Known issues in Splunk IT Service Intelligence
This version of IT Service Intelligence (ITSI) has the following known issues and workarounds.
Notable Events
Date filed | Issue number | Description |
---|---|---|
2025-06-26 | ITSI-40536 | NATS Configuration Not Updating with SHC Membership Changes Workaround: *Known Issue to be document: Search Head Cluster (SHC) Membership Changes Do Not Update* Template:Nats-js.conf *Routes Automatically* When a Search Head (SH) is removed from a Search Head Cluster (SHC), the Template:$SPLUNK HOME/etc/apps/SA-ITOA/bin/nats/nats-js.conf file is not automatically updated to reflect this change in the NATS route configuration.
{noformat}$SPLUNK_HOME/etc/apps/SA-ITOA/bin/nats$ ./nats-server --signal reload {noformat} OR restart the NATS server on each Search Head.
{noformat}"routes": [ "nats://SH1:4248", "nats://SH2:4248", "nats://SH3:4248" ] {noformat} and Template:SH2 is removed from the cluster, you must manually remove the Template:"nats://SH2:4248" entry from the Template:Routes array on all Search Heads and restart the NATS server on them.
|
Uncategorized issues
Date filed | Issue number | Description |
---|---|---|
2019-05-30 | ITSI-3322 | If you add a correlation search in ITSI which contains a sub-search returning into an eval, you get a message "Invalid search string: This search cannot be parsed when parse_only is set to true." Workaround: You can't use a sub-search returning into an eval in a correlation search. As a workaround, create and save a basic correlation search with all of the information you want outside of the search. Then as an admin user, go to Settings > Searches, reports, and alerts and open the correlation search you just created. Add the sub-search you were trying to add there. |
Fixed issues in Splunk IT Service Intelligence | Removed features in Splunk IT Service Intelligence |
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.20.1
Feedback submitted, thanks!