Splunk® ITSI: Manage IT Service Performance and Health
Your Splunk platform needs to remain usable as volumes and requirements evolve. Connect configuration, architecture and operational monitoring to inform your decisions. Strengthen your ability to organise data infrastructure aligned with expected services.
- Duration
- 3 days 21 hours
- Code
- ASR006FR Code
Presentation
In modern technology environments, monitoring individual components is no longer enough to ensure operational continuity. Infrastructure complexity requires a service-centred approach to gain real-time visibility of overall information system health. Splunk IT Service Intelligence (ITSI) provides advanced analytics to turn massive data volumes into actionable business indicators.
This intensive 3-day course develops your command of Splunk ITSI architecture and essential components. You will be guided through creating complex entity models, defining KPIs rigorously and implementing advanced correlation policies. The approach combines an understanding of service topology with predictive analytics to anticipate failures.
By the end of the course, your expertise will help significantly reduce mean time to resolution (MTTR) through accurate root cause analysis. You will be able to automate corrective actions and integrate ITSI with other IT service management (ITSM) tools. This technical development demonstrates your ability to manage proactive monitoring and optimise your organisation's operational performance.
Objectives
By the end of this Splunk ITSI course, you will be able to:
- understand Splunk ITSI architecture and specific components in depth;
- create and configure critical IT services and their associated KPIs for accurate monitoring;
- represent complex service topology and hierarchy through expert use of entity models;
- define key performance indicators and configure alert thresholds to assess service health;
- use advanced analytics and correlation policies to automate incident detection;
- analyse incidents and trends through advanced visualisations to identify root causes;
- configure automatic response actions and integrate ITSI with third-party ITSM tools;
- apply optimisation best practices to ensure effective, proactive monitoring.
Program
Module 1: Understand Splunk ITSI architecture and features
- Splunk ITSI fundamentals and the scope of its features.
- Detailed understanding of architecture and component interactions.
Module 2: Configure IT services and KPIs
- Create and configure IT services in Splunk ITSI.
- Define key performance indicators (KPIs) for monitoring.
Practical exercises
- Create a business service and define its strategic health KPIs.
Module 3: Build entity models and service topology
- Use entity models to represent infrastructure components.
- Advanced configuration to accurately reflect service hierarchy.
Practical exercises
- Model a complex service hierarchy by importing entities.
Module 4: Define performance indicators and thresholds
- Select performance indicators to assess service health.
- Configure static or dynamic alert thresholds for indicators.
Practical exercises
- Configure multilevel alert thresholds for real performance indicators.
Module 5: Correlate events and automate detection
- Use advanced analytics to detect anomalies and incidents.
- Configure correlation policies to reduce noise and automate detection.
Practical exercises
- Implement a correlation policy to aggregate alerts into incidents.
Module 6: Analyse services and automate actions
- Use dashboards (Glass Tables) and visualisations for monitoring.
- Analyse incidents and identify root causes (Root Cause Analysis).
- Integrate with ITSM tools and configure automatic actions.
Practical exercises
- Design a customised Glass Table view and configure an automated action workflow.
Module 7: Optimise configurations and apply best practices
- Optimise settings to improve overall solution effectiveness.
- Deploy a proactive monitoring strategy based on lessons learned.
Audience
This course is intended for professionals responsible for keeping critical services operational, including:
- Splunk administrators seeking to deploy and manage ITSI;
- systems engineers responsible for monitoring infrastructure performance;
- operations managers seeking a unified view of IT service health;
- IT consultants responsible for integrating observability and AIOps solutions.
Prerequisites
The following prerequisites apply:
- Technical knowledge: advanced Splunk administration proficiency (Splunk Admin level) is essential, including index management, searches (SPL) and distributed deployments.
- Professional experience: proven experience in systems administration or infrastructure engineering is required to understand service hierarchy.
- Required equipment: this course requires an environment with a valid Splunk ITSI licence.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
- Service-oriented perspective: learn to turn raw data into clear health indicators to manage IT services end to end.
- Intelligent correlation: automate complex incident detection using advanced correlation policies to reduce alert noise.
- Root cause analysis: master visualisation and analysis tools to identify problems' origins quickly and reduce MTTR.
- Operational automation: learn to configure automatic incident responses, ensuring optimal infrastructure responsiveness.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Splunk is a registered trademark of Cisco Systems, Inc. or its subsidiaries in the United States and other countries.
Its mention for educational purposes does not constitute an endorsement or partnership.
fr
en