New features in the Splunk App for Content Packs
The Splunk App for Content Packs version 2.0.0 was released on July 13, 2023.
Version 2.0.0 of the Splunk App for Content Packs contains updates in these content packs:
|New feature or enhancement||Description|
|Deactivated the saved searches of all content packs||Saved searches are deactivated by default on upgrade and install of Splunk App for Content Packs 2.0 to avoid negative impact on ITSI performance and to provide more control for users to enable saved searches only for in-use content packs To activate the saved searches, refer to the Install and Configure documentation of the required content pack.
|Mapping for the
||Automatic lookup responsible for returning the service_name field for the itsi_summary index is removed when users upgrade to Splunk App for Content Packs 2.0.0. This change to service name field mapping protocol in Service and Episode Monitoring Correlation Searches improves data reliability by eliminating the previous requirement for refreshing automatic lookup periodically to ensure that the service_name field populated for all records in the itsi_summary index.|
If you rely on the service_name field, this change affects you.
To obtain the
index=itsi_summary | lookup service_kpi_lookup _key AS serviceid OUTPUT title AS service_name | search service_name="*Web*"
You must incorporate the lookup command into your own SPL queries to obtain the service_name field.
|Updated content packs||This version of the Splunk App for Content Packs contains updates to the following content packs:
For fixed issues, see Fixed issues for the Splunk App for Content Packs.
For known issues, see Known issues for the Splunk App for Content Packs.
To get started with the app, see Install the Splunk App for Content Packs.
Fixed issues in the Splunk App for Content Packs
This documentation applies to the following versions of Splunk® App for Content Packs: 2.0.0