Version-specific upgrade notes for ITSI
Consider the following guidelines when upgrading to specific versions of IT Service Intelligence.
After upgrading to version 4.4.x
As of version 4.4.x, you can make changes to a local copy of the
itsi_rules_engine.properties file at
$SPLUNK_HOME/etc/apps/SA-ITOA/local/ and these changes will take precedence over the default file. Previously, this file was not treated like a regular Splunk .conf file, so changes to a local copy of the file had no impact. For more information, see Configuration file precedence in the Splunk Enterprise Admin Manual.
If you've made changes to the default file in the past, make a copy of these changes before upgrading to 4.4.x. After you upgrade, create a blank
itsi_rules_engine.properties file at
$SPLUNK_HOME/etc/apps/SA-ITOA/local/ and add these changed settings to the local file. This step ensures that your changes to the file will persist through future upgrades.
Make all future changes to
itsi_rules_engine.properties in the local file rather than the default file. For the contents of the file, see Tune notable event grouping in ITSI in the Administration Manual.
After upgrading to version 4.2.x
Entity Alias Filtering field used in KPI searches was removed in version 4.2.0. With the removal of entity alias filtering, ITSI now strictly matches entities against KPI search results using both the alias key and value, whereas before it only used the alias value.
This strict association change can cause some entities to not be included in KPI results. If this is the case, a message appears in Splunk Web with a link to documentation on how to fix potentially broken entities. For information, see Removed features in Splunk IT Service Intelligence.
After upgrading to version 4.0.4
To initiate the fix for ITSI-1868 concerning entity rules, you need to trigger the service-entity rule change handler. To trigger the handler, run the kvstore_to_json mode 4 option, which will regenerate your KPI search schedules.
After upgrading to version 4.0.x
- Remove unnecessary XML files from the ITSI OS Module that were removed or renamed as of ITSI 4.0.0. Remove the following files from
IT Service Intelligence Internals *DO NOT COPY* stackto ensure that you don't pay for notable events generated by ITSI. The sourcetypes used to track notable events and episodes are counted on this special stack with no impact on your Splunk Enterprise license. When calculating your daily license usage, disregard this stack.
After upgrading to version 3.1.x
- If you have a dedicated license master, remove
SA-ITOAfrom the license master since ITSI no longer requires the add-on as of version 3.1.x.
- When the objects in ITSI are exported during a backup or migration, if the number of KPIs linked to a service is high, the instance can hit a KV store memory size limit causing some objects to be dropped from the backup and lost after the upgrade.
Workaround: Increase the KV store bulk get limit in
$SPLUNK_HOME/etc/apps/SA-ITOA/local/limits.confand retry the backup or upgrade. Increase the
max_size_per_result_mbvalue as necessary.
[kvstore] # The maximum size, in megabytes (MB), of the result that will be returned for a single query to a collection. # ITSI requires approximately 50MB per 1,000 KPIs. Override this value if necessary. # Default: 500 MB max_size_per_result_mb = 500
This action increases the memory used by the KV store during operations.
Upgrade IT Service Intelligence in a search head cluster environment
Troubleshoot an upgrade of IT Service Intelligence
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.4.0, 4.4.1, 4.4.2, 4.4.3