Skip to content
fernet.consultores

Splunk Cloud

Splunk ITSI.

Stop watching servers and start seeing services: we model your services in Splunk IT Service Intelligence to see their health and group alerts into episodes.

The problem we solve.

When you monitor servers instead of services, one incident generates dozens of separate alerts and nobody knows its business impact. Operations and management look at different screens and talk about different things.

What’s included.

  • Service and dependency modelling
  • Definition of KPIs and base searches
  • Adaptive thresholds by hour and day
  • Event aggregation policies into episodes
  • Glass tables and views for each audience

How we work.

Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.

We review your platform, your data sources, your searches and your licence consumption to know where you stand.

We design the solution on Splunk Cloud Platform: indexes, retention, ingest paths, apps and access controls.

We model the services, create the KPIs and their base searches, and configure adaptive thresholds and aggregation policies.

We check against recent incidents that the service map reflects what happened and that episodes group alerts correctly.

We measure usage, performance and cost after go-live and adjust what isn't adding value.

Technical capabilities.

  • Splunk IT Service Intelligence
  • Service trees
  • KPI base searches
  • Adaptive thresholding
  • Notable event aggregation policies
  • Glass tables and deep dives

Use cases.

Service map

See at a glance which business service is degraded and why.

Alert storms

Group hundreds of alerts into a single actionable episode.

Reporting to management

Measure service health with understandable indicators.

Benefits for your organisation.

  • Visible business impact
  • Fewer duplicate alerts
  • Faster diagnosis
  • A common language between teams

Deliverables.

  • Modelled services and KPIs
  • Aggregation policies
  • Glass tables
  • Model maintenance guide

Frequently asked questions.

Where do we start with ITSI?

With one or two critical services and a few well-chosen KPIs. It's then expanded using the same methodology.

Does ITSI replace our current alerts?

It puts them in order: it groups alerts into episodes by service so the problem is dealt with, not each symptom.

What are adaptive thresholds?

Thresholds that learn each KPI's normal behaviour by time of day, instead of a single fixed value for the whole day.

Shall we talk about ITSI?

Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.

Request this service