What can a KPI widget on a glass table drill down into?
Another glass table.
A Splunk dashboard.
A custom deep dive.
Any of the above.
In Splunk IT Service Intelligence (ITSI), a KPI widget on a glass table can be configured to drill down into a variety of destinations based on the needs of the user and the design of the glass table. This flexibility allows users to dive deeper into the data or analysis represented by the KPI widget, providing context and additional insights. The destinations for drill-downs from a KPI widget can include:
A. Another glass table, offering a different perspective or more detailed view related to the KPI. B. A Splunk dashboard that provides broader analysis or incorporates data from multiple sources. C. A custom deep dive for in-depth, time-series analysis of the KPI and related metrics.
This versatility makes KPI widgets powerful tools for navigating through the wealth of operational data and insights available in ITSI, facilitating effective monitoring and decision-making.
When in maintenance mode, which of the following is accurate?
Once the window is over, KPIs and notable events will begin to be generated again.
KPIs are shown in blue while in maintenance mode.
Maintenance mode slots are scheduled on a per hour basis.
Service health scores and KPI events are deleted until the window is over.
Which of the following items apply to anomaly detection? (Choose all that apply.)
Use AD on KPIs that have an unestablished baseline of data points. This allows the ML pattern to perform it’s magic.
A minimum of 24 hours of data is needed for anomaly detection, and a minimum of 4 entities for cohesive analysis.
Anomaly detection automatically generates notable events when KPI data diverges from the pattern.
There are 3 types of anomaly detection supported in ITSI: adhoc, trending, and cohesive.
What is an episode?
A workflow task.
A deep dive.
A notable event group.
A notable event.
It's a deduplicated group of notable events occurring as part of a larger sequence, or an incident or period considered in isolation.
What happens when an anomaly is detected?
A separate correlation search needs to be created in order to see it.
A SNMP trap will be sent.
An anomaly alert will appear in core splunk, in index=main.
An anomaly alert will appear as a notable event in Episode Review.
When an anomaly is detected in Splunk IT Service Intelligence (ITSI), it typically generates a notable event that can be reviewed and managed in the Episode Review dashboard. The Episode Review is part of ITSI's Event Analytics framework and serves as a centralized location for reviewing, annotating, and managing notable events, including those generated by anomaly detection. This process enables IT operators and analysts to efficiently identify, prioritize, and respond to potential issues highlighted by the anomaly alerts. The integration of anomaly alerts into the Episode Review dashboard streamlines the workflow for managing and investigating these alerts within the broader context of IT service management and operational intelligence.
Which of the following statements describe default glass tables in ITSI?
The Service Health Score default glass table.
There is one default glass table per service.
There is one service template default glass table.
There are no default glass tables.
In Splunk IT Service Intelligence (ITSI), glass tables are fully customizable dashboards that provide a visual representation of an organization's IT environment, along with the health and status of services and KPIs. Unlike some pre-configured views or dashboards that might come with default setups in various platforms, ITSI does not provide default glass tables out of the box. Instead, users are encouraged to create their own glass tables tailored to their specific monitoring needs and operational views. This approach ensures that each organization can design glass tables that best represent their unique infrastructure, applications, and service landscapes, providing a more personalized and relevant operational overview.
There are two departments using ITSI. Finance and Sales. Analysts in each department should not be allowed to see each other’s services. What are the role configuration steps required to accomplish this?
itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.
itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_team_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.
itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.
itoa_finance_admin, inherited from itoa_team_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.
C is the correct answer because teams are a feature of ITSI that allow you to restrict access to service content in UI views based on user roles. To create separate teams for finance and sales analysts, you need to create custom roles that inherit from the itoa_analyst role, which has read-only access to ITSI content. For example, you can create itoa_finance_analyst and itoa_sales_analyst roles that inherit from itoa_analyst. Then, you need to create custom teams that include these roles and assign them to the relevant services. For example, you can create a finance team that includes the itoa_finance_analyst role and assign it to the finance services. Similarly, you can create a sales team that includes the itoa_sales_analyst role and assign it to the sales services. This way, analysts in each department can only see their own services and not each other’s. References: Create teams in ITSI, Assign teams to services in ITSI
Which of the following actions can be performed with a deep dive?
Create a Multi-KPI alert from the deep dive's current state to warn of similar situations in the future.
Create a predictive analysis model from the deep dive to warn of future service degradation.
Create an anomaly detection alert to show when the same pattern begins in the future.
Create a custom service analyzer from selected deep dive lanes.
Deep dives in Splunk IT Service Intelligence (ITSI) allow for an in-depth analysis of services and their KPIs over time, providing a detailed view of the operational health and performance trends. One of the powerful actions that can be performed with a deep dive is the creation of a Multi-KPI alert from the deep dive's current state. This functionality enables users to define alerts based on the complex conditions observed during the deep dive analysis, allowing for the early detection of similar situations in the future. By configuring a Multi-KPI alert directly from a deep dive, ITSI users can leverage their insights and observations to proactively monitor for patterns or conditions that may indicate potential service degradation or failure, enhancing the overall responsiveness and effectiveness of the IT monitoring strategy.
Which scenario would benefit most by implementing ITSI?
Monitoring of business services functionality.
Monitoring of system hardware.
Monitoring of system process statuses
Monitoring of retail sales metrics.
Which index is used to store KPI values?
itsi_summary_metrics
itsi_metrics
itsi_service_health
itsi_summary
The IT Service Intelligence (ITSI) metrics summary index, itsi_summary_metrics, is a metrics-based summary index that stores KPI data.
Which of the following accurately describes base searches used for KPIs in a service?
Base searches can be used for multiple services.
A base search can only be used by its service and all dependent services.
All the metrics in a base search are used by one service.
All the KPIs in a service use the same base search.
KPI base searches let you share a search definition across multiple KPIs in IT Service Intelligence (ITSI). Create base searches to consolidate multiple similar KPIs, reduce search load, and improve search performance.
Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)
A pre-configured default ITSI backup job is provided that can be modified, but not deleted.
ITSI backup is inclusive of KV Store, ITSI Configurations, and index dependencies.
kvstore_to_json.py can be used in scripts or command line to backup ITSI for full or partial backups.
ITSI backups are stored as a collection of JSON formatted files.
ITSI provides a kvstore_to_json.py script that lets you backup/restore ITSI configuration data, perform bulk service KPI operations, apply time zone offsets for ITSI objects, and regenerate KPI search schedules.
When you run a backup job, ITSI saves your data to a set of JSON files compressed into a single ZIP file.
Which of the following is an advantage of an adaptive time threshold?
Automatically alerting when KPI value patterns change over time.
Automatically adjusting thresholds as normal KPI values change over time.
Automatically adjusting to holiday schedules.
Automatically predicting future degradation of KPI values over time.
An adaptive time threshold in the context of Splunk IT Service Intelligence (ITSI) refers to the capability of dynamically adjusting threshold values for Key Performance Indicators (KPIs) based on historical data trends and patterns. This feature allows thresholds to evolve as the 'normal' behavior of KPIs changes over time, ensuring that alerts remain relevant and reduce the likelihood of false positives or negatives. The advantage of this approach is that it accommodates for natural fluctuations in KPI values that may occur due to changes in business operations, seasonality, or other factors, without requiring manual threshold adjustments. This makes the monitoring system more resilient and responsive to actual conditions, improving the overall effectiveness of IT operations management.
Which views would help an analyst identify that a memory usage KPI is going critical? (select all that apply)
Memory KPI in a glass table.
Memory panel of the OS Host Details view in the Operating System module.
Memory swim lane in a Deep Dive.
Service & KPI tiles in the Service Analyzer.
To identify that a memory usage KPI is going critical, an analyst can leverage multiple views within Splunk IT Service Intelligence (ITSI), each offering a different perspective or level of detail:
A.Memory KPI in a glass table:A glass table can display the current status of the memory usage KPI, along with other related KPIs and services, providing a high-level overview of system health.
B.Memory panel of the OS Host Details view in the Operating System module:This specific panel within the OS Host Details view offers detailed metrics and trends related to memory usage, allowing for in-depth analysis.
C.Memory swim lane in a Deep Dive:Deep Dives allow analysts to visually track the performance and status of KPIs over time. A swim lane dedicated to memory usage can highlight periods where the KPI goes critical, along with the context of other related KPIs.
D.Service & KPI tiles in the Service Analyzer:The Service Analyzer provides a comprehensive overview of all services and their KPIs. The tiles related to memory usage can quickly alert analysts to critical conditions through color-coded indicators.
Each of these views contributes to a comprehensive monitoring strategy, enabling analysts to detect and respond to critical memory usage conditions from various analytical perspectives.
When creating a custom deep dive, what color are services/KPIs in maintenance mode within the topology view?
Gray
Purple
Gear Icon
Blue
When creating a custom deep dive, services or KPIs that are in maintenance mode are shown in gray color in the topology view. This indicates that they are not actively monitored and do not generate alerts or notable events. References: Deep Dives
Which is the least permissive role required to modify default deep dives?
itoa_analyst
admin
power
itoa_admin
To modify default deep dives in Splunk IT Service Intelligence (ITSI), the least permissive role typically required is theitoa_adminrole. This role is specifically designed within ITSI to provide administrative capabilities, including the ability to configure and customize various aspects of ITSI, such as services, KPIs, and deep dives. Theitoa_adminrole has the necessary permissions to edit and manage default deep dives, enabling users with this role to tailor the deep dives to meet specific operational requirements and preferences. Other roles likeitoa_analyst,admin, orpowermight not have sufficient privileges to modify default deep dives, as these roles are generally more restricted in terms of their ability to make broad changes within ITSI.
Which index will contain useful error messages when troubleshooting ITSI issues?
_introspection
_internal
itsi_summary
itsi_notable_audit
When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)
Copy SA-IndexCreation to all indexers.
Copy SA-IndexCreation to the etc/apps directory on the index cluster master node.
Extract installer package into etc/apps directory of the cluster deployer node.
Extract ITSI app package into etc/apps directory of search head.
Copy SA-IndexCreation to $SPLUNK_HOME/etc/apps/ on all individual indexers in your environment.
ITSI Saved Search Scheduling is configured to use realtime_schedule = 0. Which statement is accurate about this configuration?
If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time.
If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time.
If this value is set to 0, the scheduler may skip scheduled execution periods.
If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range.
ITSI Saved Search Scheduling is a feature that allows you to schedule searches that run periodically to populate the data for your KPIs. You can configure various settings for your scheduled searches, such as the search frequency, the time range, the cron expression, and so on. One of the settings is realtime_schedule, which controls the way the scheduler computes the next execution time of a scheduled search. The statement that is accurate about this configuration is:
B. If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time. This is called continuous scheduling. If set to 0, the scheduler never skips scheduled execution periods. However, the execution of the saved search might fall behind depending on the scheduler’s load. Use continuous scheduling whenever you enable the summary index option.
The other statements are not accurate because:
A. If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time. This is not true because this is what happens when the value is set to 1, not 0.
C. If this value is set to 0, the scheduler may skip scheduled execution periods. This is not true because this is what happens when the value is set to 1, not 0.
D. If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range. This is not true because this is what happens when the value is set to 1, not 0.
Which of the following describes a realistic troubleshooting workflow in ITSI?
Correlation Search –> Deep Dive –> Notable Event
Service Analyzer –> Notable Event Review –> Deep Dive
Service Analyzer –> Aggregation Policy –> Deep Dive
Correlation search –> KPI –> Aggregation Policy
A realistic troubleshooting workflow in ITSI is:
B. Service Analyzer –> Notable Event Review –> Deep Dive
This workflow involves using the Service Analyzer dashboard to monitor the health and performance of your services and KPIs, using the Notable Event Review dashboard to investigate and manage the notable events generated by ITSI, and using the Deep Dive dashboard to analyze the historical trends and anomalies of your KPIs and metrics.
The other workflows are not realistic because they involve components that are not part of the troubleshooting process, such as correlation search, aggregation policy, and KPI. These components are used to create and configure the alerts and episodes that ITSI generates, not to investigate and resolve them. References: [Service Analyzer dashboard in ITSI], Overview of Episode Review in ITSI, [Overview of deep dives in ITSI]
Which of the following is a characteristic of notable event groups?
Notable event groups combine independent notable events.
Notable event groups are created in the itsi_tracked_alerts index.
Notable event groups allow users to adjust threshold settings.
All of the above.
In Splunk IT Service Intelligence (ITSI), notable event groups are used to logically group related notable events, which enhances the manageability and analysis of events:
A.Notable event groups combine independent notable events:This characteristic allows for the aggregation of related events into a single group, making it easier for users to manage and investigate related issues. By grouping events, users can focus on the broader context of an issue rather than getting lost in the details of individual events.
While notable event groups play a critical role in organizing and managing events in ITSI, they do not inherently allow users to adjust threshold settings, which is typically handled at the KPI or service level. Additionally, while notable event groups are utilized within the ITSI framework, the statement that they are created in the 'itsi_tracked_alerts' index might not fully capture the complexity of how event groups are managed and stored within the ITSI architecture.
After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?
6 months.
9 months.
1 year.
3 months.
By default, notable event metadata is archived after six months to keep the KV store from growing too large.
Which of the following are characteristics of service templates? (select all that apply)
Service templates can be modified after services are instantiated from it.
Service templates contain KPIs and KPI thresholds.
Service templates can contain specific or generic entity rules.
Service templates contain domain specific dashboards and deep dives.
Service templates in Splunk IT Service Intelligence (ITSI) are designed to streamline the creation of services by providing pre-defined configurations:
B.Service templates contain KPIs and KPI thresholds:This allows for the standardized deployment of services with predefined performance indicators and their associated thresholds, ensuring consistency across similar services.
C.Service templates can contain specific or generic entity rules:These rules define how entities are associated with services created from the template, allowing for both broad and targeted applicability.
While service templates contain configurations for KPIs, thresholds, and entity rules, the ability to modify templates after services have been instantiated from them is limited. Changes to a template do not retroactively affect services already created from that template. Moreover, service templates do not inherently contain domain-specific dashboards or deep dives; these are created separately within ITSI.
Which of the following is a problem requiring correction in ITSI?
Twoormore entitieswiththe same service ID.
Twoormore entitieswiththe same entity ID.
Twoormore entitieswiththe same value in a single alias field.
Twoormore entitieswiththe same entity key value inanyinfo field.
In Splunk IT Service Intelligence (ITSI), entities represent infrastructure components, applications, or other elements that are monitored. Each entity is uniquely identified by its entity ID, and entities can be associated with one or more services through the concept of aliases. A problem arises when two or more entities have the same value in a single alias field because aliases are used to match events to entities in ITSI. If multiple entities share the same alias value, ITSI might incorrectly associate data with the wrong entity, leading to inaccurate monitoring and analytics. This scenario requires correction to ensure that each alias uniquely identifies a single entity, thereby maintaining the integrity of the monitoring and analysis process within ITSI. The uniqueness of service IDs, entity IDs, and entity key values in info fields is also important but does not typically present the same level of issue as duplicate values in an alias field.
How can admins manually control groupings of notable events?
Correlation searches.
Multi-KPI alerts.
notable_event_grouping.conf
Aggregation policies.
In Splunk IT Service Intelligence (ITSI), administrators can manually control the grouping of notable events using aggregation policies. Aggregation policies allow for the definition of criteria based on which notable events are grouped together. This includes configuring rules based on event fields, severity, source, or other event attributes. Through these policies, administrators can tailor the event grouping logic to meet the specific needs of their environment, ensuring that related events are grouped in a manner that facilitates efficient analysis and response. This feature is crucial for managing the volume of events and focusing on the most critical issues by effectively organizing related events into manageable groups.
TESTED 21 Aug 2026
