ITSI has its own correlation search framework separate from Enterprise Security. These searches run against the itsi_summary index (where KPI data is written) and generate Notable Events when conditions are met. They can detect complex multi-service patterns like "3 infrastructure services degraded simultaneously."
Unlike simple threshold alerts, ITSI correlation searches can evaluate cross-service conditions, time-over-time comparisons, and statistical anomalies. They are configured in the Event Analytics section and can trigger aggregation policies, create episodes, and execute actions.