ITSI provides a platform to turn your never-ending stream of app and infrastructure data into manageable KPIs that you can act on, but how do you manage the number of events ITSI detects? What if you need to extend ITSI with additional capabilities in order to merge your alerts with your support team's response processes? We will turn ITSI up to 11 by adding the concept of "platforms" as a collection of related services, support reoccurring maintenance windows, and generate rich alerts that include information such as which entities are impacted and what the KPI values are. These concepts are combined so that all the problems in your platform generate a single alert with alert text rich enough that that your support teams can respond without opening ITSI, and we will do it all with just SPL.
Slides PDF link - https://conf.splunk.com/files/2019/slides/IT2184.pdf?podcast=1576909575