Harbor Energy has a mature Splunk ITSI 4.20 deployment with service teams, KPI base searches, Event Analytics, and shared operational views. After a recent change, pipeline sensor data arrives late from one basin while central authentication remains green. The NOC sees symptoms in ITSI, but platform telemetry includes unrelated license warnings and a completed indexer rolling restart from the prior day. The admin must choose the action that addresses the ITSI maintenance handoff issue without masking the real signal.
Which action is most defensible?