Splunk® IT Service Intelligence

Release Notes

New features in Splunk IT Service Intelligence

This version has these new and changed features.

Service Insights

New feature or enhancement Description
KPI drift detection Proactively identify when KPIs change incrementally or suddenly over time (for example, increasing latency over months) and remediate potential issues. Drift detection allows you to prevent performance issues in your environment and ensure your KPIs report accurate values. For more information, see Monitor KPI data drift in ITSI.
Entity normalization Efficiently review and take action to remediate duplicate entity issues. View duplicate entities in the Configuration issues detected section on the ITSI Configuration Assistant, and follow the remediation steps to remove duplicates. For more information, see Inspect entity configuration issues.
Scaled adaptive thresholding You can now apply adaptive thresholding for up to 100,000 KPIs, supporting larger environments. Adaptive thresholding uses machine learning to dynamically adjust thresholds levels of KPI based on the historical behavior of the KPI. For more information, see Create adaptive KPI thresholds in ITSI.
Service analyzer enhancements Several enhancements were implemented to improve user experience for the service analyzer, including improved error toast notifications, and an update that prevents unnecessary searches from running after an automatic refresh on inactive browser tabs.

Event Analytics

New feature or enhancement Description
Simplified alert onboarding You can now onboard alert and event data from external monitoring tools into ITSI with a guided workflow, and quickly get started with event monitoring. For more information, see Ingest and normalize third-party alerts into ITSI.
New data integrations As part of the alert onboarding process, you can now onboard alerts from several third-party tools. For more information, see Available data integrations in ITSI.
Rules Engine queue mode The Rules Engine now runs by default with a queue processing system that efficiently processes notable events and prevents latency. For more information, see Rules Engine queue mode.

Backup and Restore

New feature or enhancement Description
Backup and restore enhancements You can now include the following objects to your partial or full backup files in ITSI: entity types, service analyzers, and saved episode reviews. Additionally, prevent errors during the restoration process by receiving alerts when missing dependencies are not included in your backup file. For more information, see Create a full backup of ITSI.

Data integrations

New feature or enhancement Description
Content Pack for AppDynamics Use the content pack to integrate Cisco AppDynamics services with ITSI to dynamically correlate application and infrastructure data with databases. This integration enhances visibility and helps teams quickly find problems and troubleshoot in-context. For more information, see About the Content Pack for Splunk AppDynamics.
Content Pack for ThousandEyes Use the content pack to monitor and troubleshoot Cisco ThousandEyes tests in IT Service Intelligence (ITSI). Use the content pack to create ITSI services and entities from Cisco ThousandEyes tests and monitor them for performance management and service health analysis. For more information, see About the Content Pack for Cisco ThousandEyes.
Azure cloud deployment support ITSI now supports cloud deployment on Azure.
ITSI support for IPv6 Splunk Enterprise Security supports IPv6 from version Splunk Enterprise Security version 8.0 and higher, and for cloud deployments. The support for IPv6 is offered as Dual Stack networking with IPv6 fallback to IPv4 addresses. During Early Access releases, Splunk products might have limitations on customer access, features, maturity, and regional availability. For additional information on Early Access, contact Splunk Support. For more information on how to implement the IPv6 early access feature, see Enable IPv6 dual-stack functionality in the Splunk Enterprise Admin manual.

Dashboards

New feature or enhancement Description
NATS Monitoring Dashboard Monitor the performance of the Rules Engine when it runs in queue mode, and troubleshoot specific performance issues. For more information, see NATS Monitoring Dashboard.
Last modified on 27 February, 2025
  Fixed issues in Splunk IT Service Intelligence

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.20.0


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters