demo-SA-IndexCreation app icon

demo-SA-IndexCreation

Creates and configures custom summary indexes for ITSI deployments, including indexes for KPI summaries, metrics, notable events, anomaly detection, and infrastructure monitoring data.

splunk product badge

Latest Version 4.21.1
May 20, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.4, 10.3, 10.2, 9.5, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 8.x, 6.x, 5.x, 4.x, 3.x
Rating

0

(0)

Log in to rate this app
Support
demo-SA-IndexCreation support icon
Developer Supported app
Ranking

#2

in Generic
The demo-SA-IndexCreation add-on creates and configures custom summary indexes required for IT Service Intelligence (ITSI) deployments. This add-on provisions specialized indexes for storing KPI summaries, metric data, notable events, anomaly detection results, and infrastructure monitoring telemetry. It handles data from multiple sources including ITSI-native event types, AWS CloudWatch metrics, Windows Performance Monitor counters, and Kubernetes cluster objects. The add-on defines indexes with appropriate retention policies and data types to support ITSI's analytics workflows, including the itsi_summary index for aggregated KPI data, itsi_summary_metrics for time-series metrics, itsi_tracked_alerts for alert correlation, and itsi_im_metrics for infrastructure health data. By pre-creating these indexes across the indexer tier, the add-on ensures that ITSI can immediately begin ingesting and analyzing service-level data without encountering missing index errors. The add-on supports a wide range of performance and monitoring source types, including Windows performance counters for CPU, memory, disk, network, system processes, Active Directory, DFS replication, and DNS services, as well as container orchestration data from Kubernetes pods and nodes.

Categories

Generic

Created By

Przemyslaw Teodorski

Type

app

Downloads

13

Resources

Log in to report this app listing