Splunk® IT Service Intelligence

Administer Splunk IT Service Intelligence

Download manual as PDF

Download topic as PDF

Set up Predictive Analytics in ITSI

Before you can predict service health scores with ITSI Predictive Analytics, you need to configure the Splunk Machine Learning Toolkit application and optionally set up permissions.

Enable Predictive Analytics

To use Predictive Analytics, you need to install the Splunk Machine Learning Toolkit (MLTK) and share the machine learning macros with all apps so ITSI can access them. To minimize memory and disk consumption, configure the Machine Learning Toolkit configuration file. This will allow the MLTK to handle more memory and events.

  1. Install the Python for Scientific Computing add-on version 1.3 or later for your operating system:
  2. Install the Splunk Machine Learning Toolkit. Follow the steps in Install the Splunk Machine Learning Toolkit in the MLTK User Guide. For compatible MLTK versions, see ITSI compatibility with other apps and add-ons.
  3. Give the MLTK app Global permissions:
    1. In ITSI, click App: IT Service Intelligence > Manage Apps.
    2. In the filter bar, enter Splunk Machine Learning Toolkit.
    3. Click Permissions.
    4. Ensure that All apps is selected.
    5. Click Save.
  4. (Optional) Configure the MLTK to handle more memory and events:
    1. Create a copy of mlspl.conf in $SPLUNK_HOME/etc/apps/Splunk_ML_Toolkit/local.
    2. Configure the following settings under the [default] stanza and in each algorithm-specific stanza:
      Setting Recommended value
      max_inputs 1000000
      max_memory_usage_mb 2000
      max_model_size_mb 30
      max_fit_time 2400
    3. Save the file and restart Splunk software.

Permissions requirements

The following table summarizes the ITSI roles and corresponding Predictive Analytics capabilities:

Role Capabilities
itoa_admin
  • Train a model
  • Test a model
  • Add a model to a glass table
  • Create alerts from a model
  • Delete a model
itoa_team_admin
  • Train a model (with write access to the service)
  • Test a model
  • Add a model to a glass table
  • Create alerts from a model
  • Delete a model
itoa_analyst
  • Read models (with read access to the service)
  • Test a model
  • Add a model to a glass table
  • Create alerts from a model
itoa_user
  • Read models (with read access to the service)
  • Test a model
  • Create alerts from a model

See also

PREVIOUS
Predict and prevent outages with ITSI Predictive Analytics
  NEXT
Access Predictive Analytics in ITSI

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.3.0, 4.3.1, 4.4.0, 4.4.1


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters