ITSI follows a modular architecture. The core components include: Services (logical groupings of KPIs), Entities (the physical or virtual infrastructure being monitored), KPIs (metrics derived from Splunk searches), and Glass Tables (real-time operational dashboards).
Data flows into ITSI through standard Splunk ingestion pipelines. Base searches run on a schedule to compute KPI values. These values feed into service health scores, which in turn power Glass Tables and Notable Event generation via aggregation policies.