Known issues in Splunk IT Service Intelligence
This version of IT Service Intelligence (ITSI) has the following known issues and workarounds.
Predictive Analytics
Date filed | Issue number | Description |
---|---|---|
2024-08-06 | ITSI-36922 | Updates to the Machine Learning Toolkit and the Splunk Python for Scientific Computing affect ITSI predictive analytics. Workaround:
|
Adaptive Thresholding
Date filed | Issue number | Description |
---|---|---|
2024-09-04 | ITSI-37270 | Use Recommended Thresholding Configuration cannot use all backfilled events Workaround: While backfilling the KPI customer can set the fill data gaps option other than Template:Last available value and after backfill completes successfully they can switch the option to Template:Last available value. |
Notable Events
Date filed | Issue number | Description |
---|---|---|
2024-12-12 | ITSI-38413 | Events from two sources get backfilled multiple times, causing them to be indexed into itsi_grouped_alerts after an hour delay. Workaround: Change the order so that the bidirectional event conditional comes before the time-based conditional. Rules engine will not group any events into a group that has an action conditional in this order: a time based conditional, then a bidirectional event conditional. For example, creating a rule like "If an episode existed for 300 seconds and a specific event occurs in ServiceNow, then do X" would not work. |
2024-11-07 | ITSI-37939 | The preview for a notable event aggregation policy doesn't display results, without error message Workaround: Reduce the number of notable events sampled, by changing the macro *neap_preview_event_limit* (change from default is 10000 to 1000) |
Notable Event Aggregation Policies
Date filed | Issue number | Description |
---|---|---|
2024-12-12 | ITSI-38413 | Events from two sources get backfilled multiple times, causing them to be indexed into itsi_grouped_alerts after an hour delay. Workaround: Change the order so that the bidirectional event conditional comes before the time-based conditional. Rules engine will not group any events into a group that has an action conditional in this order: a time based conditional, then a bidirectional event conditional. For example, creating a rule like "If an episode existed for 300 seconds and a specific event occurs in ServiceNow, then do X" would not work. |
2024-11-07 | ITSI-37939 | The preview for a notable event aggregation policy doesn't display results, without error message Workaround: Reduce the number of notable events sampled, by changing the macro *neap_preview_event_limit* (change from default is 10000 to 1000) |
Glass Table
Date filed | Issue number | Description |
---|---|---|
2024-08-20 | ITSI-37082, ITSI-37083 | Duplicate search job running while opening/reloading glass table, causing slowness. Workaround: Upgrade to fixed version (4.19.3 or 4.20.*) |
Performance
Date filed | Issue number | Description |
---|---|---|
2024-07-23 | ITSI-36787, ITSI-31548 | App SA-ITSI-AT-Recommendations and SA-ITSI-DriftDetection failing Python3 readiness check Workaround: Check next major release for fix. |
Service Analyzer
Date filed | Issue number | Description |
---|---|---|
2025-01-10 | ITSI-38711 | Dispatch search jobs with 'itsi' as app param rather than 'search' default value |
2025-01-07 | ITSI-38647 | Add service analyzer search timeout value to itsi_service_analyzer.conf file. |
2024-12-20 | ITSI-38565 | Service analyzer page shows error modals for some searches automatically cancelled after 65 seconds. Workaround: N/A |
2023-01-12 | ITSI-28014 | On Splunk Enterprise SH Cluster, Drill-down link on Service is not functional for ITSI Dev Build Workaround: # Workaround from the UI (easier and recommended):
|
Service Definition
Date filed | Issue number | Description |
---|---|---|
2024-09-10 | ITSI-37299 | Discrepancy in the "Per-Entity Threshold Value" graph |
Predictive Analytics
Date filed | Issue number | Description |
---|---|---|
2025-01-12 | ITSI-38715 | Predictive analysis Dashboard's cause analysis tab is not showing R2 results |
Uncategorized issues
Date filed | Issue number | Description |
---|---|---|
2024-12-19 | ITSI-38545 | Upgrade Readiness Dashboard - failing to fix "Incorrect service linked to entity" and "Dependent services missing" Workaround: Fix in coming ITSI 4.20 |
2024-12-13 | ITSI-38442 | Error for non itoa_admin users when loading the KPI base searches lister page |
2024-11-12 | ITSI-37977 | The list of saved episodes fails to load, and displays a kvstore memory limit error. |
2024-10-18 | ITSI-37708 | ITSI 4.19.* throwing python errors / warnings on Splunk 9.2.* "PkgResourcesDeprecationWarning: unknown is an invalid version and will not be supported in a future release" |
2024-07-22 | ITSI-36739 | Panel shows incorrect results in dashboards : "ITSI Health Check" , "Event Analytics Monitoring" Workaround: # Find the list of SHs from Settings -> Search Head Clustering
For example : host_list Definition -> {{host IN (<list of hosts comma separated >)}} Example -> Template:Host IN (host1, host2, host3)
Example -> Template:Index= internal `host list`
|
2024-04-24 | ITSI-35347 | After upgrading ITSI, the navigation bar does not reflect the latest updates. Workaround: The Splunk navigation bar is cached in local storage, and updates to the navigation bar should appear in 24 hours. You can manually update the cache by following these steps:
|
2021-09-01 | ITSI-18709 | ITSI redirects to suite_redirect 500 Internal Server Error - because of python library isolation between apps Workaround: Step 1: Identify all the splunklib directories within the splunk apps directory using command find . -name 'splunklib' | xargs -r ls -lah .
Step 2: For each directory listed in step 1, check if file Step 3: Copy the Step 4: Clean the cached files using Step 5: Restart Splunk on the ITE Work or ITSI search head. |
Fixed issues in Splunk IT Service Intelligence | Removed features in Splunk IT Service Intelligence |
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.19.1
Feedback submitted, thanks!