Splunk® IT Essentials Work

Overview of Splunk IT Essentials Work

Acrobat logo Download manual as PDF

Splunk IT Essentials Work version 4.9.0 isn't available for download.
This documentation does not apply to the most recent version of ITEWork. Click here for the latest version.
Acrobat logo Download topic as PDF

Overview of Splunk IT Essentials Work

Splunk IT Essentials Work is a free app that helps you get started monitoring and analyzing your IT infrastructure. The app provides data integrations and investigation tools for operating systems, virtual infrastructures, and containers. IT Essentials Work comprises the Entity Integrations functionality of Splunk IT Service Intelligence (ITSI), including default entity integrations, entity types, and entity dashboards. For more information, see the Overview of entity integrations in ITSI topic in the Entity Integrations manual.

In IT Essentials Work, an entity represents an IT component that requires management to deliver an IT service. Entities are usually hosts, but can also be items such as cloud or virtual resources, network devices, or applications. IT Essentials Work helps you correlate logs and metrics for each entity, and then use that information to observe and understand the performance of your entities.

IT Essentials Work is available both for cloud and on-premises users.

IT Essentials Work features

IT Essentials Work gives you access to the default entity integrations including *nix, Windows, and VMware. After you import your entities, you can view and monitor your entity types on the Infrastructure Overview page. Drill down further into individual entities to analyze associated log data and track performance metrics.

Note: If you are a ITSI user, you have access to all of these features with your premium ITSI license.

Feature Resources
Entity integrations
Infrastructure Overview About the Infrastructure Overview in ITSI
Entity dashboards
Alerts Overview of Alerts in IT Essentials Work
Splunk App for Content Packs You can install the Splunk App for Content Packs along with IT Essentials work to get access to out-of-the-box content that you can use to quickly set up your IT Essentials Work environment. See a list of the content packs available in IT Essentials Work in the Overview of content packs topic.

You have to first install the Splunk App for Content Packs to access the Data Integrations page where the content packs are installed. For more information, see Install the Splunk App for Content Packs.


The version number for this release of IT Essentials Work is 4.9.0 which corresponds with the latest version of Splunk IT Service Intelligence (ITSI).

Upgrade from IT Essentials Work to ITSI

If you upgrade to ITSI from IT Essentials Work by installing a premium license on an on-premises instance, it might take up to 10 minutes to enable the premium license and access premium ITSI features. If your premium license and features aren't enabled, restart Splunk. For more information, go to the ITSI license requirements in the Install and Upgrade manual.

If your ITSI license expires, there is a grace period of 90 days before premium ITSI features are disabled. Once the grace period ends, you need to install an updated ITSI license to access premium features again.

Note: The product reverts to IT Essentials Work when the ITSI license expires. Your notable events, KPIs, and glass table data are preserved, however, you won't be able to access these knowledge objects until you upload a new ITSI license or renew the ITSI license.

IT Essentials Work and ITSI aren't supported on the Splunk Free license. To learn more about Splunk Free, see About Splunk Free.

IT Essentials Work and Splunk App for Infrastructure

As of version 4.9, the Splunk App for Infrastructure (SAI) is no longer packaged with IT Essentials Work. To continue using your SAI entities, enable entity discovery saved searches in IT Essentials Work. For more information, see ITSI entity discovery searches.

Last modified on 01 September, 2021
Install IT Essentials Work

This documentation applies to the following versions of Splunk® IT Essentials Work: 1.0.0, 4.9.0

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters