ITSI Episode Analysis

Analyzing ITSI degraded service episodes with KPI correlation and prioritized action plans

ITSI Episode Analysis

The ITSI Episode Analysis workflow helps you investigate degraded service alerts. It correlates KPIs, identifies affected entities, and produces a prioritized action plan.


The Scenario

An ITSI (IT Service Intelligence) episode fires: a critical service is degraded. You need to understand what's wrong, which KPIs are affected, and what to fix first. Manually correlating entities and KPIs takes time. You want a structured analysis and action plan.

What the Workflow Does

The ITSI Episode Analysis workflow:

  • Identifies degraded services from episodes
  • Correlates KPIs and entities
  • Produces a prioritized action plan

Duration: 2–5 minutes | Complexity: Intermediate

Steps

  1. Open Workflows — Go to the Workflows section and select the ITSI Episode Analysis template.
  2. Select the episode — Provide the episode ID or let the workflow discover recent episodes.
  3. Run the workflow — The workflow connects to your Splunk and ITSI data via MCP.
  4. Review the output — You get an episode summary, affected services, KPI correlations, and a ranked list of recommended actions.

KPI Correlation

The workflow maps degraded services to underlying KPIs. You see which metrics drove the episode and how they relate to entities (hosts, applications, services). This reduces guesswork and speeds root cause analysis.

Prioritized Action Plan

Actions are ranked by impact and feasibility. You get a clear order of operations: fix the highest-impact items first, with suggested SPL or config changes where applicable.