Splunk® IT Service Intelligence

Install and Upgrade Manual

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of ITSI. Click here for the latest version.
Acrobat logo Download topic as PDF

Where to install IT Service Intelligence in a distributed environment

You can install ITSI in any distributed Splunk Enterprise environment. For more information on distributed Splunk Enterprise environments, see Distributed deployments in this manual.

The Splunk App for Infrastructure and the Splunk Add-on for Infrastructure are included in the ITSI installation package. See Integration with the Splunk App for Infrastructure in this manual.

Where to install IT Service Intelligence

Splunk instance type Supported Required Actions required
Search heads Yes Yes Install ITSI on all search heads as described in Install Splunk IT Service Intelligence. Search heads must be running a compatible version of Splunk Enterprise. For compatible versions, see the Splunk products version compatibility matrix.
Indexers Yes Yes SA-IndexCreation is required on all indexers. For non-clustered distributed environments, copy SA-IndexCreation to $SPLUNK_HOME/etc/apps/ on individual indexers. Indexers must be running a compatible version of Splunk Enterprise. For compatible versions, see the Splunk products version compatibility matrix.
License master Yes Yes Install SA-ITSI-Licensechecker and SA-UserAccess on any license master in a distributed or search head cluster environment. If a search head in your environment is also a license master, the license master components are installed when you install ITSI on the search heads.
Heavy forwarders Yes Yes SA-IndexCreation is required on heavy forwarders.
Universal forwarders Yes No ITSI does not contain a data collection component.

Distributed deployment feature compatibility

This table describes the compatibility of ITSI with Splunk distributed deployment features.

Distributed deployment feature Supported Actions required
Search head clusters Yes Use the deployer to distribute ITSI to search head cluster members. Search heads must be running a compatible version of Splunk Enterprise. For detailed instructions, see Install IT Service Intelligence in a search head cluster environment.
Indexer clusters Yes Use the configuration bundle method to replicate SA-IndexCreation across all peer nodes. On the master node, place a copy of SA-IndexCreation in $SPLUNK_HOME/etc/master-apps/.
Deployment server Yes No actions required.
Last modified on 27 October, 2021
PREVIOUS
Install Splunk IT Service Intelligence on a single instance
  NEXT
Install IT Service Intelligence in a search head cluster environment

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.9.0, 4.9.1, 4.9.2, 4.9.3, 4.9.4, 4.10.0 Cloud only, 4.10.1 Cloud only


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters