Splunk IT Service Intelligence

How to define Services or Applications without the ITSI module


I have CMDB imported from ServiceNow but i'm struggling to find a way to define services or applications and provide holistic insight into the service health and availability without ITSI module.

For example, i have a list of 10 servers which make up "Service X", web front, db, app, etc. Relationship is defined in CMDB. How would i go about building the following:

  1. "Service X" health score - which is a combination of web front, db, app, etc server health scores. IE if one gets degraded it reduces overall score

  2. Visually diagram the relationship between the servers based on their relationship defined in CMDB.

  3. Is there any way to make use of CMDB data from ServiceNow without ITSI module?

Tags (1)
0 Karma


I'm unsure about your familiarity with ITSI, but once you understand how it works, it's pretty easy to build from the ground up in core Splunk. Essentially you need some scheduled searches to populate a summary index, then you need to build a dashboard to query that summary index and build a health score from those values. If you want to split by entity, then you just add a by clause in your populating search.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...