Splunk ITSI

Need docs for enhance monitoring using splunk

imamsynch
New Member

Hi,

I have joined recently as splunk architect. Have been assigned to work on enhancement of monitoring. We have deployed itsi on our environment. Need to know how best to enable monitoring for different areas such as network, server and applications etc.
Any docs which would be of help, please let me know.

0 Karma
1 Solution

skalliger
Motivator

Hi,

for a succesful ITSI deployment, you might want to consider getting some PS involved. Premium solutions like ITSI shouldn't be "just installed" and started to work on without proper planning before. ITSI brings some key concepts with it, like Correlation Searches, KPIs, Multi-KPI alerting, Predictive Analytics, Entities and other things likes teams, glass tables.

The docs are great in explaining things but they're not meant as an implementation guide of how to map your business services to Splunk. To understand certain features, this docs page will get you started. Go from there. I still suggest to get Splunk or a partner involved or ITSI will could end up in a messed up way after some time. 🙂

Skalli

View solution in original post

0 Karma

skalliger
Motivator

Hi,

for a succesful ITSI deployment, you might want to consider getting some PS involved. Premium solutions like ITSI shouldn't be "just installed" and started to work on without proper planning before. ITSI brings some key concepts with it, like Correlation Searches, KPIs, Multi-KPI alerting, Predictive Analytics, Entities and other things likes teams, glass tables.

The docs are great in explaining things but they're not meant as an implementation guide of how to map your business services to Splunk. To understand certain features, this docs page will get you started. Go from there. I still suggest to get Splunk or a partner involved or ITSI will could end up in a messed up way after some time. 🙂

Skalli

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise Security 8.0!

Join us on Wednesday, November 20 to learn about Splunk Enterprise Security 8.0!To enhance SOC efficiency, ...

Mastering Threat Hunting

Register to watch Mastering Threat Hunting on Monday, November 18Join us for an insightful talk where we dive ...

Upcoming Community Maintenance: 10/28

Howdy folks, just popping in to let you know that the Splunk Community site will be in read-only mode ...