<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="26426" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/splunk-isitsi" lastchanged="2026-01-23T17:46:49+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Implementing Splunk IT Service Intelligence</title><productcode>ISITSI</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-ISITSI</fullproductcode><version>4.15</version><essentials>&lt;p&gt;To be successful, students should have a working understanding of the following courses:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sesa&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise System Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SESA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-seda&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise Data Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SEDA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Or,&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-scla&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise Cluster Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SCLA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;Administrators&lt;/p&gt;</audience><outline>&lt;h4&gt;Module 1- Key Concepts&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Basic ITSI User Interface&lt;/li&gt;&lt;li&gt;Key App Organizational Concepts&lt;/li&gt;&lt;li&gt;Useful Add-ons and Apps&lt;/li&gt;&lt;li&gt;Install ITSI Support Software&lt;/li&gt;&lt;li&gt;Identify Add-on and App Dependencies

&lt;h4&gt;Module 2 &amp;ndash; About Entities and Types&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Entity basics&lt;/li&gt;&lt;li&gt;Entity Type basics&lt;/li&gt;&lt;li&gt;Explore existing types&lt;/li&gt;&lt;li&gt;Edit and create Entity Types&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 3 &amp;ndash; Creating and Importing Entities&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Manually creating entities&lt;/li&gt;&lt;li&gt;Importing entities by search&lt;/li&gt;&lt;li&gt;Entity management and retirement policies&lt;/li&gt;&lt;li&gt;Delete or retire entities&lt;/li&gt;&lt;li&gt;Monitoring entities&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 4 &amp;ndash; Service Plan&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Understanding service health scores&lt;/li&gt;&lt;li&gt;Defining service dependencies&lt;/li&gt;&lt;li&gt;Finding and using data for a service&lt;/li&gt;&lt;li&gt;Compile a service plan&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 5 &amp;ndash; Key Performance Indicator Design&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Understanding KPIs&lt;/li&gt;&lt;li&gt;KPI criteria and sources&lt;/li&gt;&lt;li&gt;Defining KPI thresholds&lt;/li&gt;&lt;li&gt;Designing a service&amp;#039;s KPIs&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 6 &amp;ndash; KPI Base Searches&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Analyze a data environment&lt;/li&gt;&lt;li&gt;Identify entity-oriented KPIs&lt;/li&gt;&lt;li&gt;Creating Base Searches&lt;/li&gt;&lt;li&gt;Understanding and using pseudo entities&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 7 &amp;ndash; Implementing Services&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Creating the ITSI service from the plan&lt;/li&gt;&lt;li&gt;Create KPIs using base searches&lt;/li&gt;&lt;li&gt;Configure KPI lag and backfill&lt;/li&gt;&lt;li&gt;Set KPI importance&lt;/li&gt;&lt;li&gt;Calculate service health score&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 8 &amp;ndash; Service Templates&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;About Service Templates&lt;/li&gt;&lt;li&gt;Create a template from a service&lt;/li&gt;&lt;li&gt;Create a service from a template&lt;/li&gt;&lt;li&gt;Create dependencies between services&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 9 &amp;ndash; Service Sandbox&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Understanding the Service Sandbox&lt;/li&gt;&lt;li&gt;Creating a file for Sandbox import&lt;/li&gt;&lt;li&gt;Import a Service Sandbox&lt;/li&gt;&lt;li&gt;Create dependencies between services&lt;/li&gt;&lt;li&gt;Perform a Service Health Score simulation&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 10 &amp;ndash; Using Thresholds and Time Policies&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Understanding static thresholds&lt;/li&gt;&lt;li&gt;Configure KPI thresholds&lt;/li&gt;&lt;li&gt;Use aggregate and entity-level thresholds&lt;/li&gt;&lt;li&gt;Apply time policies to thresholds&lt;/li&gt;&lt;li&gt;Create custom threshold templates&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module &amp;ndash; 11 Machine Learning and AI in ITSI&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Understanding ML/AI-assisted threshold types and algorithms&lt;/li&gt;&lt;li&gt;Configure adaptive thresholds&lt;/li&gt;&lt;li&gt;Configure AI Recommended thresholds&lt;/li&gt;&lt;li&gt;Create a custom adaptive threshold template&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 12 &amp;ndash; Predictive Analytics&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Define predictive analytics&lt;/li&gt;&lt;li&gt;Train a predictive model&lt;/li&gt;&lt;li&gt;Configure predictive analytics for services&lt;/li&gt;&lt;li&gt;Configure alerting for predicted Service Health Scores&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 13 &amp;ndash; Anomaly Detection&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Understanding anomaly detection&lt;/li&gt;&lt;li&gt;Configure anomaly detection for KPIs&lt;/li&gt;&lt;li&gt;Alerts for Deep Dives and Notable Event Episodes&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 14 &amp;ndash; Multi-KPI Alerts and Correlation Searches&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Define Multi-KPI alerts&lt;/li&gt;&lt;li&gt;Create Multi-KPI alerts&lt;/li&gt;&lt;li&gt;Understanding Correlation Searches&lt;/li&gt;&lt;li&gt;Describing existing Correlation Searches&lt;/li&gt;&lt;li&gt;Defining a Correlation Search&lt;/li&gt;&lt;/ul&gt;

&lt;h4&gt;Module 15 &amp;ndash; Notable Event Aggregation Policies&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Define aggregation policy capabilities&lt;/li&gt;&lt;li&gt;Modify the default aggregation policy&lt;/li&gt;&lt;li&gt;Create a custom aggregation policy&lt;/li&gt;&lt;li&gt;Describe Action Rules&lt;/li&gt;&lt;li&gt;Understand third-party integration&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>To be successful, students should have a working understanding of the following courses:



- Splunk Enterprise System Administration (SESA)
- Splunk Enterprise Data Administration (SEDA)
Or,



- Splunk Enterprise Cluster Administration (SCLA)</essentials_plain><audience_plain>Administrators</audience_plain><outline_plain>Module 1- Key Concepts


- Basic ITSI User Interface
- Key App Organizational Concepts
- Useful Add-ons and Apps
- Install ITSI Support Software
- Identify Add-on and App Dependencies

Module 2 – About Entities and Types



- Entity basics
- Entity Type basics
- Explore existing types
- Edit and create Entity Types


Module 3 – Creating and Importing Entities



- Manually creating entities
- Importing entities by search
- Entity management and retirement policies
- Delete or retire entities
- Monitoring entities


Module 4 – Service Plan



- Understanding service health scores
- Defining service dependencies
- Finding and using data for a service
- Compile a service plan


Module 5 – Key Performance Indicator Design



- Understanding KPIs
- KPI criteria and sources
- Defining KPI thresholds
- Designing a service's KPIs


Module 6 – KPI Base Searches



- Analyze a data environment
- Identify entity-oriented KPIs
- Creating Base Searches
- Understanding and using pseudo entities


Module 7 – Implementing Services



- Creating the ITSI service from the plan
- Create KPIs using base searches
- Configure KPI lag and backfill
- Set KPI importance
- Calculate service health score


Module 8 – Service Templates



- About Service Templates
- Create a template from a service
- Create a service from a template
- Create dependencies between services


Module 9 – Service Sandbox



- Understanding the Service Sandbox
- Creating a file for Sandbox import
- Import a Service Sandbox
- Create dependencies between services
- Perform a Service Health Score simulation


Module 10 – Using Thresholds and Time Policies



- Understanding static thresholds
- Configure KPI thresholds
- Use aggregate and entity-level thresholds
- Apply time policies to thresholds
- Create custom threshold templates


Module – 11 Machine Learning and AI in ITSI



- Understanding ML/AI-assisted threshold types and algorithms
- Configure adaptive thresholds
- Configure AI Recommended thresholds
- Create a custom adaptive threshold template


Module 12 – Predictive Analytics



- Define predictive analytics
- Train a predictive model
- Configure predictive analytics for services
- Configure alerting for predicted Service Health Scores


Module 13 – Anomaly Detection



- Understanding anomaly detection
- Configure anomaly detection for KPIs
- Alerts for Deep Dives and Notable Event Episodes


Module 14 – Multi-KPI Alerts and Correlation Searches



- Define Multi-KPI alerts
- Create Multi-KPI alerts
- Understanding Correlation Searches
- Describing existing Correlation Searches
- Defining a Correlation Search


Module 15 – Notable Event Aggregation Policies



- Define aggregation policy capabilities
- Modify the default aggregation policy
- Create a custom aggregation policy
- Describe Action Rules
- Understand third-party integration</outline_plain><duration unit="d" days="0">18 hours</duration><pricelist><price country="US" currency="USD">2000.00</price><price country="GB" currency="GBP">1670.00</price><price country="PL" currency="USD">2000.00</price><price country="IT" currency="USD">2000.00</price><price country="DE" currency="EUR">2000.00</price><price country="CA" currency="CAD">2760.00</price><price country="CH" currency="CHF">2200.00</price></pricelist><miles><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="IT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue></miles></course>