Known issues in Splunk IT Service Intelligence

This version of IT Service Intelligence (ITSI) has the following known issues and workarounds.

Uncategorized issues

Date filed Issue number Description Release version
2026-07-20 ITSI-45693 EventiQ Diagnose may appear unavailable on Splunk Enterprise when the user can run ITSI actions, but does not have read access to the Splunk Cloud Connect app.

Workaround:

  1. Go to Settings then Apps then Manage Apps.

  2. Find Splunk Cloud Connect in the list of installed apps.

  3. You can search for either:

    1. Splunk Cloud Connect

    2. splunk_cloud_connect

  4. Select Permissions for the Splunk Cloud Connect app. In the role permissions table, grant read access to each ITSI role whose users need EventiQ Diagnose. Common roles include: itoa_admin, itoa_team_admin, itoa_analyst. EventiQ users require only read access for this workaround.

  5. Select Save. Ask affected users to sign out of Splunk and sign back in. Refresh Episode Review and confirm that the EventiQ Diagnose action is available.

5.0