ITSI Episode Analysis
Analyzing ITSI degraded service episodes with KPI correlation and prioritized action plans
ITSI Episode Analysis
The ITSI Episode Analysis workflow helps you investigate degraded service alerts. It correlates KPIs, identifies affected entities, and produces a prioritized action plan.
Navigation
- Parent: Use Cases
- Related: Workflow Templates | Running Workflows
The Scenario
An ITSI (IT Service Intelligence) episode fires: a critical service is degraded. You need to understand what's wrong, which KPIs are affected, and what to fix first. Manually correlating entities and KPIs takes time. You want a structured analysis and action plan.
What the Workflow Does
The ITSI Episode Analysis workflow:
- Identifies degraded services from episodes
- Correlates KPIs and entities
- Produces a prioritized action plan
Duration: 2–5 minutes | Complexity: Intermediate
Steps
- Open Workflows — Go to the Workflows section and select the ITSI Episode Analysis template.
- Select the episode — Provide the episode ID or let the workflow discover recent episodes.
- Run the workflow — The workflow connects to your Splunk and ITSI data via MCP.
- Review the output — You get an episode summary, affected services, KPI correlations, and a ranked list of recommended actions.
KPI Correlation
The workflow maps degraded services to underlying KPIs. You see which metrics drove the episode and how they relate to entities (hosts, applications, services). This reduces guesswork and speeds root cause analysis.
Prioritized Action Plan
Actions are ranked by impact and feasibility. You get a clear order of operations: fix the highest-impact items first, with suggested SPL or config changes where applicable.