Splunk® IT Service Intelligence

Release Notes

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of ITSI. Click here for the latest version.
Acrobat logo Download topic as PDF

Known issues in Splunk IT Service Intelligence

IT Service Intelligence (ITSI) version 4.10.0 has the following known issues and workarounds.

Splunk platform issues that impact ITSI compatibility

Date filed Issue number Description
2019-02-14 SPL-155648
  • ITSI Event Analytics is incompatible with Splunk Enterprise version 7.2.0 - 7.2.3.
  • On versions 7.2.4 - 7.2.10, Event Analytics might duplicate events. To work around this issue, create a limits.conf file on all search heads at $SPLUNK_HOME/etc/apps/SA-ITOA/local/ and add the following stanza:
[search]
phased_execution_mode = auto
  • If you do not plan on using ITSI's Event Analytics functionality, the above does not apply.

See Splunk Enterprise system requirement in the Install and Upgrade Splunk IT Service Intelligence manual.

Adaptive Thresholding

Date filed Issue number Description
2021-07-28 ITSI-17991 AdaptiveThresholding: KPI calculated thresholdValues get overwritten

Bulk Import

Date filed Issue number Description
2021-07-22 ITSI-17897 Bulk Import Entity from csv file not able to display the column name if its in non-english characters

Workaround:
Changing the column name to english works. Attached CSV which works
2021-07-03 ITSI-17628, ITSI-17629, ITSI-17947 Entity Import: User with itoa_admin role is unable to save recurring import
2021-06-09 ITSI-17178 Some ITSI Import Objects saved searches fail to merge entities with the host field and may create duplicate entities.

Workaround:
#Disable ITSI Import Objects - VMware VM.
  1. Copy the ITSI Import Objects - VMware VM saved search, but change the entity_merge_field attribute to host.
  1. Enable the updated ITSI Import Objects - VMware VM search.

Notable Events

Date filed Issue number Description
2021-09-13 ITSI-18828 Alerts and Episodes unable to search by field key/value
2021-01-21 ITSI-13167 On Safari, there is a 10 to 15 second delay when editing a Notable Event Aggregation Policy using the ServiceNow action.

Glass Table

Date filed Issue number Description
2021-07-16 ITSI-17853 Changing a KPI widget from a single value visualization to a single value radial visualization causes the KPI ID to appear instead of the alert value.

Service Analyzer

Date filed Issue number Description
2021-08-05 ITSI-18101 Service Analyzer Entity Panel always shows N/A after selecting a KPI that is N/A

Predictive Analytics

Date filed Issue number Description
2021-07-16 ITSI-17856 Security warning in Predictive Analytics search - fit command

Uncategorized issues

Date filed Issue number Description
2021-10-04 ITSI-19103, ITSI-19699 Data Integration UI is not showing all content pack chiclets
2021-09-22 ITSI-18967, ITSI-19697 Content Pack upgrade fails as already installed ITSI objects are not shown as "Already Present" in Content Pack UI during upgrade scenario for CP present in Content library
2021-09-15 ITSI-18876 Multi word entity titles in Entity Rules are broken in 4.10.x upon import....
2021-09-09 ITSI-18800 When you add ITSI instances as search peers to another Splunk instance, the peers might be disabled after 72 hours. This is because the ITSI licenses are flagged as duplicates on the search peers.
2021-08-16 ITSI-18364 The last updated version for ITSI should be 4.7.0 instead of 4.6.0.
2021-08-03 ITSI-18066 ITE-Work throws errors after upgrade for "The Rules Engine will continue restarting until the upgrade has completed." - Disable itsi_event_grouping for ITE Work and enable it when customer upgrades to ITSI
2021-07-29 ITSI-18031 Could not enable Bidirectional Ticketing correlation search
2021-07-22 ITSI-17898 Hide / Show dashboard button behavior is not working properly when creating Episode Review views.
2021-07-22 ITSI-17901 After installing IT Essentials Work, receive an error of ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\Python3.exe"
2021-07-13 ITSI-17752 Telemetry search results do not show up on the telemetry instance
2021-06-14 ITSI-17255 Backend: Filtering alerts by entity title or entity id will retrieve alerts for an entity even when there is no alert configured for that type
2021-06-14 ITSI-17254 Alerts severity filter on entity overview should filter by entity id/key instead of title
2021-05-25 ITSI-16870, ITSI-17181 Entity page doesn't load when IT Essentials Work is installed on search head cluster
2021-03-16 ITSI-14805 ITSI Refresher feature is dead - error message shown for ITSI: Unable to initialize modular input...itsi_refresher

All ITSI Modules

Publication date Issue number Description
2017-03-21 ITOA-7585 When you bulk add services and an error caused by the racing condition occurs, the incorrect message "itsi_module does not exist" is displayed.
2017-03-07 MOD-979 KPIs do not have consistent backfill settings across all modules.
2017-01-17 MOD-452 The Analyze KPI button on the Service Details page is broken.
2017-01-17 MOD-402 The Export to PDF option does not work in the drilldown to a module.
2017-01-17 MOD-296 The extendable tab XML generator REST endpoint is located in DA-ITSI-OS instead of in common components where it can be used by all modules.
2017-01-17 MOD-591 ITSI displays a misleading error message when a KPI template contains a field that cannot be resolved.
2017-01-17 MOD-498 There is no upper limit to the number of characters a KPI title or description can contain. Long strings can negatively affect performance.
2017-01-17 MOD-309 The Gruntfile.js included in ITSI modules uses double quotes instead of single quotes, which does not conform to the standard for all JavaScript files.
2017-04-17 MOD-2002 When you drilldown from the Events tab, an "Invalid earliest_time" error occurs.


Workaround:
Disable drilldown from the Events tab.

2017-01-17 MOD-439 Some modules do not have descriptions for saved searches.

Application Server Module

Publication date Issue number Description
2017-01-27 MOD-492 If you reuse the same panel within a dashboard, the duplicate panel does not display any event data.

Cloud Services Module

There are no known issues for this release.

Database Module

Publication date Issue number Description
2017-01-17 MOD-586 When a lookup is not configured for TA-Microsoft-SqlServer, ITSI displays a misleading error message on the server drilldown page.

End User Experience Module

There are no known issues for this release.

Load Balancer Module

Publication date Issue number Description
2017-01-27 MOD-492 If you reuse the same panel within a dashboard, the duplicate panel does not display any event data.

Operating System Module

Publication date Issue number Description
2017-04-13 MOD-555 The Storage Free Space % base search runs every minute while the Linux df command runs every 5 minutes. This causes data gaps.
2017-04-10 MOD-1964 Windows data for memory free space is collected at different intervals than the Memory Free % KPI.
2017-01-17 MOD-1398 Line, stack, and area charts do not display a metric gap when no metrics are available during a time period.

Storage Module

There are no known issues for this release.

Virtualization Module

There are no known issues for this release.

Web Server Module

Publication date Issue number Description
2017-03-17 MOD-320 Some KPI ad hoc searches transform data with the stats command and do not retain time fields. The KPIs do not render anything and do not show thresholding details.
2017-03-17 MOD-538 When you add a new tab with panels and refresh the page, the page breaks.
Last modified on 17 November, 2021
PREVIOUS
Fixed issues in Splunk IT Service Intelligence
  NEXT
Removed features in Splunk IT Service Intelligence

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.10.0 Cloud only


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters