Uninstall Splunk IT Service Intelligence
Once you uninstall ITSI, you can perform a clean reinstallation. See Install Splunk IT Service Intelligence in this manual.
To uninstall ITSI, perform the following high-level steps:
- Clean the KV store.
- Delete all ITSI entries in collections.conf.
- Remove all Splunk apps installed with ITSI.
- Remove all ITSI-specific indexes.
ITSI does not provide an automatic way to clean up the contents for a distributed deployment. To clean a distributed deployment you must perform these steps on individual search heads and indexers.
These steps permanently delete all data associated with your ITSI deployment. Do not perform these steps unless you are certain that you want to permanently delete your ITSI deployment. If you are uncertain how to proceed, contact Splunk support for guidance.
Step 1: Clean the KV store
The steps to clean the KV store differ depending on your deployment architecture.
Clean the KV store on a standalone search head or license master
On all search heads, and the license master if applicable, clean the KV store. There are two ways to clean the KV store:
Use the Splunk CLI or run a
curl request to delete each individual SA-ITOA collection.
- Splunk CLI:
$SPLUNK_HOME/bin/splunk clean kvstore -app SA-ITOA
$curl –k –u admin:changeme –X DELETE https://localhost:8089/servicesNS/nobody/SA-ITOA/storage/collections/data/itsi_services
A complete listing of all
SA-ITOA collections is available in
Clean the KV store in a search head cluster
To clean the KV store in a search head cluster environment, run one of the above options to clean the KV store on a single cluster member. The cluster replicates this action and cleans the KV store on each cluster member. See Configuration methods that trigger replication in the Splunk Enterprise Distributed Search manual.
Step 2: Delete all ITSI entries in the collections.conf file
On all search heads, delete all ITSI entries in the collections.conf file.
- Only users with file system access, such as system administrators, can edit collections.conf.
- Review the steps in How to edit a configuration file in the Splunk Enterprise Admin Manual.
Never change or copy the configuration files in the default directory. The files in the default directory must remain intact and in their original location.
- Open the local
- Delete all entries whose stanza name starts with
Step 3: Remove all Splunk apps installed with ITSI
Remove all Splunk apps and add-ons installed with the current or previous versions of ITSI.
Do not remove
Splunk_SA_CIM if they are in use by another app, such as Splunk Enterprise Security or Splunk App for VMware. If you remove them, any dependent apps will not function as expected.
Remove apps from standalone or non-clustered distributed environments
- Stop your Splunk platform deployment.
- On all search heads and indexers where ITSI or dependent apps and add-ons are installed, delete all items installed by the ITSI installation package. For example:
cd $SPLUNK_HOME/etc/apps rm rf DA* rm rf SA* rm rf itsi
- Start your Splunk platform deployment.
- Remove any ITSI modules that have been installed independently from ITSI, such as the Splunk ITSI Module for Application Performance Monitoring.
For a complete listing of apps and add-ons installed by the ITSI installation package, see About the ITSI installation package in this manual.
Remove apps from clusters
To delete an app from a search head cluster, you must remove it from the configuration bundle on the deployer. The next time you push the bundle, each cluster member deletes the app from its own file system. For more information, see Where to place the configuration bundle on the deployer in the Splunk Enterprise Distributed Search manual.
To delete an app from an indexer cluster, you must remove it from the deployment location on the cluster master. For more information, see Update common peer configurations and apps in the Splunk Enterprise Managing Indexers and Clusters of Indexers manual.
Step 4: Remove all ITSI indexes
Remove the following ITSI-specific indexes that
SA-IndexCreation places in
Do not remove any indexes that are currently in use by Splunk Enterprise Security or other Splunk apps, including
cd $SPLUNK_HOME/var/lib/splunk rm -rf itsi_* anomaly_detection
Configure multiple ITSI deployments to use the same indexing layer
Plan an upgrade of IT Service Intelligence
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.3.0, 4.3.1, 4.4.0