Splunk® IT Service Intelligence

Release Notes

Acrobat logo Download manual as PDF

Splunk IT Service Intelligence version 4.3.x will no longer be supported as of July 17, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see Before you upgrade IT Service Intelligence.
This documentation does not apply to the most recent version of ITSI. Click here for the latest version.
Acrobat logo Download topic as PDF

New features in Splunk IT Service Intelligence

Splunk IT Service Intelligence (ITSI) version 4.3.0 was released on July 17, 2019. It has the following new and changed features.

Episode Review

  • Ability to bulk add a comment to multiple episodes.
  • Ability to create multiple incidents in bulk for multiple episodes. See Create ServiceNow tickets for multiple episodes in the Use Splunk IT Service Intelligence manual.
  • Ability to link multiple episodes to one external ticket.

Notable Event Actions SDK updates

  • The custom_event_action_base.py module was renamed to custom_group_action_base.py to account for the immutability of individual notable events in post-4.0.0 ITSI versions.
  • The CustomEventActionBase class has been renamed to CustomGroupActionBase.
  • The following methods were renamed in the CustomGroupActionBase class:
    • get_event to get_group
    • extract_event_id to extract_group_or_event_id
  • A new grouping.py module was added to work on episodes (groups of notable events). The EventGroup class was moved to this new module along with some methods of the Event class to the EventGroup class.

For more information, see Use the Notable Event Actions SDK.


  • ITSI now saves the last seven days of default scheduled backups rather than just one day. You can configure the number of days of backups that ITSI stores. See Default scheduled backup in the Administer Splunk IT Service Intelligence manual.
  • When downloading or restoring the default scheduled backup, you can select which day of the backup you want to download/restore.

Integration with the Splunk App for Infrastructure

  • When you integrate entities from SAI with ITSI, the entities now merge on title instead of key to prevent entity duplication. See How entities are merged in the Integrate the Splunk App for Infrastructure with ITSI manual.
  • When viewing SAI entities in a deep dive, you can drill down to the Entity Overview in SAI. See Investigate service issues in a deep dive.
  • When viewing the entity health page of an SAI entity, you can drill down to the Entity Overview in SAI.

Beta glass table editor

  • Version 4.3.0 offers updates and improvements to the beta glass table editor. For a list of fixes, see Fixed issues in Splunk IT Service Intelligence.
  • The following new features were added to the beta glass table editor:
    • Beta glass tables now support inputs which let you perform actions on the canvas and on visualizations. See Inputs in the Use IT Service Intelligence manual.
    • KPI widgets update their threshold status automatically if you change the thresholds in the service definition.
    • You can add some visualization types through the UI. See Add a chart or table visualization.


The Event Analytics Monitoring dashboard was added to provide basic statistics for troubleshooting event analytics.

What's new in the docs

Topic Description
Back up and restore ITSI KV store data Expanded information about the default scheduled backup, as well as instructions to edit the default scheduled backup.
Set up a recurring import of entities in ITSI Added instructions to set up a recurring entity import in a search head cluster environment.
Install IT Service Intelligence in a search head cluster environment Expanded instructions on installing ITSI in a search head cluster environment. Includes a diagram of what the search head cluster looks like and a table explaining where to install ITSI and other dependencies.
Last modified on 06 November, 2019
Fixed issues in Splunk IT Service Intelligence

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.3.0

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters