Splunk IT Service Intelligence Certified Admin Preparation Details
The Splunk IT Service Intelligence Certified Admin exam validates your ability to install, configure, and administer Splunk ITSI for real-time service monitoring and event analytics. This guide maps every blueprint objective to official Splunk documentation covering glass tables, deep dives, notable events, and KPI thresholds. You can also explore more Splunk certification study guides on the Splunk Certification to keep building your skills.
Splunk IT Service Intelligence Certified Admin Materials
| Coursera | Learn to Analyze Data with Splunk Fundamentals |
| Udemy | Splunk IT Service Intelligence From the Ground Up |
| Whizlabs | Splunk Basics |
1.0 Introducing ITSI 5%
Topics Covered
1.1 Identify what ITSI does
About Splunk IT Service Intelligence
Splunk IT Service Intelligence
Overview of Service Insights in ITSI
1.2 Describe reasons for using ITSI
About administering IT Service Intelligence
Overview of Service Insights in ITSI
1.3 Examine the ITSI user interface
About administering IT Service Intelligence
Overview of the glass table editor in ITSI
Overview of deep dives in ITSI
2.0 Glass Tables 5%
Topics Covered
2.1 Describe glass tables
Overview of the glass table editor in ITSI
Getting Started With Splunk ITSI Glass Tables
Overview of Service Insights in ITSI
2.2 Use glass tables
Overview of the glass table editor in ITSI
Tutorial: Build a glass table to monitor your infrastructure
Configure the layout of glass tables in ITSI
2.3 Design glass tables
Configure the layout of glass tables in ITSI
Install and configure the Content Pack for Example Glass Tables
Glass table reference for the Content Pack for Example Glass Tables
2.4 Configure glass tables
Overview of the glass table editor in ITSI
Configure the layout of glass tables in ITSI
Install and configure the Content Pack for Example Glass Tables
3.0 Managing Notable Events 10%
Topics Covered
3.1 Define key notable events terms and their relationships
Overview of notable events in ITSI
Overview of Event Analytics in ITSI
Overview of Episode Review in ITSI
3.2 Describe examples of multi-KPI alerts
Create multi-KPI alerts in ITSI
Building multi-KPI alerts in Splunk ITSI
Overview of correlation searches in ITSI
3.3 Describe the notable events workflow
Overview of Event Analytics in ITSI
Generate events with correlation searches in ITSI
Overview of notable events in ITSI
3.4 Work with notable events
Take action on an episode in ITSI
3.5 Custom views
Customize Episode Review in ITSI
Modify analyst permissions within Episode Review in ITSI
Overview of Episode Review in ITSI
4.0 Investigating Issues with Deep Dives 10%
Topics Covered
4.1 Describe deep dive concepts and their relationships
Overview of deep dives in ITSI
Configure deep dive lanes in ITSI
Add entity and anomaly overlays to a deep dive in ITSI
4.2 Use default deep dives
Overview of deep dives in ITSI
Configure deep dive lanes in ITSI
Monitor your services with the ITSI Service Analyzer
4.3 Create and customize new custom deep dives
Overview of deep dives in ITSI
Configure deep dive lanes in ITSI
Add entity and anomaly overlays to a deep dive in ITSI
4.4 Add and configure swim lanes
Configure deep dive lanes in ITSI
Add entity and anomaly overlays to a deep dive in ITSI
Overview of deep dives in ITSI
4.5 Describe effective workflows for troubleshooting
Monitor your services with the ITSI Service Analyzer
Overview of deep dives in ITSI
Analyze entity performance metrics in ITSI
5.0 Installing and Configuring ITSI 10%
Topics Covered
5.1 List ITSI hardware recommendations
Before you upgrade IT Service Intelligence
5.2 Describe ITSI deployment options
Install IT Service Intelligence in a search head cluster environment
5.3 Identify ITSI components
About Splunk IT Service Intelligence
5.4 Describe the installation procedure
Install IT Service Intelligence in a search head cluster environment
Before you upgrade IT Service Intelligence
5.5 Identify data input options for ITSI
What is an entity integration?
Import entities from a search in ITSI
Import entities from a CSV file in ITSI
5.6 Add custom data to an ITSI deployment
Overview of creating custom content packs in ITSI
Import entities from a search in ITSI
Import entities from a CSV file in ITSI
6.0 Designing Services 5%
Topics Covered
6.1 Given customer requirements, plan an ITSI implementation
Overview of creating services in ITSI
Overview of Service Insights in ITSI
6.2 Identify site entities
What is an entity integration?
Import entities from a search in ITSI
Define entity rules for a service in ITSI
7.0 Data Audit and Base Searches 5%
Topics Covered
7.1 Use a data audit to identify service key performance indicators
Use the ITSI Configuration Assistant
Monitor KPI data drift in ITSI
Overview of creating KPIs in ITSI
7.2 Design base searches
Create KPI base searches in ITSI
Define a KPI source search in ITSI
Split and filter a KPI by entities in ITSI
8.0 Implementing Services 5%
Topics Covered
8.1 Use a service design to implement services in ITSI
Overview of creating services in ITSI
Create a service from a service template in ITSI
Add service dependencies in ITSI
Define entity rules for a service in ITSI
9.0 Thresholds and Time Policies 5%
Topics Covered
9.1 Create KPIs with static and adaptive thresholds
Create time-based static KPI thresholds in ITSI
Create adaptive KPI thresholds in ITSI
Configure KPI thresholds in ITSI
9.2 Use time policies to define flexible thresholds
Create time-based static KPI thresholds in ITSI
Create adaptive KPI thresholds in ITSI
10.0 Entities and Modules 5%
Topics Covered
10.1 Importing entities
Import entities from a search in ITSI
Import entities from a CSV file in ITSI
What is an entity integration?
10.2 Using entities in KPI searches
Split and filter a KPI by entities in ITSI
Define entity rules for a service in ITSI
Generate pseudo entities in ITSI
10.3 Using modules
Overview of creating custom content packs in ITSI
What is an entity integration?
11.0 Templates and Dependencies 5%
Topics Covered
11.1 Use templates to manage services
Overview of service templates in ITSI
Create a service from a service template in ITSI
11.2 Define dependencies between services
Add service dependencies in ITSI
Overview of creating services in ITSI
12.0 Anomaly Detection 5%
Topics Covered
12.1 Enable anomaly detection
Apply anomaly detection to a KPI in ITSI
Add entity and anomaly overlays to a deep dive in ITSI
12.2 Work with generated anomaly events
Apply anomaly detection to a KPI in ITSI
Add entity and anomaly overlays to a deep dive in ITSI
Overview of Episode Review in ITSI
13.0 Correlation and Multi KPI Searches 5%
Topics Covered
13.1 Define new correlation searches
Overview of correlation searches in ITSI
Generate events with correlation searches in ITSI
13.2 Define multi KPI alerts
Create multi-KPI alerts in ITSI
Building multi-KPI alerts in Splunk ITSI
13.3 Manage notable event storage
ITSI metrics summary index reference
Overview of notable events in ITSI
14.0 Aggregation Policies 5%
Topics Covered
14.1 Create new aggregation policies
Overview of aggregation policies in ITSI
About the default aggregation policy in ITSI
14.2 Use smart mode
Group similar events with Smart Mode in ITSI
Overview of aggregation policies in ITSI
15.0 Access Control 5%
Topics Covered
15.1 Configure user access control
Configure users and roles in ITSI
15.2 Create service level teams
16.0 Troubleshooting ITSI 10%
Topics Covered
16.1 Backup and restore
Restore a full or partial backup of ITSI
Troubleshoot ITSI backups and restores
16.2 Maintenance mode
Schedule maintenance downtime in ITSI
Overview of maintenance windows in ITSI
16.3 Creating modules
Overview of creating custom content packs in ITSI
What is an entity integration?
16.4 Troubleshooting
Use the ITSI Health Check dashboard
Troubleshoot ITSI backups and restores
Use the ITSI Configuration Assistant
Wrapping Up Splunk IT Service Intelligence Certified Admin
This guide walked through every domain of the Splunk IT Service Intelligence Certified Admin blueprint, from glass tables and deep dives to correlation searches and aggregation policies. Working through the linked Splunk documentation for each objective builds the hands-on ITSI admin skills the exam expects. You can also explore more Splunk certification study guides on the Splunk Certification to keep building your skills. Have a question or tip? Leave a comment below.
Receive Updates on Splunk IT Service Intelligence Certified Admin Exam
Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.