Overview of enrichment policies in ITSI
Enrichment policies in Splunk IT Service Intelligence enrich your alert data to improve incident resolution. These policies add meaningful metadata and contextual information—such as service topology, entity details, CMDB CI information, and maintenance windows—to your raw alerts, facilitating faster incident detection.
Enrichment policies leverage data from Configuration Management Databases (CMDBs) such as ServiceNow, asset management tools, and dynamic service topologies.
Create an enrichment policy
Before you create an enrichment policy, ensure your data is properly configured and formatted for ingestion into Splunk ITSI.
-
On the Data Integrations page, select Enrichment policies.
-
Select Create mapping.
-
Add a name and description to your policy.
-
Specify the data source. Specify an existing lookup search, or use a new lookup by selecting a CSV file that will be parsed and imported to make lookup selections. Select Next.
-
In the Match field section, select one or more fields to map against the event fields, and populate the enriched fields if a match is identified.
-
In the Fields to add to events section, specify the additional metadata to add to the source field. Preview the enriched fields in the preview panel.
-
Select Next to confirm your settings.
-
Select Save to save the policy.
Apply enrichment policies to your data
You can apply your new enrichment policy to an existing data integration in ITSI.
-
On the Data Integrations page, select one of the data integrations.
-
From the Configure alert enrichment collapsible section, select your enrichment policy in the Source dropdown.
-
(Optional) Apply the Default CMDB Enrichment Policy to your data integration. This enrichment policy enriches notable events with additional fields that includes information about external configuration items, including CI relationships. Before applying the policy, ensure that your CMDB has been integrated using a Splunk Technology Add-on or another supported integration method.
-
From the Match fields field, select a notable event field to enrich with the additional metadata specified by the Match field from your enrichment policy. These additional enrichment fields can include information such as the count, maintenance windows, and other context that provide more detail to your alerts. If a match is found, more fields will be added to your alerts.
Manage Default CMDB Enrichment Policy
Navigate to the Advanced configuration page and select Managing CMDB integration to configure settings, such as frequency of search runs, and the relevant CI fields to use.
View enriched alerts in Episode Review
You can view the additional data added to your alerts on the Episode Review dashboard. Select the Events Timeline tab to view event changes or outages.
ITSI categorizes incoming data into distinct event types to process and enrich notable events effectively:
- Monitoring alerts: Standard alerts generated by your monitoring tools.
- Change events: Records of changes to your IT infrastructure (for example, ITSM change requests).
- Maintenance windows (outages): Scheduled downtime or known outages for services and KPIs.
- Service/KPI alerts: ITSI alerts generated by service health degradation or KPI threshold changes.
Backup and restore for enrichment policies
Enrichment policies are only available as part of a full backup. Enable the include .conf files to include these policies. Any lookup definitions can be also included if include dependencies flag is enabled. CSV lookups or collections data from the lookup definition are not included, and are considered missing dependencies that require manual download and installation.