Splunk® IT Service Intelligence

Install and Upgrade Manual

Acrobat logo Download manual as PDF

Splunk IT Service Intelligence version 4.4.x will no longer be supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see Before you upgrade IT Service Intelligence.
This documentation does not apply to the most recent version of ITSI. Click here for the latest version.
Acrobat logo Download topic as PDF

Uninstall Splunk IT Service Intelligence

Once you uninstall ITSI, you can perform a clean reinstallation. See Install Splunk IT Service Intelligence in this manual.

ITSI doesn't provide an automatic way to clean up the contents for a distributed deployment. To clean a distributed deployment you must perform these steps on individual search heads and indexers.

These steps permanently delete all data associated with your ITSI deployment. Do not perform these steps unless you're certain you want to permanently delete your ITSI deployment. If you're uncertain how to proceed, contact Splunk Support for guidance.

Step 1: Remove all Splunk apps installed with ITSI

Remove all Splunk apps and add-ons installed with the current or previous versions of ITSI.

Note: Don't remove SA-ThreatIntelligence, SA-Ticketing, SA-Utils, or Splunk_SA_CIM if they're used by another app, such as Splunk Enterprise Security or Splunk App for VMware. If you remove them, any dependent apps won't function as expected.

Remove apps from standalone or non-clustered distributed environments

  1. Stop your Splunk platform deployment.
    $SPLUNK_HOME/bin/splunk stop
  2. On all search heads and indexers where ITSI or dependent apps and add-ons are installed, delete all items installed by the ITSI installation package. For example:
    cd $SPLUNK_HOME/etc/apps
    rm ­-rf DA*
    rm -­rf SA*
    rm -­rf itsi 
  3. Start your Splunk platform deployment.
  4. Remove any ITSI modules that have been installed independently from ITSI, such as the Splunk ITSI Module for Application Performance Monitoring.

For a complete listing of apps and add-ons installed by the ITSI installation package, see About the ITSI installation package in this manual.

Remove apps from clusters

To delete an app from a search head cluster, you must remove it from the configuration bundle on the deployer. The next time you push the bundle, each cluster member deletes the app from its own file system. For more information, see Where to place the configuration bundle on the deployer in the Splunk Enterprise Distributed Search manual.

To delete an app from an indexer cluster, you must remove it from the deployment location on the cluster master. For more information, see Update common peer configurations and apps in the Splunk Enterprise Managing Indexers and Clusters of Indexers manual.

Step 2: Remove all ITSI indexes

Remove the following ITSI-specific indexes that SA-IndexCreation places in $SPLUNK_HOME/var/lib/splunk.

Do not remove any indexes that are currently in use by Splunk Enterprise Security or other Splunk apps, including notable and risk indexes.

  • anomaly_detection
  • itsi_grouped_alerts
  • itsi_notable_archive
  • itsi_notable_audit
  • itsi_summary
  • itsi_tracked_alerts
  • snmptrapd

For example:

cd $SPLUNK_HOME/var/lib/splunk
rm -rf itsi_* anomaly_detection

Step 3: Delete scheduled backups

Scheduled backups of ITSI are stored in the $SPLUNK_HOME/var/itsi folder.

To remove the folder, run the following command on all search heads:

rm -rf $SPLUNK_HOME/var/itsi
Last modified on 14 May, 2020
Configure multiple ITSI deployments to use the same indexing layer
Before you upgrade IT Service Intelligence

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.3.0, 4.3.1, 4.4.0, 4.4.1, 4.4.2, 4.4.3, 4.4.4, 4.4.5, 4.5.0 Cloud only, 4.5.1 Cloud only

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters