Splunk ITSI

How to define Services or Applications without the ITSI module

draganmarkov
Explorer

I have CMDB imported from ServiceNow but i'm struggling to find a way to define services or applications and provide holistic insight into the service health and availability without ITSI module.

For example, i have a list of 10 servers which make up "Service X", web front, db, app, etc. Relationship is defined in CMDB. How would i go about building the following:

  1. "Service X" health score - which is a combination of web front, db, app, etc server health scores. IE if one gets degraded it reduces overall score

  2. Visually diagram the relationship between the servers based on their relationship defined in CMDB.

  3. Is there any way to make use of CMDB data from ServiceNow without ITSI module?

Tags (1)
0 Karma

skoelpin
SplunkTrust
SplunkTrust

I'm unsure about your familiarity with ITSI, but once you understand how it works, it's pretty easy to build from the ground up in core Splunk. Essentially you need some scheduled searches to populate a summary index, then you need to build a dashboard to query that summary index and build a health score from those values. If you want to split by entity, then you just add a by clause in your populating search.

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...