIs with existing data and generate recommendations for optimal threshold values. Thresholds let you monitor KPI status (normal, low, medium, high, and critical) and set trigger conditions for alerts. |
Optional |
Documentation:
Question 4: What is “drift detection” and how is that used?
Answer:
Documentation:
Q5: What are best practices to deal with events as fast as they are generated?
Answer
Documentation:
https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/detect-and-act-on-notable-events/4.21/overview/overview-of-event-analytics-in-itsi
Question 6: Can we learn more about ITSI integrations with Teams and Slack?
Answer
Documentation: