Splunk® IT Service Intelligence

Install and Upgrade Manual

Roll back an upgrade of ITSI

If your upgrade to a new version of IT Service Intelligence (ITSI) fails, you can restore it to the old state using the backup/restore functionality in either ITSI or Splunk Enterprise.

Two types of backups are automatically taken before an ITSI upgrade begins:

  • A JSON-formatted ITSI backup of the search head which is stored in $SPLUNK_HOME/etc/apps/SA-ITOA/lib. You can restore this backup using ITSI's backup/restore functionality.
  • A KV store backup taken by the KV store REST endpoint. The backup is stored in $SPLUNK_HOME/var/lib/splunk/kvstorebackup/. If you use the KV store backup, you also need to manually restore your local configuration files.

You can safely roll back your ITSI upgrade using either of these methods.

Roll back an upgrade using the ITSI backup

  1. Download and install the previous version of ITSI that you upgraded from. You can find all past versions of ITSI on Splunkbase.
  2. Restore the ITSI backup from $SPLUNK_HOME/etc/apps/SA-ITOA/lib. For instructions, see Restore a full or partial backup of ITSI.

Roll back an upgrade using the Splunk Enterprise KV store backup

  1. Download and install the previous version of ITSI that you upgraded from. You can find all past versions of ITSI on Splunkbase.
  2. Restore the KV store backup from $SPLUNK_HOME/var/lib/splunk/kvstorebackup to the KV store directory through the kvstore/backup/restore endpoint.
  3. Manually restore your local configuration files stored in $SPLUNK_HOME/etc/apps/SA-ITOA/lib/backup_xxx/itsi_local.zip and $SPLUNK_HOME/etc/apps/SA-ITOA/lib/backup_xxx/itoa_local.zip. To restore the files, manually untar them into the following locations:
    Backup location Untarred location
    $SPLUNK_HOME/etc/apps/SA-ITOA/lib/backup_xxx/itsi_local.zip $SPLUNK_HOME/etc/apps/itsi/local
    $SPLUNK_HOME/etc/apps/SA-ITOA/lib/backup_xxx/itoa_local.zip $SPLUNK_HOME/etc/apps/SA-ITOA/local
Last modified on 29 November, 2022
Upgrade IT Service Intelligence in a search head cluster environment   Version-specific upgrade notes for ITSI

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.11.0, 4.11.1, 4.11.2, 4.11.3, 4.11.4, 4.11.5, 4.11.6, 4.13.0, 4.13.1, 4.13.2, 4.13.3, 4.15.0, 4.15.1, 4.15.2, 4.15.3, 4.17.0, 4.17.1, 4.18.0, 4.18.1, 4.19.0, 4.19.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters