A. Service access control requirements for ITSI Team Access should be considered, and appropriate teams provisioned prior to creating the ITSI Service.
B. Entities, entity meta-data, and entity rules should be planned carefully to support the service design and configuration.
C. Services, entities, and saved searches are stored in the ITSI app, while events created by KPI execution are stored in the itsi_summary index.
D. Backfill of a KPI should always be selected so historical data points can be used immediately and alerts based on that data can occur.
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/ImplementPerms