Where to install IT Service Intelligence in a distributed environment
You can install ITSI in any distributed Splunk Enterprise environment. For more information on distributed Splunk Enterprise environments, see Distributed deployments in this manual.
Where to install IT Service Intelligence
|Splunk instance type
|Install ITSI on all search heads as described in Install Splunk IT Service Intelligence. Search heads must be running a compatible version of Splunk Enterprise. For compatible versions, see the Splunk products version compatibility matrix.
SA-IndexCreation is required on all indexers. For non-clustered distributed environments, copy
SA-IndexCreation to $SPLUNK_HOME/etc/apps/ on individual indexers. Indexers must be running a compatible version of Splunk Enterprise. For compatible versions, see the Splunk products version compatibility matrix.
SA-UserAccess on any license manager in a distributed or search head cluster environment. If a search head in your environment is also a license manager, the license manager components are installed when you install ITSI on the search heads.
SA-IndexCreation is required on heavy forwarders.
|ITSI does not contain a data collection component.
Distributed deployment feature compatibility
This table describes the compatibility of ITSI with Splunk distributed deployment features.
|Distributed deployment feature
|Search head clusters
|Use the deployer to distribute ITSI to search head cluster members. Search heads must be running a compatible version of Splunk Enterprise. For detailed instructions, see Install IT Service Intelligence in a search head cluster environment.
|Use the configuration bundle method to replicate
SA-IndexCreation across all peer nodes. On the master node, place a copy of
SA-IndexCreation in $SPLUNK_HOME/etc/manager-apps/.
For Splunk Enterprise versions 8.2.9 and lower, place a copy in $SPLUNK_HOME/etc/master-apps/.
|No actions required.
Alongside IT Essentials Work
ITSI can't be installed on the same search head as IT Essentials Work.
Install ITSI in a FIPS enabled environment
Install IT Service Intelligence in a search head cluster environment
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.11.0, 4.11.1, 4.11.2, 4.11.3, 4.11.4, 4.11.5, 4.11.6, 4.12.0 Cloud only, 4.13.0, 4.13.1, 4.13.2, 4.13.3, 4.15.0, 4.15.1, 4.15.2, 4.15.3, 4.17.0, 4.17.1, 4.18.0