Create a full backup of ITSI
Create a full backup of IT Service Intelligence (ITSI) to make a copy of all your configuration information. Taking regular backups from a healthy environment enables you to restore from a backup in the event of a disaster, or if you add a search head to a cluster. You can also take a backup before migrating to a different machine.
Make sure to be familiar with the standard backup and restore tools and procedures used by your organization.
For more information about ITSI backups, including what gets backed up, see Overview of backing up and restoring ITSI KV store data.
- You must have the itoa_admin role or the write_itsi_backup_restore capability to create a backup job.
- Before creating a backup, make sure no service templates are syncing. Check the sync status of service templates by clicking Configuration > Service Templates from the ITSI main menu.
- From the ITSI main menu, click Configuration > Backup/Restore.
- Click Create Job > Create Backup Job.
- Select Full Backup.
- Provide a name and description of the backup job.
- (Optional) Enable Include .conf files to back up the following configuration files located in
- savedsearches.conf (only in
ITSI backs up these .conf files only if they exist in a non-default directory, such as
$SPLUNK_HOME/etc/apps/itsi/local. For more information, see About configuration files. When restored, the backed up .conf file overrides the existing local version.
- Click Create.
The backup job appears on the Backup/Restore Jobs page with the status "Queued" until the job runs. When the backup job finishes, the status changes to "Completed" and a confirmation message appears in the Messages drop-down list in Splunk Web.
You can run any completed backup job again by clicking Edit > Start Backup in the Actions column. You can also modify the completed backup job before running it again.
To restore the backup you created, see Restore a full or partial backup of ITSI.
About the default scheduled backup in ITSI
Create a partial backup of ITSI
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.5.0 Cloud only, 4.5.1 Cloud only, 4.6.0 Cloud only, 4.6.1 Cloud only, 4.6.2 Cloud only, 4.7.0, 4.7.1