Splunk® IT Service Intelligence

Release Notes

This documentation does not apply to the most recent version of Splunk® IT Service Intelligence. For documentation on the most recent version, go to the latest release.

Known issues in Splunk IT Service Intelligence

This version of IT Service Intelligence (ITSI) has the following known issues and workarounds. If no issues appear here, no issues have yet been reported.

Backup/Restore and Migration Issues

Date filed Issue number Description
2024-01-25 ITSI-34174 kvstore full backup missing json data files

Workaround:
To increase the limit to fetch the number of rows per query, need to add following parameters inTemplate:$SPLUNK HOME/etc/apps/SA-ITOA/local/limits.conf

{noformat}[kvstore] max_rows_per_query = <unsigned integer>{noformat}

2022-12-08 ITSI-27621 "include conf setting" in ITSI restore overwrites and does not seem to merge conf settings

Notable Events

Date filed Issue number Description
2023-06-29 ITSI-31192 All Events tab does not render default columns if they are not present in NEAP JSON definition

Workaround:
# Use the latest ITSI Backup file to edit the NEAP JSON definition and remove the property Template:All events columns and restore the backup.
  1. Go to Episode Review page and add back all the desired columns

Glass Table

Date filed Issue number Description
2022-12-21 ITSI-27763 Assigning an ad-hoc search as a datasource to the empty viz, breaks the entire glass table page

KPI Search Calculation

Date filed Issue number Description
2023-08-17 ITSI-31761 KPI preview fails to render - issue still occurring after upgrade to ITSI 4.15.2

Role Based Access Controls

Date filed Issue number Description
2023-05-04 ITSI-30017 A user in itoa_user role cannot open ITSI homeview in SHC.

Workaround:
We have to add the list_search_head_clustering capability to the default authorize.conf.

Service Analyzer

Date filed Issue number Description
2023-06-09 ITSI-30822 ITSI degraded-entities-search-manager may have caused indexers cluster to crash

Workaround:
If Service Analyser is running for more than 1 week's time range and search is going through millions of events try to limit the service analyser time range to less than 1 week to limit the search time range.
2023-06-07 ITSI-30580 When the dbconnect app is installed, non-admin ITSI users cannot access their homepage but are routed to the upgrade page.

Workaround:
Add the db_connect_read_app_conf capability to the custom user with a non-admin role. Enable this capability in the default authorize.conf file.

Uncategorized issues

Date filed Issue number Description
2024-01-23 ITSI-34041 ITSI Episode view triggers a search to populate linked tickets, that is looking back to epoch time=1 second till now
2023-08-02 ITSI-31555, ITSI-31464 the ITSI integration create SNOW tickets with SPL instead of INC prefix when using Episode Action with custom endpoints with ServiceNow_TA version 7.6.0

Workaround:
Until bug in service now ADDON 7.6 bug (ADDON-64098 & ADDON-63502 ) are resolved, to avoid the issue, in ITSI, do not specify a custom endpoint in the action setup, keep the field empty.
2023-05-10 ITSI-30068 Event Analytics Monitoring Rules Engine Information panel uses an All time search

Workaround:
  • Edit the Event Analytics Monitoring Dashboard.
  • Click on the magnifying glass under the Rules Engine Information panel.
  • Change the Time Range to Shared Time Picker (time_token).

  • 2022-12-20 ITSI-27741 When closing episodes in bulk, episodes with different statuses display as closed but aren't actually closed.

    Workaround:
    During the bulk update of the episodes from the UI, make sure that all the Episodes selected for the bulk update at a time have same Status.
    Last modified on 25 June, 2024
    Fixed issues in Splunk IT Service Intelligence   Removed features in Splunk IT Service Intelligence

    This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.15.2


    Was this topic useful?







    You must be logged into splunk.com in order to post comments. Log in now.

    Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

    0 out of 1000 Characters