Where to install IT Service Intelligence in a distributed environment
You can install ITSI in any distributed Splunk Enterprise environment. For more information on distributed Splunk Enterprise environments, see Distributed deployments in this manual.
Where to install IT Service Intelligence
Splunk instance type | Supported | Required | Actions required |
---|---|---|---|
Search heads | Yes | Yes | Install ITSI on all search heads as described in Install Splunk IT Service Intelligence. Search heads must be running a compatible version of Splunk Enterprise. For compatible versions, see the Splunk products version compatibility matrix. |
Indexers | Yes | Yes | SA-IndexCreation is required on all indexers. For non-clustered distributed environments, copy SA-IndexCreation to $SPLUNK_HOME/etc/apps/ on individual indexers. Indexers must be running a compatible version of Splunk Enterprise. For compatible versions, see the Splunk products version compatibility matrix.
|
License manager | Yes | Yes | Install SA-ITSI-Licensechecker and SA-UserAccess on any license manager in a distributed or search head cluster environment. If a search head in your environment is also a license manager, the license manager components are installed when you install ITSI on the search heads.
|
Heavy forwarders | Yes | Yes | |
Universal forwarders | Yes | No | ITSI does not contain a data collection component. |
Distributed deployment feature compatibility
This table describes the compatibility of ITSI with Splunk distributed deployment features.
Distributed deployment feature | Supported | Actions required |
---|---|---|
Search head clusters | Yes | Use the deployer to distribute ITSI to search head cluster members. Search heads must be running a compatible version of Splunk Enterprise. For detailed instructions, see Install IT Service Intelligence in a search head cluster environment. |
Indexer clusters | Yes | Use the configuration bundle method to replicate SA-IndexCreation across all peer nodes. On the master node, place a copy of SA-IndexCreation in $SPLUNK_HOME/etc/manager-apps/.
For Splunk Enterprise versions 8.2.9 and lower, place a copy in $SPLUNK_HOME/etc/master-apps/. |
Deployment server | Yes | No actions required. |
Alongside IT Essentials Work
ITSI can't be installed on the same search head as IT Essentials Work.
Install ITSI in a FIPS enabled environment | Install IT Service Intelligence in a search head cluster environment |
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.11.0, 4.11.1, 4.11.2, 4.11.3, 4.11.4, 4.11.5, 4.11.6, 4.12.0 Cloud only, 4.13.0, 4.13.1, 4.13.2, 4.13.3, 4.15.0, 4.15.1, 4.15.2, 4.15.3, 4.17.0, 4.17.1, 4.18.0, 4.18.1, 4.19.0, 4.19.1
Feedback submitted, thanks!