Known issues in Splunk IT Service Intelligence
This version of IT Service Intelligence (ITSI) has the following known issues and workarounds.
Entities
| Date filed | Issue number | Description |
|---|---|---|
| 2025-09-05 | ITSI-41680 | Users with itoa_user, itoa_analyst roles seeing 403 error when retrieving entity drilldowns in service analyzer. |
| 2024-04-11 | ITSI-35019, ITSI-35068 | Entity dashboard page re-renders when the entity sidebar is closed or opened. |
Uncategorized issues
| Date filed | Issue number | Description |
|---|---|---|
| 2025-10-18 | ITSI-37708 | Error "PkgResourcesDeprecationWarning: unknown is an invalid version and will not be supported in a future release". Workaround: Remove older deprecated library folder /splunk/etc/apps/SA-ITOA/lib/SA_ITOA_app_common/scp_download_simple_crypto-unknown.dist-info. |
| 2025-09-24 | ITSI-41765 | Unable to initialize modular input "itsi_summary_worker" after upgrading to ITSI 4.21.0. Workaround: Install Python for Scientific Computing and the Splunk AI Toolkit to resolve the issue. |
| 2025-09-18 | ITSI-41761 | The upgrade readiness check for Maximum number of events using base search reached displays a false positive error. Workaround: Ignore this error if all the instances of this error are a false positive. |
| 2025-09-05 | ITSI-41681 | Filter Episode Monitoring alerts before passing them to EventIQ policies. Workaround: Update the filtering criteria for the Event iQ policy to filter out all monitoring alerts created by other policies in order to avoid overlap. For example: AND source does not match *Episode Monitoring*, or AND itsi_policy_id does not match *episode*. |
| 2025-08-19 | ITSI-41290 | Splunk throttling is enabled for default connections when disabled in connection payload. |
| 2025-08-05 | ITSI-41271 | When clicking impacted services from Episode Review, an error occurs on the Service Analyzer. |
| 2024-10-18 | ITSI-37708 | Errors stating PkgResourcesDeprecationWarning: unknown is an invalid version and will not be supported in a future release appear after upgrading Splunk to 9.2.2. Workaround: Remove deprecated library folder /splunk/etc/apps/SA-ITOA/lib/SA_ITOA_app_common/scp_download_simple_crypto-unknown.dist-info |
| 2024-06-25 | ITSI-36467 | Some actions not running in the rules engine. Workaround: Update each search head to disable asynchornous execution of actions in the Rules Engine.
|