Splunk IT Service Intelligence

How to define Services or Applications without the ITSI module


I have CMDB imported from ServiceNow but i'm struggling to find a way to define services or applications and provide holistic insight into the service health and availability without ITSI module.

For example, i have a list of 10 servers which make up "Service X", web front, db, app, etc. Relationship is defined in CMDB. How would i go about building the following:

  1. "Service X" health score - which is a combination of web front, db, app, etc server health scores. IE if one gets degraded it reduces overall score

  2. Visually diagram the relationship between the servers based on their relationship defined in CMDB.

  3. Is there any way to make use of CMDB data from ServiceNow without ITSI module?

Tags (1)
0 Karma


I'm unsure about your familiarity with ITSI, but once you understand how it works, it's pretty easy to build from the ground up in core Splunk. Essentially you need some scheduled searches to populate a summary index, then you need to build a dashboard to query that summary index and build a health score from those values. If you want to split by entity, then you just add a by clause in your populating search.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...