Splunk IT Service Intelligence (ITSI) is Splunk's premium app for service monitoring: it turns searches into KPIs, rolls KPIs up into a health score per service, and groups the resulting alerts into episodes. This guide explains how ITSI works, what it costs to run, and how the same model looks on a lighter platform such as LogPulse Service Intelligence.
What Splunk ITSI is
ITSI is an app that runs on top of Splunk Enterprise or Splunk Cloud. It is licensed separately from the core platform, as a premium product. Where plain Splunk answers "what is in my logs?", ITSI answers "is my service healthy, and if not, which part is failing?". It does that with a handful of building blocks.
- Services: a model of something you operate, such as checkout, payments or an internal API, often built from service templates and linked to entities (hosts, containers, devices).
- KPIs: a scheduled search per metric, usually built on a shared KPI base search, with an aggregation such as error rate or p95 latency.
- Thresholds: static, time-based (different per hour of the week) or adaptive, where ITSI learns the normal range from history.
- Health score: a 0–100 score per service, a weighted combination of its KPIs plus the health of the services it depends on.
- Service Analyzer, glass tables and deep dives: the views: a service tree, free-form visual dashboards, and swim-lane timelines for investigation.
- Episodes: notable events grouped by aggregation policies, worked in Episode Review.
A KPI, from search to health
Everything in ITSI starts with a search. A typical error-rate KPI for a web service reads the access logs, counts the failed requests and divides by the total. ITSI runs that search on a schedule, compares the result with the thresholds and feeds the severity into the service health score.
| Step | Splunk ITSI (SPL) | LogPulse (LPQL) |
|---|---|---|
| Base search | index=web sourcetype=access_combined | index=web sourcetype=access_combined |
| Aggregate | | stats count(eval(status>=500)) as errors, count as total | | stats count(eval(status>=500)) as errors, count as total |
| KPI value | | eval error_rate=round(errors*100/total, 2) | | eval error_rate=round(errors*100/total, 2) |
| Schedule | KPI search frequency (e.g. every 5 min) | KPI schedule (e.g. every 5 min) |
| Threshold | Static, time-based or adaptive | Warning and critical level plus a seasonal anomaly baseline |
The query itself barely changes: LPQL uses the same pipe model as SPL, including count(eval(...)). The differences are in what happens around it.
What it takes to run ITSI
ITSI is powerful, and it is also one of the heavier things you can run on Splunk. Three costs come up again and again:
- Licence: ITSI is a premium app on top of Splunk Enterprise or Cloud, so you pay for both. Splunk does not publish list prices; expect a sales conversation.
- Search load: every KPI is a scheduled search. Hundreds of KPIs at a five-minute interval add up, and adaptive thresholds need history to train on.
- Modelling effort: services, entities, templates, dependencies and aggregation policies have to be designed and kept current. Teams often need an ITSI specialist or a partner.
For a large enterprise already standardised on Splunk, that is often worth it. For a team that mainly wants "is our service healthy, and why not?", it is a lot of platform.
ITSI and LogPulse Service Intelligence side by side
LogPulse Service Intelligence follows the same idea (services, KPIs, health, dependencies) on a lighter, flat-priced platform. This is how the concepts map, including where LogPulse has no equivalent.
| Concept | Splunk ITSI | LogPulse Service Intelligence |
|---|---|---|
| Service | Service, often from a template, with entity rules | Service scoped by entity labels or by log source; members update automatically |
| KPI | Scheduled KPI search on a base search | LPQL query with a value field, run on a schedule; KPI templates included |
| Thresholds | Static, time-based, adaptive | Warning and critical levels, with direction (above or below) |
| Learning normal | Adaptive thresholds, anomaly detection | Per-KPI baseline with daily and weekly seasonality; feedback tunes it |
| Health | Weighted 0–100 health score | Worst KPI wins: Healthy, Warning, Critical or Unknown |
| Dependencies | Service tree; health propagates | Dependency graph per service |
| Reliability targets | Built around KPIs and health | SLOs with error budgets and burn-rate alerts |
| Change context | Via correlation searches and add-ons | Change events (deploys, config) marked on KPI charts |
| Visual layer | Service Analyzer, glass tables, deep dives | Service overview, dashboards, Entity 360 |
| Alert grouping | Episodes via aggregation policies | Incidents, but no aggregation-policy engine |
| AI | Predictive analytics on health score | AI Investigator and an MCP server, so coding agents can read service health and propose KPIs |
| Pricing | Premium app on top of Splunk | Included in every plan, Free too, at a flat monthly price |
What LogPulse does not have
No glass tables, no weighted health score (the worst KPI decides), no aggregation-policy engine like Episode Review, and no predictive health score. If your operations depend on those, ITSI is the better fit. If you mainly need services, KPIs, anomalies and SLOs without a Splunk estate underneath, LogPulse covers that.
Moving KPIs out of ITSI
1. Start with the services that page you
Export the services and KPIs that actually drive alerts. Many ITSI estates carry KPIs nobody looks at; migration is a good moment to drop them.
2. Translate the KPI searches
Because LPQL shares SPL's pipe syntax, most KPI base searches carry over with small changes. Macros and Splunk-specific commands need rewriting; the LPQL vs SPL guide lists the differences.
3. Recreate thresholds, then let baselines learn
Copy the static warning and critical levels first. LogPulse builds a seasonal baseline per KPI on its own, so adaptive thresholds do not need to be configured by hand.
4. Run both side by side
Send the same logs to both for a few weeks and compare what each one flags before switching alerting over.
Service Intelligence in LogPulse
Service Intelligence is part of every LogPulse plan, Free included, on the same engine as search and security monitoring. See the Service Intelligence overview, the documentation and the platform comparison.