> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vortexiq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Splunk on Vortex IQ

> Monitor Splunk health, cost and reliability signals, and catch incidents and runaway spend early.

Monitor Splunk health, cost and reliability signals, and catch incidents and runaway spend early.

No changes are made without the configured approval policy. Read-only operations do not modify the connected system; schedules, access scopes, API usage and data handling remain governed by Vortex IQ controls.

[Connect or manage this source](https://app.vortexiq.ai/workbench/settings/sources) · [How connecting works](/integrations/connector-catalogue)

| **19**              | **4**            | **Build your own** | **Ready to build yours** | **10**         |
| ------------------- | ---------------- | ------------------ | ------------------------ | -------------- |
| performance signals | automated checks | automated fixes    | workflows                | API operations |

## Monitor performance

19 performance signals. Signals with an alert band can raise Nerve Centre alerts; every signal supports a merchant-configured watcher.

| Signal                              | Outcome                 | Alert behaviour              | What it tracks                                                                                           |
| ----------------------------------- | ----------------------- | ---------------------------- | -------------------------------------------------------------------------------------------------------- |
| **Revenue at Risk (services down)** | Protect revenue         | Merchant rule                | Live \$/min on fire while a commerce-path service is down or degraded - the COO's number, not the SRE's. |
| **Alerts Acknowledged**             | Run operations          | Watch only                   | Alerts a responder has acknowledged - distinguishes 'seen' from 'firing-but-ignored'.                    |
| **Alerts Firing**                   | Run operations          | Alert band 0 / 1             | Detectors currently in a firing state.                                                                   |
| **Apdex Score**                     | Customer experience     | Alert band 0.95 / 0.7        | Application performance index - satisfied/tolerating/frustrated request ratio.                           |
| **Avg Response Time**               | Customer experience     | Alert band 200 / 1000        | Mean APM service response time over the window.                                                          |
| **Error Rate**                      | Customer experience     | Alert band 0.5 / 2           | Share of requests returning errors across APM services, from SignalFlow over the chosen window.          |
| **Incidents Open**                  | Run operations          | Alert band 0 / 3             | Open On-Call incidents not yet resolved.                                                                 |
| **Incidents Resolved (24h)**        | Run operations          | Watch only                   | Incidents closed in the trailing 24 hours - throughput of the on-call rotation.                          |
| **Mean Time To Acknowledge**        | Run operations          | Alert band 300000 / 1800000  | Average time from incident trigger to first human acknowledgement.                                       |
| **Mean Time To Resolve**            | Run operations          | Alert band 1800000 / 3600000 | Average time from incident trigger to resolution - the headline reliability number.                      |
| **SLA Compliance**                  | Run operations          | Merchant rule                | Percentage of SLO targets met across the window.                                                         |
| **Services Degraded**               | Run operations          | Merchant rule                | Services in a degraded (warning) state - early-warning surface before full outage.                       |
| **Services Down**                   | Run operations          | Merchant rule                | Services reporting fully down - any non-zero value is an active outage.                                  |
| **Services Healthy**                | Run operations          | Watch only                   | Count of APM services reporting a healthy state.                                                         |
| **Throughput (req/min)**            | Customer experience     | Alert band 0 / -10           | Requests per minute across APM services - sustained drops flag capacity or outage.                       |
| **Top Alerting Services**           | Run operations          | Merchant rule                | Services ranked by alert volume - concentration on one service is the regression signal.                 |
| **Top Error Types**                 | Control risk and change | Watch only                   | Most frequent error classes across services - where to point remediation first.                          |
| **p95 Latency**                     | Customer experience     | Alert band 200 / 1000        | 95th-percentile service latency - the tail that customers feel.                                          |
| **p99 Latency**                     | Customer experience     | Alert band 200 / 1000        | 99th-percentile latency - worst-case experience for the slowest 1%.                                      |

## Audit risks and opportunities

A fix status appears only where the action, inputs, approval, verification and recovery controls are mapped. Candidate remediations are never executable.

| Check                                       | Severity | Outcome             | Why it matters                                                                                                                                                                                 | Fix status  |
| ------------------------------------------- | -------- | ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------- |
| **Error rate above 2%**                     | critical | Customer experience | More than 1 in 50 requests is failing right now. Depending on which endpoints are affected, this can mean pages failing to load, checkout steps failing silently, or background jobs dropping  | Report only |
| **Apdex score below 0.85**                  | high     | Customer experience | Apdex below 0.85 means a meaningful share of visits are experiencing the site as slow or frustrating rather than satisfying, using the same industry-standard scoring that tells you when perf | Report only |
| **Avg response time above 1500ms**          | medium   | Protect revenue     | Average response time over 1.5 seconds is well past the point where shoppers notice the delay, and slow response times are a documented driver of higher bounce and lower conversion; this is  | Report only |
| **Throughput dropped > 30% week-over-week** | medium   | Run operations      | Requests handled dropped more than 30% versus the prior week. This can mean genuinely lower traffic (worth knowing on its own) or it can mean the application is silently failing to serve req | Report only |

### Build your own automated fixes

4 checks report findings on Splunk today. Turn any finding into an automated fix with a Vortex IQ workflow: **13,885 read and write operations across 229 connectors** are available as building blocks, with approval, verification and rollback on every change.

## Automate approved work

Vortex IQ is integrated with **8 read** and **2 write** operations across alertmutings, apipublicincidents, apipublicincidentacks, apipublicreportingmetrics, apmservices, detectors on Splunk. Combine them with anything from the **13,885 operations across 229 connectors** to automate the work in your own words.

Changes follow the merchant's configured approval policy: the target, proposed change, affected records, risk, reversibility and verification plan are shown before execution. Read-only operations do not modify the connected system.

[Create a workflow](https://app.vortexiq.ai/workbench/flows/create?connector=splunk)

<Accordion title="Browse the operations you can build with">
  | Resource                  | Read operations | Write operations |
  | ------------------------- | --------------- | ---------------- |
  | alertmutings              | 1               | 0                |
  | apipublicincidents        | 1               | 0                |
  | apipublicincidentacks     | 0               | 1                |
  | apipublicreportingmetrics | 1               | 0                |
  | apmservices               | 1               | 0                |
  | detectors                 | 1               | 0                |
  | incidents                 | 1               | 0                |
  | organizations             | 1               | 0                |

  Signed-in users see the full catalogue in the workflow builder, filtered to the sources they have connected.
</Accordion>

### Ready to build your first Splunk workflow

Pick a trigger, add the operations above as steps, and every step that changes data pauses for your approval. Monitoring and audits are live now and can start any workflow you build.

***

*Generated from the connector capability graph. Counts reflect the servable registry after alias normalisation and de-duplication, and refresh automatically when the registry changes.*
