Create teams in ITSI
Implement teams in IT Service Intelligence (ITSI) to restrict service-level and episode-level information to only the departments or organizations that need access to it. Teams empower domain experts in different areas within an organization to create and monitor the services and episodes that pertain to their department.
Prerequisites
- See Overview of teams in ITSI to determine whether you need to implement teams for your organization.
- Plan out what teams you need to create in ITSI. You can create teams for technology areas or for different departments within your organization. Create a team for every area that needs a separate view of ITSI service-level data or that needs to be administered independently within ITSI.
High-level steps
- Create team admin roles to administer each team and assign users to those roles.
- Create custom analyst and user roles for each team.
- Create teams and assign read/write permissions to the team admin roles you created.
- Create services within teams.
- (Optional) Sharing episodes with other teams using Notable Event Aggregation Policies (NEAPs).
Step 1: Create roles to administer your teams
After you determine the teams you are going to create in ITSI, create roles to administer the services in each team.
- Create a role in the Splunk platform for each ITSI team admin.
- Configure the roles to inherit from the
itoa_team_adminrole in order to obtain the appropriate capabilities. - Assign users to each team admin role you created.
For example, the Splunk administrator creates an itoa_finance_admin role that inherits from the itoa_team_admin role for the administrator of the Finance team. The Splunk admin then assigns the Finance team administrator to the itoa_finance_admin role.
Splunk Cloud Platform administrators need to request Splunk Support to create the custom roles needed for teams.
For information about the itoa_team_admin role's capabilities, see Configure users and roles in ITSI. For information about creating custom roles, see About configuring role-based user access.
Step 2: Create custom roles within each team
Create custom roles for the ITSI analysts and users in each team. For example, create an itoa_finance_analyst role that inherits from the itoa_analyst role for the analysts in the Finance department. Create an itoa_finance_user role that inherits from the itoa_user role for the users in the Finance department. You can then assign permissions to the Finance team without allowing access to analysts and users from other departments.
Step 3: Create teams
Create teams to group services by department, organization, or type of service and control access to the services.
Prerequisites
- You must have the
itoa_adminrole to create a team. - Before you create a team, you must create the team admin role that will administer the team so that you can assign permissions to the role when creating the team. See Implement teams in ITSI for information.
Steps
- Click Configuration > Teams.
- Click Create Team.
- Provide a team name and description. Duplicate team names are allowed, but be aware of other team names and use naming conventions to avoid confusion.
- Assign read or write access to the listed roles as appropriate. The
itoa_adminrole has read/write permissions by default. If a role has write permissions for a team, a user with this role can create and modify services in the team. The user can't delete a service in the team unless the role has the delete capability for a service. - Click Create.
itoa_team_admin role. If you are logged in using the itoa_admin role, rather than the admin role, also make sure that the itoa_admin role inherits from the custom team admin role and any other custom roles you have created.
Open a team to see the services that belong to it or to review or change team permissions.
Step 4: Create services within each team
Step 5: Sharing episodes with other teams using NEAPs
Episode Granular Permissions is enabled by default from ITSI 5.0. It controls access to episodes generated by notable event aggregation policies (NEAPs) through an owner team and shared teams. After an upgrade to ITSI 5.0, the owner team for all existing NEAPs is set to Global. Review the owner team for each NEAP and update it as needed.
Prerequisites and important considerations
- Episode Granular Permissions is enabled by default in ITSI 5.0. If it is deactivated, the legacy role-based
Actions → Edit Permissionsoption is shown. - NEAP access is controlled through an owner team and shared teams.
- Shared teams receive read-only access.
- Team-based permissions restrict episode visibility and support team-scoped episode actions.
-
You can assign non-Global owner teams and shared teams to individual NEAPs as needed.
-
Configuring owner and shared teams does not require a separate data migration or KV Store modification.
Steps
-
From the ITSI menu, select .
-
Open the NEAP that you want to configure. To edit a NEAP, a user must be a member of the NEAP owner team, have write permission for that team, and have the
write_itsi_notable_aggregation_policycapability. -
Open Filtering Criteria and Instructions.
-
Expand Aggregation Policy and Episode Permission.
-
Select the owner team. After an upgrade to ITSI 5.0, the owner team for all existing NEAPs is set to Global. This assignment does not by itself give every user permission to edit the NEAP. The NEAP owner team is not the same as the individual owner assigned to an episode in Episode Review.
-
Select any shared teams. Shared teams have read-only access and cannot edit the NEAP.
-
Click Save.
Known Limitations
Filtering Criteria and Instructions > Aggregation Policy & Episode Permissions. Do not use the service-sharing Edit Permissions workflow for NEAP permissions.
-
Bulk editing team permissions for multiple NEAPs is not available; configure permissions in each NEAP policy.
-
Reassign associated NEAPs before deleting a team.
-
Bulk sharing of NEAPs is not available.
-
Changing the owner team can reset the episode assignee and action-rule assignees to
Unassigned; review these fields after changing the owner team.