Splunk® IT Service Intelligence

Release Notes

Known issues in Splunk IT Service Intelligence

This version of IT Service Intelligence (ITSI) has the following known issues and workarounds.

Predictive Analytics

Date filed Issue number Description
2024-08-06 ITSI-36922 Updates to the Machine Learning Toolkit and the Splunk Python for Scientific Computing affect ITSI predictive analytics.
Workaround:


  • Re-train all the models (Gradient Boosting Regressor, Random Forest Regressor, Linear Regression and Logistic Regression) on the services with predictive analytics.
  • Delete the existing correlation searches for the trained model, or update the existing correlation search to refer to the newly trained model(s).
  • If the correlation search was deleted, re-create the correlation searches and reference the newly trained model(s).

Adaptive Thresholding

Date filed Issue number Description
2024-09-04 ITSI-37270 Use Recommended Thresholding Configuration cannot use all backfilled events

Workaround:
While backfilling the KPI customer can set the fill data gaps option other than Template:Last available value and after backfill completes successfully they can switch the option to Template:Last available value.

Notable Events

Date filed Issue number Description
2024-11-07 ITSI-37939 The preview for a notable event aggregation policy doesn't display results, without error message

Workaround:
Reduce the number of notable events sampled, by changing the macro *neap_preview_event_limit* (change from default is 10000 to 1000)

Notable Event Aggregation Policies

Date filed Issue number Description
2024-11-07 ITSI-37939 The preview for a notable event aggregation policy doesn't display results, without error message

Workaround:
Reduce the number of notable events sampled, by changing the macro *neap_preview_event_limit* (change from default is 10000 to 1000)

Service Definition

Date filed Issue number Description
2024-09-10 ITSI-37299 Discrepancy in the "Per-Entity Threshold Value" graph

Uncategorized issues

Date filed Issue number Description
2024-11-12 ITSI-37977 the list of saved Episode Reviews fails to load, and throw kvstore mem limit error
2024-10-18 ITSI-37708 ITSI 4.19.* throwing python errors / warnings on Splunk 9.2.2* "PkgResourcesDeprecationWarning: unknown is an invalid version and will not be supported in a future release"
2024-07-22 ITSI-36739 Panel shows incorrect results in dashboards : "ITSI Health Check" , "Event Analytics Monitoring"

Workaround:
# Find the list of SHs from Settings -> Search Head Clustering
  1. Create a Macro on SHC with permission to share the macro with itsi app.

For example : host_list Definition -> {{host IN (<list of hosts comma separated >)}} Example -> Template:Host IN (host1, host2, host3)

  1. Open dashboard -> Click on edit -> go to the panel which is displaying incorrect results -> go to the data source
  2. Edit the search -> add created macro Template:`host list` afterTemplate:Index= internal / index= introspection / index= audit

Example -> Template:Index= internal `host list`

  1. Repeat the same steps for other SHC.
2024-04-24 ITSI-35347 After upgrading ITSI, the navigation bar does not reflect the latest updates.

Workaround:
The Splunk navigation bar is cached in local storage, and updates to the navigation bar should appear in 24 hours. You can manually update the cache by following these steps:
  1. Open your web browser's web console.
  2. Navigate to the browser's *Developer tools,* then *Applications*, then localStorage folder to see the saved values.
  3. Remove the following key in the folder:


splunk-appnav:itsi:admin:en-GB

  1. Reload the page.
Last modified on 17 December, 2024
Fixed issues in Splunk IT Service Intelligence   Removed features in Splunk IT Service Intelligence

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.19.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters