Splunk® IT Service Intelligence

Administer Splunk IT Service Intelligence

Download manual as PDF

Download topic as PDF

Overview of configuring services in ITSI

This topic provides an overview of how to configure services in IT Service Intelligence (ITSI). For more information about ITSI services, see Overview of creating services in ITSI.

Prerequisite

You must have the write_itsi_service capability to configure services. The itoa_admin and itoa_team_admin roles have this capability by default.

Option 1: Configure a service manually

The following diagram shows the steps to manually configure an ITSI service:

ServiceConfig.png

The following table describes the steps to manually configure a service:

Step Description Required/Optional
Create new service Either create a single service, import services from a CSV file, or import them from a Splunk search. Required
Add entity rules Entity rules let you dynamically filter KPI searches based on entity alias matches. Optional
Add KPIs A Key Performance Indicator (KPI) is a recurring saved search that returns the value of an IT performance metric, such as CPU load percentage, memory used percentage, response time, and so on. Required
Add service dependencies Adding service dependencies can help you detect if one service is having a negative impact on another service, and can be useful in performing root cause analysis. Optional

Option 2: Configure a service created from a service template

If you created a service from a service template, the entity rules and KPIs are populated for you. You still need to configure service dependencies. For more information, see Configure a service created from a service template in ITSI.

Option 3: Configure a service created from pre-built KPIs

If you created a service using pre-built KPIs from modules, the entity rules and KPIs are populated for you. For more information, see Define a source search from a base search and About ITSI modules.

PREVIOUS
Bulk import services in ITSI
  NEXT
Add entity rules to a service in ITSI

This documentation applies to the following versions of Splunk® IT Service Intelligence: 3.1.0, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.1.0, 4.1.1, 4.1.2, 4.1.5, 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.3.0, 4.3.1, 4.4.0, 4.4.1


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters