Splunk ITSI

Need docs for enhance monitoring using splunk

imamsynch
New Member

Hi,

I have joined recently as splunk architect. Have been assigned to work on enhancement of monitoring. We have deployed itsi on our environment. Need to know how best to enable monitoring for different areas such as network, server and applications etc.
Any docs which would be of help, please let me know.

0 Karma
1 Solution

skalliger
Motivator

Hi,

for a succesful ITSI deployment, you might want to consider getting some PS involved. Premium solutions like ITSI shouldn't be "just installed" and started to work on without proper planning before. ITSI brings some key concepts with it, like Correlation Searches, KPIs, Multi-KPI alerting, Predictive Analytics, Entities and other things likes teams, glass tables.

The docs are great in explaining things but they're not meant as an implementation guide of how to map your business services to Splunk. To understand certain features, this docs page will get you started. Go from there. I still suggest to get Splunk or a partner involved or ITSI will could end up in a messed up way after some time. 🙂

Skalli

View solution in original post

0 Karma

skalliger
Motivator

Hi,

for a succesful ITSI deployment, you might want to consider getting some PS involved. Premium solutions like ITSI shouldn't be "just installed" and started to work on without proper planning before. ITSI brings some key concepts with it, like Correlation Searches, KPIs, Multi-KPI alerting, Predictive Analytics, Entities and other things likes teams, glass tables.

The docs are great in explaining things but they're not meant as an implementation guide of how to map your business services to Splunk. To understand certain features, this docs page will get you started. Go from there. I still suggest to get Splunk or a partner involved or ITSI will could end up in a messed up way after some time. 🙂

Skalli

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...