Splunk® IT Service Intelligence

Release Notes

Acrobat logo Download manual as PDF

Splunk IT Service Intelligence version 4.4.x will no longer be supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see Before you upgrade IT Service Intelligence.
Acrobat logo Download topic as PDF

New features in Splunk IT Service Intelligence

Splunk IT Service Intelligence (ITSI) version 4.4.0 was released on October 22, 2019. It has the following new and changed features.

Python 3 Migration

New feature or enhancement Description
Python 3 migration with ITSI ITSI version 4.4.x is compatible with both Python 2.7 and Python 3.7 runtimes. Consider the following information when migrating your Splunk instance to Python 3:
  • Do not upgrade to Splunk Enterprise version 8.0.x without first upgrading to ITSI version 4.4.x. Even if your Splunk Enterprise instance is in Python 2 mode, pre-4.4.x ITSI versions break on version 8.0.
  • If you're using ITSI's Predictive Analytics feature, you must retrain all predictive models saved into each of your services after you migrate to Python 3.

For more information about each upgrade scenario, see Python 3 migration with ITSI.

Event Analytics

New feature or enhancement Description
Episodes break when closed When an episode is closed through an aggregation policy action rule, the episode automatically breaks. Previously, episodes closed through action rules continued to receive events. For more information, see Create a custom aggregation policy in ITSI.
Changes to itsi_rules_engine.properties file persist You can now make changes to a local copy of the itsi_rules_engine.properties file at $SPLUNK_HOME/etc/apps/SA-ITOA/local/ and these changes will take precedence over the default file.

Previously, this file was not treated like a regular Splunk .conf file, so changes to a local copy of the file had no impact. For more information, see the Version-specific upgrade notes for ITSI for version 4.4.x.

Hybrid action dispatching through the UI After you configure hybrid action dispatching, you can now run actions through the Episode Review UI on the master node.

Previously, you could only run actions through aggregation policy action rules. Only the Link Ticket and Share Episode options were available in the UI.

Improved performance when configuring aggregation policies Aggregation policies display a preview of episodes only if you click Preview results in order to improve performance.
Specify bidirectional ticketing index When configuring bidirectional ticketing, you can specify which index to look at for available fields when populating fields and values in the aggregation policy action rules. For more information, see Enable bidirectional integration with an external ticketing system in ITSI.
Episode comments stored in index Episode comments are now stored in the index rather than the KV store. When you upgrade to version 4.4.x, all existing and deprecated episode comments are migrated from the KV store to the index.
Event Analytics panels added to Episode Review Five panels from the Event Analytics Audit dashboard were added to Episode Review to better demonstrate the value of ITSI's event analytics functionality.

Content packs

New feature or enhancement Description
Content packs Content packs provide out-of-the-box content that you can use to quickly set up your ITSI environment. Content packs are standalone products that do not follow regular ITSI releases. The following content packs have been released:


New feature or enhancement Description
Back up deep dives You can now back up deep dives as part of a partial backup. For more information, see Create a partial backup.
Preview objects to be restored When restoring a backup, the Restore modal displays a preview of the count of knowledge objects to be restored.

Service Analyzer

New feature or enhancement Description
Acknowledge episodes through the Service Analyzer When viewing critical and high episodes in the Service Analyzer, you can acknowledge a new episode to indicate that you're working on it. This action changes the status to In Progress and assigns it to the current user. For more information, see Investigate a service with poor health in ITSI.

Beta glass table editor

New feature or enhancement Description
Improved thresholding experience Thresholds on beta glass table visualizations now show a maximum value for threshold ranges. Ranges also reorder automatically from lowest to highest. For more information, see Configure thresholds in the Use Splunk IT Service Intelligence manual.
Connect shapes to data sources You can connect ellipses and rectangles to data sources such as KPIs, service health scores, and ad hoc searches. For more information, see Connect a shape to a data source.
Add multiple time range pickers You can add multiple time range pickers to a beta glass table and set different time ranges for different visualizations. For more information, see Set different time ranges for visualizations in the Use Splunk IT Service Intelligence manual.
Support for maintenance windows When a service is in maintenance mode, related single-value KPI and service health score visualizations are greyed out on the beta glass table editor. Greying out of single-value radial visualizations is not currently supported.
KPI and service health score searches are read-only You can no longer edit the searches for KPI and service health score visualizations. These searches can only be updated through the service definition.
Keyboard shortcuts The following shortcuts were added:
  • Undo a change: Command + Z
  • Redo a change: Command + Shift + Z
  • Duplicate an object: Option + D

For more information, see Beta glass table keyboard shortcuts in ITSI.

Filler gauge visualization The filler gauge visualization type is now a supported chart option. For more information, see Filler gauge in the Splunk Enterprise Dashboards and Visualizations manual.


New feature or enhancement Description
Team admins can perform bulk imports Team admins with a role that inherits from the itoa_team_admin role can now bulk import services and entities to teams they have write access to.

KPI base searches

New feature or enhancement Description
See a count of associated KPIs The KPI base search lister page displays a count of the number of KPIs currently associated with each base search. Use this information when deciding whether to disable or delete a base search.

Infrastructure Monitoring

New feature or enhancement Description
VMware vCenter Server monitoring Integrate with VMware to monitor vCenter Servers. Collect metrics, task, inventory, event, and log data for vCenter Servers, ESXi clusters, ESXi hosts, and virtual machines. Collect VMware data with Data Collection Nodes. Manage Data Collection Nodes with Data Collection Schedulers.

Configure VMware data collection in the Splunk App for Infrastructure (SAI). The ITSI package includes the vmware_ta_itsi parent directory which contains VMware data collection components you have to install and configure.

For information about VMware data collection requirements, see VMware data collection planning and requirements in the Install and Upgrade Splunk App for Infrastructure guide.

For information about configuring VMware data collection, see Configure VMware data collection for Splunk App for Infrastructure in the Administer Splunk App for Infrastructure guide.

Last modified on 17 August, 2020
Fixed issues in Splunk IT Service Intelligence

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters