What data sources does agentic ITOps use
Agentic IT operations have arrived. It’s no longer a question of if enterprise IT departments will adopt agentic ITOps, but how quickly. The question we hear most often at BigPanda isn’t “what are agentic ITOps,” it’s “what data do we actually need to get started?” That’s the right question to ask. Agentic AI is only as good as the data and context that feeds it.
Real-time observability and telemetry data from machines.
Structured ITSM and workflow records.

Unstructured, tacit knowledge that is buried in chat threads, call transcripts, and documentation.
Traditional AIOps and rules-based automation could only process clean, structured inputs. Agentic AI offers transformational capabilities by reasoning across messy, scattered enterprise data to glean the operational context that AI agents need to detect, diagnose, and resolve incidents with minimal human intervention.
This is critical because your organizational data is the single biggest factor determining whether agentic ITOps succeeds or stalls in your enterprise. Agentic AI is only as good as the data and context it can access. Get the foundation wrong, and you end up with agents that are error-prone and hallucinate. Get it right, and you unlock AI agents that resolve incidents at machine speed while getting smarter and more effective over time.
The good news is that all the data you need already exists inside your enterprise, and none of it needs to be cleaned before you start. This article breaks down the data sources that power agentic ITOps, and how the BigPanda IT Knowledge Graph unifies them into a living model of your IT environment.
Your enterprise’s data is the foundation of agentic ITOps
The shift from AIOps to agentic ITOps is, at its core, a shift in what data AI can use to detect, respond to, and remediate incidents and outages.
Traditional AIOps platforms delivered real value through noise reduction, event correlation, and faster triage. Still, they relied on structured data housed in a configuration management database (CMDB) and processed through rule-based systems. That architecture placed a hard ceiling on what traditional AIOps could accomplish. Rules could only act on data that fit a schema. This meant the vast majority of your organization’s operational knowledge, which contains the context that actually resolves incidents, remained invisible to automation.
“There are $250 billion worth of manual ITOps workflows ripe for intelligent automation,” said Assaf Resnick, CEO of BigPanda. “With agentic ITOps, we’re helping enterprises move beyond manual, slow incident management toward intelligent systems that free up talent and reduce operating costs.”
Unlocking that $250 billion opportunity requires AI that can work with data as it actually exists in the enterprise: fragmented, siloed, half-structured, and scattered across dozens of tools. That’s precisely what agentic AI delivers. The knowledge required to resolve most incidents already exists inside your enterprise, locked away in incident records, change logs, post-mortems, chat threads, and the heads of your most experienced engineers. Rules-based automation couldn’t touch any of that information. Agentic ITOps can.
Let’s look at each category of data that feeds agentic IT operations.
Data source #1: Observability and telemetry data
The first pillar of agentic ITOps is real-time machine data that describes what’s happening in your environment right now. This is the data layer most enterprises already invest in heavily, and it includes:

Metrics and traces:
CPU load, memory utilization, latency, error rates, and application performance traces collected through frameworks like OpenTelemetry and Prometheus. These signals tell AI agents that something is degrading and where it is.

Machine logs:
System, application, and security event logs streaming continuously from every layer of the stack. Logs provide the granular evidence agents use to move from symptoms to probable causes.

Topology and infrastructure events:
Real-time state changes across network paths, cloud services, and container clusters. As environments become more dynamic and ephemeral, this live topology data matters far more than any static inventory.

External dependency signals:
Third-party provider incidents, internet and power outages, and even social media reports — real-world events that traditional monitoring never sees but that frequently explain what your internal telemetry cannot.
Here’s the uncomfortable truth about this category. Enterprises are spending more on observability and monitoring tools than ever and, but they are still missing incidents. Despite a 20% year-over-year increase in spending on observability and ITSM tools, incident detection remains poor. End-users, not system telemetry, still report 65% of all incidents.
Observability data alone lacks context. A spike in error rates means little without knowing what changed, who owns the service, how a similar incident was resolved last quarter, and whether a maintenance window is currently open. That context lives in the next two data categories, and this is where agentic ITOps separates itself from traditional AIOps.
Data source #2: ITSM and workflow records
The second pillar is the structured and semi-structured record of how your organization operates: the tickets, changes, and configuration data that flow through your ITSM platforms every day. Key sources include:

Incident tickets:
Historical post-mortems, active ticket narratives, and resolution notes. Historical incident data provides context on classification, priority, duration, assignments, and closure codes from comparable incidents — dramatically accelerating investigations. When an AI agent recognizes that tonight’s database alert matches a pattern that has been resolved 14 times before, triage that once took an hour happens in seconds.

Change management logs:
Scheduled maintenance windows, deployment records, and configuration modifications. Changes remain the single biggest driver of IT outages, which makes change data one of the highest-value inputs for agentic ITOps. By correlating incidents with recent changes, AI agents can automatically flag high-risk changes before they go live and pinpoint root cause of change-related issues in minutes.

Knowledge bases and runbooks:
The documented procedures, known-error records, and remediation steps stored inside ITSM platforms, which give agents evidence-based next steps rather than guesses.

Configuration databases:
Asset inventories and CMDBs still contribute, but agentic ITOps handles them very differently from older AIOps tools.
That last point deserves emphasis, because it’s where AI in ITOps has fundamentally changed.
The CMDB becomes one input among many, not the foundation of your operations
For years, the assumption was that automation required perfect data. Teams were expected to clean the CMDB, normalize every source, and get the foundation “right” before doing anything else. That multi-year data project became the reason automation stalled, and why the $250 billion problem of manual ITOps workflows never got solved. A CMDB was sold as a complete, up-to-date map of every service and component in the environment. In practice, it rarely is.
“We’ve reached peak frustration with getting your ITOps or ITSM teams all the fragmented, siloed CIs into a CMDB,” said Jason Walker, Chief Innovation Officer at BigPanda. “Agentic AI can ingest and index all the valuable, unstructured data from your organization and convert it into data that can be leveraged to improve your operations.”
This is the shift agentic AI makes possible. Instead of treating data quality as the gatekeeper, it treats data quality as an output. AI can observe patterns, infer relationships, and fill in gaps through daily operations. Every incident it touches strengthens the knowledge layer underneath it. The CMDB becomes one input among many, rather than the single source of truth on which everything else depends.
Data source #3: Unstructured and tacit knowledge data
The third pillar is the one that legacy AIOps could never access, and it’s arguably the most valuable. The richest operational knowledge in any enterprise isn’t in a database at all. It’s in the conversations, recordings, and documents where your teams actually work.

Every dot on this picture represents organizational knowledge that’s relevant to your environment. The orange dots are documented knowledge, including CMDB, service maps, architecture diagrams, runbooks, change logs, service desk tickets, postmortems, and on-call systems. In other words, this is knowledge your organization has already captured in some system.
But that’s only half the picture. The purple icons represent something different, and arguably more valuable: the organizational knowledge that never gets written down. This is information such as who your team actually calls when a certain service goes down, even if the CMDB says someone else owns it. Or the workaround that fixed the exact same issue months ago, and was never turned into a runbook. This information doesn’t live in any system; it lives in people’s heads, built up through experience.
The problem is that all of this data is fragmented and scattered across tools and teams. The documented knowledge is buried across dozens of disconnected tools. Organizational knowledge is scattered among dozens of people, and it walks out the door every time someone leaves your company or a team relocates. And when a live incident is happening, and your teams need this information in seconds, you’re lucky if you find the right information at all.
This rich, tacit data holds the keys to transforming ITOps and ITSM. Agentic ITOps eliminates the need for structured data and rules, opening the floodgates to these unstructured sources and providing unprecedented understanding and visibility. Enterprises can finally harness the vital information buried in chat histories, call transcripts, and ITSM logs to detect, respond to, and prevent incidents at machine speed.
Just as importantly, this data category solves the expertise-drain problem that every IT leader knows too well. When your most experienced engineer retires or changes teams, their knowledge no longer walks out the door with them. Agentic ITOps captures it, indexes it, and makes it available to every responder and AI agent thereafter.
How the BigPanda IT Knowledge Graph brings it all together
Each of these data sources is useful on its own. Unified, they become transformative. That unified view of your entire environment is exactly what the BigPanda IT Knowledge Graph delivers.
The IT Knowledge Graph is the real-time intelligence engine powering agentic ITOps on the BigPanda platform. It continuously ingests and connects data previously buried in fragmented systems and silos across the enterprise, including observability telemetry, ITSM records, change logs, chat threads, transcripts, and documentation. This data is used to build an intelligent, living model of your IT environment.

All the data in the image above falls into four types: topological (how things connect), organizational (who owns what), historical (what happened before), and situational (what’s happening now). The BigPanda IT Knowledge Graph uniquely unifies all four. Unlike a CMDB, which decays the moment it’s published, the IT Knowledge Graph strengthens through use. Every alert it correlates, every incident it investigates, and every resolution it observes deepens its understanding of how your services relate, which teams own what, which changes carry risk, and which fixes actually work. Data quality stops being a prerequisite you have to satisfy and becomes a byproduct of daily operations.
Designed to enable an AI-first data strategy, the IT Knowledge Graph allows your enterprise to evolve from reactive IT operations to proactive, agentic AI-powered decisions. It’s the connective tissue that enables AI agents to perform contextual, cross-domain correlation across all structured and unstructured data. This is also the foundation for advanced capabilities such as AI Detection and Response, AI Incident Prevention, and the AI Incident Assistant.
Get started by connecting data in phases and tying agentic ITOps to operational goals
If the list of data sources above feels daunting, just remember that you don’t need to connect every source on day one, and you don’t need to clean your data first. BigPanda is designed to work with messy, incomplete, and scattered inputs and to get smarter through daily use.
The enterprises moving fastest with agentic ITOps are the ones that adopt a phased approach that is tied to specific operational goals, such as:
- Accelerate incident detection and response. Start by ingesting observability, service desk, and external dependency data. Teams move from patchy, delayed visibility into alerts to a complete, contextualized view of incidents as they unfold — improving first-contact resolution and preventing disruptive, expensive escalations.
- Reduce the volume and risk of change-related incidents. Next, connect ITSM data — ticket history, change records, and the CMDB — so that high-risk changes are flagged automatically before they go live, without first building complex integrations across dozens of tools.
- Augment IT experts with AI assistance. Then bring in ITSM, on-call, and chat tool data to give incident commanders, SREs, and L2/L3 engineers instant access to institutional knowledge that once lived only in someone’s memory — reducing bridge calls and unnecessary escalations.
Each phase builds on the last, feeding a continuously evolving knowledge base rather than requiring a single, all-or-nothing data migration. Value arrives with the first phase and compounds with each subsequent phase. To help you get started, BigPanda released our new ebook, Laying the data foundation for agentic ITOps: A strategic guide for enterprise IT leaders. Get your copy today to learn how your organization can lay the data foundation for agentic, AI-powered ITOps that reduce mean time to resolution (MTTR), lower L1 spend, prevent escalations, and improve SLAs and uptime.
5 key takeaways from this blog
- Three data categories power agentic IT operations. Agentic ITOps runs on real-time observability and telemetry data, structured ITSM and workflow records, and unstructured tacit knowledge from chat threads, call transcripts, runbooks, and documentation.
- Telemetry alone isn’t enough. Despite a 20% year-over-year increase in observability and ITSM spend, end users still report 65% of incidents. Machine data needs the context of ITSM records and human knowledge to drive detection and resolution at machine speed.
- Unstructured data is the breakthrough that separates agentic ITOps from AIOps. Traditional AIOps and rules-based automation could only process structured, CMDB-housed data. Agentic AI unlocks the tacit knowledge in chat histories, war-room transcripts, and post-mortems.
- Your messy data is an asset, not a blocker. There’s no need for a multi-year cleanup project before starting. Agentic AI works with fragmented, incomplete, siloed data as-is, treating data quality as an output that improves with every incident rather than a prerequisite that stalls adoption.
- The BigPanda IT Knowledge Graph turns fragmented data into a living foundation. By continuously ingesting and connecting siloed systems and data sources, it builds an intelligent, real-time model of your IT environment that gets smarter with use — powering the shift from reactive operations to proactive, agentic AI-driven decisions.