ITSI and Enterprise Security (ES) can share a Splunk deployment, enabling powerful cross-domain correlation. When a security incident in ES affects an IT service monitored by ITSI, operators can see both the security context and the service impact simultaneously.
Integration points include shared entities (the same server appears in both ITSI and ES asset lists), Notable Event correlation (an ES security alert triggers an ITSI service degradation), and unified dashboards that combine security posture with service health. The IT Operations team sees service impact while the SOC sees the security context.