New features in Splunk IT Service Intelligence
Splunk IT Service Intelligence version 4.2.0 has the following new and changed features.
Splunk App for Infrastructure integration
- IT Service Intelligence (ITSI) and Splunk App for Infrastructure (SAI) are packaged together as a single product. Entity and alert integration with SAI is enabled by default.
- In addition to importing individual entities and alerts from SAI into ITSI, you can now create a single ITSI service using an SAI service template.
Single KPI alerting
- You can enable alerting on a single key performance indicator (KPI) and receive a notable event when aggregate KPI threshold values change.
- The new KPI Alerting Policy groups individual KPI alerts into episodes in Episode Review based on service.
Hybrid Action Dispatch
- You can dispatch episode actions to run on a remote ITSI instance. When you configure action rules on the Master node, the actions are dispatched and executed on the remote Executor node.
- An improved beta glass table editing framework is available for customers to try out and provide feedback.
- You can clone an existing glass table to the beta framework, or create a beta glass table from scratch.
Entity matching improvements
- ITSI now strictly matches entities against KPI search results using both the alias key and value, whereas before it only used the alias values.
- This strict entity association can cause entities to not be included in a KPI's results. For steps on how to fix potentially broken entities, see Removed features in Splunk IT Service Intelligence.
Merge entities during import
- Configure the Conflict Resolution Field to specify which fields bulk import will use to merge entities during import.
- If Conflict Resolution is set to
Update Existing Entitiesor
Replace Existing Entities, ITSI resolves duplicate entities based on this field.
For more information, see:
.conf file backup
- You can back up local configuration (.conf) files when creating a full or partial backup. ITSI backs up the following .conf files:
- ITSI has added official support for Java 9, 10, and 11.
- A new manual called Install and Upgrade Splunk IT Service Intelligence is available with expanded installation and upgrade instructions for single-instance and search head cluster deployments.
- All deployment planning topics, installation and upgrade instructions, and permissions information have been moved to this new manual.
Fixed issues in Splunk IT Service Intelligence
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.2.0