Splunk® IT Service Intelligence

Release Notes

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of ITSI. Click here for the latest version.
Acrobat logo Download topic as PDF

New features in Splunk IT Service Intelligence

Splunk IT Service Intelligence (ITSI) version 4.6.0 was released on August 13, 2020. It has the following new and changed features.

Event Analytics

New feature or enhancement Description
Partial backup of correlation searches and notable event aggregation policies You can now include correlation searches and aggregation policies in a partial backup. By default, all dependent services are included in the backup as well. For more information, see Create a partial backup of ITSI in the Administration Manual.
Custom fields in ServiceNow incidents ITSI now supports the ability to update custom ServiceNow fields that are not included with the Splunk Add-on for ServiceNow. For instructions to pass custom fields, see Use custom alert actions for the Splunk Add-on for ServiceNow in the Splunk Add-on for ServiceNow manual.
Resizable episode details panel The details panel that opens when you select an episode or notable event in Episode Review is now resizable, so you can increase or decrease the size depending on what information you want to view.
Change the default episode tab You can change the default tab that's selected when you open an episode in Episode Review. The setting persists on a per-dashboard basis. For more information, see Change the episode view default tab in the Event Analytics manual.
Customizable Episode Review performance dashboard You can customize the performance dashboard at the top of Episode Review using a JSON-formatted dashboard definition. The modified dashboard applies to the individual episode view and persists after you save it.
Custom episode dashboards Add a custom JSON-formatted dashboard to display in each episode grouped by an aggregation policy. For more information, see Add an episode dashboard in the Event Analytics manual.
Action failures in the Event Analytics Monitoring dashboard A new panel called Action Failures was added to the Event Analytics Monitoring dashboard. The panel displays the details of each action failure for each episode. For more information, see Event Analytics Monitoring dashboard.
Smart episode recycling The smart episode retention policy selectively recycles inactive episodes and their related objects first before recycling other objects. This prevents duplicate episodes and the inadvertent recycling of active episodes. For more information, see itsi_notable_event_retention.conf.
Rules Engine resiliency improvements You no longer need to manually disable the Rules Engine during indexer rolling restarts. You can configure your environment so the Rules Engine detects the current health of your indexer cluster and automatically stops processing events until the cluster is in a healthy state again. For instructions to set up this automation in your environment, see Configure the Rules Engine to handle indexer cluster rolling restarts and upgrades.
Netcool correlation search template A predefined Netcool correlation search template was added to the correlation search builder. For more information, see Correlation search templates in ITSI in the Event Analytics manual.

Installation and upgrade

New feature or enhancement Description
Stable upgrade experience ITSI now offers an enhanced upgrade experience through the UI. When you extract the ITSI installation package into $SPLUNK_HOME/etc/apps, an upgrade screen appears that walks you through the upgrade. You can track your progress and see which step you're on in the process. For more information, see Upgrade IT Service Intelligence on a single instance or Upgrade IT Service Intelligence in a search head cluster environment.

Metrics-based summary index

New feature or enhancement Description
Metrics summary index KPI data is now summarized in a new metrics-based summary index called itsi_summary_metrics in addition to the events-based itsi_summary index. The new index provides a more responsive UI experience and improves the performance of searches dispatched by ITSI in the following ways:
  • Service Analyzer rendering is 28% faster
  • Service topology rendering is 18% faster

For more information, see ITSI metrics summary index reference in the Administration Manual.

Entity integrations

New feature or enhancement Description
Unix and Linux host integration There are two ways you can add *nix data to ITSI through the Unix and Linux entity integration. You can collect *nix data with the Splunk Add-on for Unix and Linux installed on the Splunk universal forwarder, or you can collect *nix data with collectd and Splunk universal forwarder. For more, see About the Unix and Linux entity integration in ITSI.
Windows host integration Ingest Windows entities into ITSI using the custom Windows integration. For more information, see About the Windows entity integration in ITSI.
VMware vSphere entity integration Ingest VMware entities into ITSI using the Splunk Add-on for VMware Metrics. For more information, see About the VMware vSphere entity integration in ITSI.
Edit default entity types You can edit a default entity type in the ITSI user interface or through the REST API endpoint. You can't delete a default entity type in ITSI. For more information, see Edit a default entity type in ITSI.
Field substitution in entity type navigation URLs You can substitute entity fields directly into the URL of an entity type navigation. For example, https://www.{host}.com constructs the URL using the host field of the specific entity of that type. For more information, see Add navigations to your entity type.
Attach Splunk dashboards to an entity type Attach one or more Splunk dashboards to an entity type. The dashboards are viewable when you investigate an entity of that entity type. For more information, see Create entity types in ITSI.
Last modified on 17 August, 2020
  NEXT
Fixed issues in Splunk IT Service Intelligence

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.6.0 Cloud only


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters