Use Cloud Connect with Splunk IT Service Intelligence

For Splunk IT Service Intelligence (ITSI), Cloud Connect provides a standard way to enable cloud-connected features introduced with ITSI 5.0, including AI-assisted capabilities that help teams onboard alerts, correlate events, and investigate episodes while continuing to work from their Splunk Enterprise and ITSI workflows.

Supported ITSI capabilities

  • AI field extraction for alert onboarding: Normalizes incoming alert data into the format required by ITSI.

  • Event iQ Detect: Analyzes alert data and recommends grouping fields and correlation strategies.

  • Event iQ Diagnose: Analyzes alert data and Splunk logs to identify likely episode root cause and provide next-step recommendations. It can include change context from tools such as ServiceNow and Jira when that context is available.

Availability and requirements

  • Cloud Connect support for ITSI is available with the Splunk IT Service Intelligence 5.0 release. ITSI supports Cloud Connect 1.1.0 or later.

  • Cloud Connect is intended for current and new ITSI customers running self-managed Splunk Enterprise.

  • Cloud Connect is available for Splunk Enterprise 9.4 and later, subject to the supported Splunk Enterprise support window.

  • Use the latest available Cloud Connect app when setting up, connecting, and enabling ITSI capabilities.

How Cloud Connect fits into an ITSI deployment

Cloud Connect provides a common administrative workflow for setup, activation, and management. After Cloud Connect is configured on a supported search head, administrators can activate eligible ITSI extensions through the Cloud Connect app or through the ITSI user interface, depending on the available workflow and administrator preference.

This approach reduces the need for separate connection patterns for each cloud-connected capability and provides a consistent place to manage supported extensions.

Before you begin

  • Confirm that your Splunk Enterprise deployment, ITSI version, and Cloud Connect app version are supported.

  • Review the ITSI documentation for prerequisites, supported regions, data handling details, and any extension-specific requirements.

  • Ensure that an administrator with the required permissions is available to complete the connection and activation workflow.

Set up Cloud Connect for ITSI

  1. Download or upgrade to the latest Cloud Connect app from Splunkbase.

  2. Open the Cloud Connect app and enter the required region, preferred tenant name, and contact information.
    Set up Cloud Connnect
  3. Link the Splunk Enterprise environment using the one-time password flow.
    Cloud Connect OTP
    After you submit the one-time passcode, Cloud Connect provisions the connection and cloud resources. This can take up to two minutes.
    Cloud Connect establishing connection
  4. Activate ITSI in the Cloud Connect app or from the ITSI user interface, if that option is available in your deployment.
    Cloud Connect overview
  5. Validate that the enabled ITSI capabilities are available and functioning as expected.

Operational considerations

  • Licensing: Cloud Connect-supported ITSI capabilities are included with existing ITSI license subscriptions at no additional cost, where supported.

  • Version currency: Keep Splunk Enterprise, ITSI, and Cloud Connect within supported versions to maintain access to cloud-connected capabilities.

  • Change management: Treat activation as a production change. Review prerequisites, communicate the change window, and validate core ITSI workflows after activation.

  • Data handling: Review documentation for what data is used by each capability and how regional or product-specific requirements apply to your environment.

Next steps