Splunk® IT Service Intelligence

Release Notes

This documentation does not apply to the most recent version of Splunk® IT Service Intelligence. For documentation on the most recent version, go to the latest release.

Known issues in Splunk IT Service Intelligence

This version of IT Service Intelligence (ITSI) has the following known issues and workarounds.

Backup/Restore and Migration Issues

Date filed Issue number Description
2025-05-05 ITSI-40007 Restore fails with Resource not found from itsi_sandbox.py

Entities

Date filed Issue number Description
2024-04-11 ITSI-35019, ITSI-35068, ITSI-39692 Entity dashboard page re-renders when the entity sidebar is closed or opened.

Notable Events

Date filed Issue number Description
2025-04-30 ITSI-39966 The new itsi_nats_metrics index in ITSI 4.20.0 is hard-coded and cannot be configured
2025-03-07 ITSI-39378 Unable to navigate to 2nd page of episode comments in EA

Service Analyzer

Date filed Issue number Description
2025-03-26 ITSI-39630, ITSI-39751 Entity side panel does not display unit alongside values until the page is reloaded

Uncategorized issues

Date filed Issue number Description
2025-05-07 ITSI-40021, ITSI-37891 ds_sources is not getting updated when the aliases get updated
2025-04-15 ITSI-39794 After upgrade to 4.20 - Severity fields are not picked up intermittently
2025-03-26 ITSI-39629 Episode Grouping stops when Event IQ is enabled
2025-03-26 ITSI-39628 Itoa_admin/sc_admin users are unable to run fix or start new precheck from ITSI upgrade readiness page in v4.20
2025-03-25 ITSI-39580 Episodes views json getting corrupted and too large

Workaround:
see manual json clean up in [1]
2025-03-17 ITSI-39488 ITSI Episode review activity tab Activity : "open in search". drilldown search uses"alltime"
2025-03-13 ITSI-39470 NEAP config page save puts the config page in unsaved state when time based action rules are configured.
2025-03-11 ITSI-39405 Unable to save Episode using save as option in ITSI 4.20.0

Workaround:
N/A
2025-03-11 ITSI-39406 Episode Review result list display does always not match the last filter.

Workaround:
There is a race condition between the populating jobs triggered each time a filter is modified. To view results from the last filter, wait for previous jobs to complete before updating the filter.
2025-03-10 ITSI-39387 Periodic Backfill for Same Events after 4.20 Upgrade
2025-03-07 ITSI-39383 Some times the events count in the header do not match with the count in the events table under the episode detail view
2025-03-05 ITSI-39324 Deployed integrations in an ITSI backup are not being restored in the data_integration collection. Deployed integrations don't display in the UI, but saved searches for the integrations are saved.
2025-02-14 ITSI-39098 Glasstables slower to load on 4.19.2, after ITSI upgrade from 4.17
2025-02-12 ITSI-39083 Admin user is able to edit and delete the out-of-the-box dashboards in Entity Types.
2025-01-07 ITSI-38650 Near constant time series in a time block leads to wrong thresholding levels in preview chart

Workaround:
In rare scenarios an adaptive thresholding recommendation could result in some time policies where the KPI values are near constant. This results in the standard deviation to be 0 or near 0. As a result when adaptive thresholding is applied some of the thresholds levels could map to the same KPI value. This can cause thresholds levels to be rendered in the incorrect order in the preview chart. As workaround the affected time policies can be manually updated by setting the policy type to Static and adjusting the threshold level so that they are associated with different values.
2024-12-05 ITSI-38265, ITSI-38212 For Entity which is marked as retireable , policy name is shown as unknown
2024-11-08 ITSI-37950 500 Internal Server Error appears in ITSI due to python libraries versions conflicts with other apps.

Workaround:
This issue is caused by the caching of incorrect or outdated files. A user with the itoa_admin, power, or admin role can run the following command to manually clear the outdated files:

| itsipyccleaner

Additionally, try upgrading third-party applications to the latest version to avoid caching of incorrect or outdated files.

2024-10-18 ITSI-37708 ITSI 4.19.* throwing python errors / warnings on Splunk 9.2.* "PkgResourcesDeprecationWarning: unknown is an invalid version and will not be supported in a future release"
2021-09-01 ITSI-18709 ITSI redirects to suite_redirect 500 Internal Server Error - because of python library isolation between apps

Workaround:
Step 1: Identify all the splunklib directories within the splunk apps directory using command find . -name 'splunklib' | xargs -r ls -lah.

Step 2: For each directory listed in step 1, check if file six.py is present.

Step 3: Copy the six.py from an existing splunklib directory into all the missing directories.

Step 4: Clean the cached files using find . -name "*.pyc" -delete

Step 5: Restart Splunk on the ITE Work or ITSI search head.

2019-05-30 ITSI-3322 If you add a correlation search in ITSI which contains a sub-search returning into an eval, you get a message "Invalid search string: This search cannot be parsed when parse_only is set to true."

Workaround:
You can't use a sub-search returning into an eval in a correlation search. As a workaround, create and save a basic correlation search with all of the information you want outside of the search. Then as an admin user, go to Settings > Searches, reports, and alerts and open the correlation search you just created. Add the sub-search you were trying to add there.
Last modified on 18 June, 2025
Fixed issues in Splunk IT Service Intelligence   Removed features in Splunk IT Service Intelligence

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.20.0


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters