Splunk® IT Service Intelligence

Install and Upgrade Manual

Where to install IT Service Intelligence in a distributed environment

You can install ITSI in any distributed Splunk Enterprise environment. For more information on distributed Splunk Enterprise environments, see Distributed deployments in this manual.

Where to install IT Service Intelligence

Splunk instance type Supported Required Actions required
Search heads Yes Yes Install ITSI on all search heads as described in Install Splunk IT Service Intelligence. Search heads must be running a compatible version of Splunk Enterprise. For compatible versions, see the Splunk products version compatibility matrix.
Indexers Yes Yes SA-IndexCreation is required on all indexers. For non-clustered distributed environments, copy SA-IndexCreation to $SPLUNK_HOME/etc/apps/ on individual indexers. Indexers must be running a compatible version of Splunk Enterprise. For compatible versions, see the Splunk products version compatibility matrix.
License manager Yes Yes Install SA-ITSI-Licensechecker and SA-UserAccess on any license manager in a distributed or search head cluster environment. If a search head in your environment is also a license manager, the license manager components are installed when you install ITSI on the search heads.
Heavy forwarders Yes Yes
Universal forwarders Yes No ITSI does not contain a data collection component.

Distributed deployment feature compatibility

This table describes the compatibility of ITSI with Splunk distributed deployment features.

Distributed deployment feature Supported Actions required
Search head clusters Yes Use the deployer to distribute ITSI to search head cluster members. Search heads must be running a compatible version of Splunk Enterprise. For detailed instructions, see Install IT Service Intelligence in a search head cluster environment.
Indexer clusters Yes Use the configuration bundle method to replicate SA-IndexCreation across all peer nodes. On the master node, place a copy of SA-IndexCreation in $SPLUNK_HOME/etc/manager-apps/.

For Splunk Enterprise versions 8.2.9 and lower, place a copy in $SPLUNK_HOME/etc/master-apps/.

Deployment server Yes No actions required.

Alongside IT Essentials Work

ITSI can't be installed on the same search head as IT Essentials Work.

Last modified on 30 August, 2024
Install Splunk IT Service Intelligence on a single instance   Install IT Service Intelligence in a search head cluster environment

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.11.0, 4.11.1, 4.11.2, 4.11.3, 4.11.4, 4.11.5, 4.11.6, 4.12.0 Cloud only, 4.13.0, 4.13.1, 4.13.2, 4.13.3, 4.15.0, 4.15.1, 4.15.2, 4.15.3, 4.17.0, 4.17.1, 4.18.0, 4.18.1, 4.19.0, 4.19.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters