What is our primary use case?
We use ITSI mainly for IT Infrastructure Operations Monitoring. The service model health scores allow us to identify when KPIs are starting to impact our services and to proactively manage our environments. To date, we have leveraged this data within Splunk to enable alerting so that we can solve incidents in real-time, but we are growing into our usage of the ITSI model for predictive modeling of our environment. Our infrastructure includes commodity hardware, mid-range, mainframe, on-premise data center, and cloud offerings. (Please note that these views are my personal opinions and not those of my employer)
How has it helped my organization?
The modeling required to setup ITSI has been very helpful in providing us a better understanding and a logical view of our services. The modeling is flexible and can be as granular or high level as our needs dictate. This flexibility also means that you need to gather a detailed understanding of your services, processes, and applications in order to build a useful model. ITSI is allowing us to more quickly identify what services are impacted by underlying infrastructure concerns.
What is most valuable?
The health scores and glass tables are extremely valuable and useful. These provide flexible visibility options to convey the meaning of the big data analysis being performed by Splunk behind the scenes. Glass tables allow you to create graphical displays that convey critical meaning with a simple clean look and feel. The deep dive also provides the ability to dig into metrics and KPIs, which are useful to isolate the time frame involved and that should be focused on. Once in the deep dive, you can quickly identify the first KPI or metric to impact the health score and focus your efforts on it.
What needs improvement?
ITSI could benefit from a security model that would allow operations team members to get involved in model building, KPI implementation, and model maintenance while maintaining appropriate segregation of duties. To date, all of our ITSI development is being done by our Splunk Admins, while our KPIs and much of the modeling work are managed by our Splunk developers. Future development of templates and ready to use add-ons could facilitate faster time to value, as many IT infra and even Packaged Application data models are consistent across organizations and could be plugged in easily.
For how long have I used the solution?
I have been using Splunk ITSI for two years.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
It is extremely scalable, and can have high data storage costs.
How are customer service and technical support?
Customer service has been very responsive to our needs.
Which solution did I use previously and why did I switch?
No, we did not replace another solution with ITSI. We used it to enhance existing solutions.
How was the initial setup?
The initial setup was fairly straightforward, but we had help from Splunk professional services.
What about the implementation team?
We had help from Splunk professional services. They were extremely knowledgeable.
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
I was not involved in the evaluation for ITSI.
What other advice do I have?
This is a powerful solution requiring configuration to meet your needs.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)