Splunk Tech Talks
Deep-dives for technical practitioners.

Splunk ITSI & Correlated Network Visibility

DayaSCanales
Splunk Employee
Splunk Employee

Screenshot 2025-07-28 at 9.44.00 AM.png

 

Now On Demand

 

Take Your Network Visibility to the Next Level


In today’s complex IT environments, performance issues can stem from anywhere—a congested network path, a sluggish backend service, or even infrastructure degradation. That’s why understanding how your networks, applications, and services connect is critical to keeping your business running smoothly.

 

Available here:

 

With Splunk ITSI and its new integrations with ThousandEyes, Catalyst Center, and Meraki, you can now correlate network telemetry and infrastructure insights faster than ever. Gain the tools to speed up root cause analysis, map device and interface health, and prioritize actions based on business impact.

Don’t just monitor your networks—understand the “why” behind issues and their relevance to your business. Learn how to seamlessly integrate and extend your visibility to make smarter, faster decisions for your IT operations.

DayaSCanales
Splunk Employee
Splunk Employee

Here are a few top of mind questions from the live Tech Talk

 

Q. There are several integrations with Cisco products, can you please let us know if the same value would be given from topology metrics and events from other vendors like SolarWinds, OpenText Dynatrace, etc...?

A. Yes, Splunk ITSI is designed as a cross-domain visibility tool and supports integration with a wide range of third-party vendors and tools, not just Cisco products. The platform can ingest, correlate, and analyze topology, metrics, and event data from other major vendors such as SolarWinds, OpenText, Dynatrace, BMC, and more.

DayaSCanales_0-1755064080490.png

Q. How does observability licensing work?

A. The Splunk Observability platform is licensed based on host, ingestion, and/or workload - and each observability capability has licensing specifics to each product: https://www.splunk.com/en_us/products/pricing/observability.html 
FAQ: https://www.splunk.com/en_us/products/pricing/faqs/observability.html 

DayaSCanales_1-1755064080491.png

Q. How does this relate to your OLI Cloud Solution?

A. ITSI is related to our Observability Cloud Solution in that ITSI is a premium application that sits on top of Splunk Observability Cloud or Splunk Enterprise.

DayaSCanales_2-1755064080491.png

Q. Can ITSI pull in data from other vendor products e.g. Aruba?

A. Yes, Splunk ITSI can ingest and correlate data from a wide variety of third-party vendor products, including Aruba and many others. As long as the data (such as logs, metrics, events, or flow data) can be sent to or collected by Splunk, ITSI can use it for analytics, alerting, and service correlation.

DayaSCanales_2-1755064080491.png

Q. Is there a way to see flow data for individual devices in ITSI?

A. Yes, Splunk ITSI can display flow data and other metrics for individual devices, provided that the necessary data is ingested into Splunk from your network tools. Through integrations and technical add-ons with products like Cisco ThousandEyes, Catalyst Center, and Meraki, as well as third-party solutions, you can bring in device-level flow data (such as NetFlow, sFlow, or similar telemetry).

DayaSCanales_2-1755064080491.png

Q. Here is a quick guided tour showcasing glass tables and service monitoring:

A. Splunk IT Service Intelligence Guided Product Tour.

DayaSCanales_3-1755067327276.png

Q. How does ITSI sit on top of the Splunk Observability Cloud, I thought it sat on top of the Splunk Core?

A. ITSI sits on top of the Splunk Core product, there are integrations available between Splunk Observability Cloud and ITSI. The two can complement each other in a hybrid environment, but they are architecturally distinct.

DayaSCanales_2-1755064080491.png

Q. Would this be a layer on top or integrated with AWS or Azure services?

A. Splunk ITSI and the observability solutions can be deployed either on-premises or in the cloud, including on AWS or Azure. They act as both a layer on top of your cloud services and can be directly integrated with AWS, Azure, and other cloud platforms.

DayaSCanales_2-1755064080491.png

Q. Will AI/ML capabilities be expanded to automate correlation and anomaly detection in ITSI?

A. There are capabilities to help with correlation powered by AI/ML namely Event IQ. ITSI leverages anomaly detection to model KPI behavior and generates alerts when these KPI's deviate from an expected pattern. Cisco and Splunk Strengthen Enterprise Digital Resilience in the AI Era  

DayaSCanales_2-1755064080491.png

Q. If there is a network service and service tree/dependency with location in ServiceNow, is it possible to import the topology to ITSI and keep it updated from there, or is there a smarter way?

A. Yes, it is possible to import service topologies (including dependencies and locations) from ServiceNow into Splunk ITSI. Splunk provides a ServiceNow technical add-on that supports this integration. This add-on can pull in data such as service trees, dependencies, and location details from ServiceNow’s CMDB or ITOM modules and bring them into ITSI for use in service monitoring and correlation.

Additionally, ITSI supports ongoing synchronization, so updates made to service topologies in ServiceNow can be reflected in ITSI, keeping your monitoring environment up to date. The process is designed to reduce manual configuration and streamline service modeling within ITSI.

DayaSCanales_2-1755064080491.png

Q. Does service topology need to be created manually or dynamically?

A. Service topology in Splunk ITSI can be created both manually and dynamically, but the platform is designed to make dynamic (automated) creation as easy as possible.

DayaSCanales_2-1755064080491.png

Q. Can you share a Demo and POC for customers who are interested in Splunk?

A. Here is the link to request a demo Splunk IT Service Intelligence (ITSI) 

DayaSCanales_2-1755064080491.png

Q. Is Catalyst Center the same as Cisco DNAC?

A. Yes, Cisco Catalyst Center is the new name for what was previously known as Cisco DNA Center (DNAC). Cisco rebranded DNA Center to Catalyst Center, but it is essentially the same platform for network management, automation, and analytics.

DayaSCanales_2-1755064080491.png

Q. Does this also track alerts in ThousandEyes, and sync respectively?

A. Yes, Splunk ITSI can track alerts from ThousandEyes. The integration pulls in alerts, metrics, and test results from ThousandEyes into ITSI, allowing those alerts to be correlated with other events and displayed in dashboards and incident views within ITSI.

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...