Splunk® IT Service Intelligence

Service Insights Manual

Create a single service in ITSI

When you create a service in IT Service Intelligence (ITSI), you have three options for populating the service:

  • Manually add the KPIs and entity rules.
  • Link the service to a service template to automatically populate the KPIs and entity rules. See Overview of service templates in ITSI for information about service templates.
  • Select prebuilt KPIs from ITSI modules to populate KPIs and entity rules. For more information, see Overview of modules in ITSI.


  • You must be assigned the write_itsi_service capability to create a single service.
  • You can only create a service in a team for which you have read and write permissions.


  1. Select Configuration, then Service Monitoring, then Service and KPI Management.
  2. Select Create Service then Create Service. You only see this action if your role has write access to at least one team.
  3. Provide a title and description for the service.
  4. Select the team to associate the service with. This service will only be visible for roles that are assigned read permission to this team. If no private teams exist for your organization, only the Global team is available. For more information about teams, see Overview of teams in ITSI in the Administration Manual.
  5. Select one of the following options:
    Option Description
    Manually add service content Manually add entities, KPIs, and other information for this service.
    Link service to a service template Populate the service with the entity rules and KPIs from a service template.
    Add prebuilt KPIs from modules Populate the service with the entity rules and pre-built KPIs from ITSI modules.
  6. If you selected Link service to a service template, do the following:
    1. Select the template to link the service to.
    2. Review the entity rules and KPIs in the template. These will be added to the new service.
    3. (Optional) Select Enable 7 days of backfill for all Service KPIs if you need to populate the summary index with data in order to use adaptive thresholding or anomaly detection with any of your KPIs. This setting applies to all the KPIs in the service. You can't backfill individual KPIs. You also can't backfill a KPI that came from the template in the service later on as this action unlinks the service from the template.
  7. If you selected Add pre-built KPIs from modules, do the following:
    1. Select any number of ITSI modules from the list. Before using pre-built KPIs, you must configure the specific ITSI module. See Overview of ITSI modules in the ITSI Modules manual.)
    2. Select the KPIs to add to the service. Recommended KPIs are pre-selected. Each KPI template populates the new service with specific entity rules and selected KPIs.
  8. Select Create.

After creating the service, see Overview of creating services in ITSI to decide how to configure the newly created service.

Clone a service

When you clone a service in ITSI, all entities, KPIs, and settings from the original service are cloned into the new service. Cloning a service does not clone summary index content of KPIs within the service. If the original service is linked to a service template, the cloned service is linked to the same service template. Service dependencies and Predictive Analytics models are not copied to the cloned service.


You must have the write_itsi_service capability to clone a service in ITSI.


  1. Select Configuration, then Service Monitoring, then Service and KPI Management.
  2. In the Actions column of the service you want to clone, select Edit > Clone.
  3. Provide a title that is different than the title of the original service (for example, Database 2). Two services can not have the same title.
  4. Select the team that the cloned service will belong to.
  5. Select Clone.
Last modified on 29 April, 2024
Overview of creating services in ITSI   Import services from a CSV in ITSI

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.19.0

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters