Splunk ITSI explained: services, KPIs and health scores

9 min readUpdated October 1, 2026

Splunk IT Service Intelligence (ITSI) is Splunk's premium app for service monitoring: it turns searches into KPIs, rolls KPIs up into a health score per service, and groups the resulting alerts into episodes. This guide explains how ITSI works, what it costs to run, and how the same model looks on a lighter platform such as LogPulse Service Intelligence.

What Splunk ITSI is

ITSI is an app that runs on top of Splunk Enterprise or Splunk Cloud. It is licensed separately from the core platform, as a premium product. Where plain Splunk answers "what is in my logs?", ITSI answers "is my service healthy, and if not, which part is failing?". It does that with a handful of building blocks.

  • Services: a model of something you operate, such as checkout, payments or an internal API, often built from service templates and linked to entities (hosts, containers, devices).
  • KPIs: a scheduled search per metric, usually built on a shared KPI base search, with an aggregation such as error rate or p95 latency.
  • Thresholds: static, time-based (different per hour of the week) or adaptive, where ITSI learns the normal range from history.
  • Health score: a 0–100 score per service, a weighted combination of its KPIs plus the health of the services it depends on.
  • Service Analyzer, glass tables and deep dives: the views: a service tree, free-form visual dashboards, and swim-lane timelines for investigation.
  • Episodes: notable events grouped by aggregation policies, worked in Episode Review.

A KPI, from search to health

Everything in ITSI starts with a search. A typical error-rate KPI for a web service reads the access logs, counts the failed requests and divides by the total. ITSI runs that search on a schedule, compares the result with the thresholds and feeds the severity into the service health score.

StepSplunk ITSI (SPL)LogPulse (LPQL)
Base searchindex=web sourcetype=access_combinedindex=web sourcetype=access_combined
Aggregate| stats count(eval(status>=500)) as errors, count as total| stats count(eval(status>=500)) as errors, count as total
KPI value| eval error_rate=round(errors*100/total, 2)| eval error_rate=round(errors*100/total, 2)
ScheduleKPI search frequency (e.g. every 5 min)KPI schedule (e.g. every 5 min)
ThresholdStatic, time-based or adaptiveWarning and critical level plus a seasonal anomaly baseline

The query itself barely changes: LPQL uses the same pipe model as SPL, including count(eval(...)). The differences are in what happens around it.

What it takes to run ITSI

ITSI is powerful, and it is also one of the heavier things you can run on Splunk. Three costs come up again and again:

  • Licence: ITSI is a premium app on top of Splunk Enterprise or Cloud, so you pay for both. Splunk does not publish list prices; expect a sales conversation.
  • Search load: every KPI is a scheduled search. Hundreds of KPIs at a five-minute interval add up, and adaptive thresholds need history to train on.
  • Modelling effort: services, entities, templates, dependencies and aggregation policies have to be designed and kept current. Teams often need an ITSI specialist or a partner.

For a large enterprise already standardised on Splunk, that is often worth it. For a team that mainly wants "is our service healthy, and why not?", it is a lot of platform.

ITSI and LogPulse Service Intelligence side by side

LogPulse Service Intelligence follows the same idea (services, KPIs, health, dependencies) on a lighter, flat-priced platform. This is how the concepts map, including where LogPulse has no equivalent.

ConceptSplunk ITSILogPulse Service Intelligence
ServiceService, often from a template, with entity rulesService scoped by entity labels or by log source; members update automatically
KPIScheduled KPI search on a base searchLPQL query with a value field, run on a schedule; KPI templates included
ThresholdsStatic, time-based, adaptiveWarning and critical levels, with direction (above or below)
Learning normalAdaptive thresholds, anomaly detectionPer-KPI baseline with daily and weekly seasonality; feedback tunes it
HealthWeighted 0–100 health scoreWorst KPI wins: Healthy, Warning, Critical or Unknown
DependenciesService tree; health propagatesDependency graph per service
Reliability targetsBuilt around KPIs and healthSLOs with error budgets and burn-rate alerts
Change contextVia correlation searches and add-onsChange events (deploys, config) marked on KPI charts
Visual layerService Analyzer, glass tables, deep divesService overview, dashboards, Entity 360
Alert groupingEpisodes via aggregation policiesIncidents, but no aggregation-policy engine
AIPredictive analytics on health scoreAI Investigator and an MCP server, so coding agents can read service health and propose KPIs
PricingPremium app on top of SplunkIncluded in every plan, Free too, at a flat monthly price

What LogPulse does not have

No glass tables, no weighted health score (the worst KPI decides), no aggregation-policy engine like Episode Review, and no predictive health score. If your operations depend on those, ITSI is the better fit. If you mainly need services, KPIs, anomalies and SLOs without a Splunk estate underneath, LogPulse covers that.

Moving KPIs out of ITSI

1. Start with the services that page you

Export the services and KPIs that actually drive alerts. Many ITSI estates carry KPIs nobody looks at; migration is a good moment to drop them.

2. Translate the KPI searches

Because LPQL shares SPL's pipe syntax, most KPI base searches carry over with small changes. Macros and Splunk-specific commands need rewriting; the LPQL vs SPL guide lists the differences.

3. Recreate thresholds, then let baselines learn

Copy the static warning and critical levels first. LogPulse builds a seasonal baseline per KPI on its own, so adaptive thresholds do not need to be configured by hand.

4. Run both side by side

Send the same logs to both for a few weeks and compare what each one flags before switching alerting over.

Service Intelligence in LogPulse

Service Intelligence is part of every LogPulse plan, Free included, on the same engine as search and security monitoring. See the Service Intelligence overview, the documentation and the platform comparison.

Frequently asked questions

What is Splunk ITSI?
Splunk IT Service Intelligence (ITSI) is a premium app on top of Splunk Enterprise or Splunk Cloud for service monitoring. It models services, turns scheduled searches into KPIs, compares them with static, time-based or adaptive thresholds, rolls them up into a 0–100 health score per service, and groups alerts into episodes.
Is Splunk ITSI included in Splunk Enterprise?
No. ITSI is licensed separately as a premium app on top of Splunk Enterprise or Splunk Cloud. Splunk does not publish list prices for it.
What is a KPI base search in ITSI?
A KPI base search is a shared scheduled search that several KPIs build on. It reads the relevant events once, and each KPI aggregates a value from it, such as an error rate or p95 latency, at a fixed interval.
What is an alternative to Splunk ITSI?
Alternatives range from full observability suites to lighter service-monitoring tools. LogPulse Service Intelligence offers services, KPIs written in LPQL (a Splunk-like query language), seasonal anomaly baselines per KPI, dependency graphs and SLOs with burn-rate alerts, on every plan including Free. It has no glass tables, weighted health score, aggregation-policy engine or predictive health score.
Can I reuse my ITSI KPI searches?
Mostly. LPQL shares SPL’s pipe syntax, including stats with count(eval(...)), so most KPI base searches carry over with small changes. Splunk macros and commands without an LPQL equivalent need rewriting.

Logging and monitoring, on one EU-hosted engine

Centralise, retain and monitor your logs with AI-assisted search and a risk-based SIEM, GDPR-compliant and hosted in the EU. Start free.

Start free