New features in Splunk IT Service Intelligence

This version has these new and changed features.

General

New feature or enhancement Description Release Version
Java Support Update IT Service Intelligence 5.0.1 requires Java 17 (minimum) and supports up to Java 21. Java 8 and Java 11 are no longer supported. See Java Requirements. 5.0.1
Security hardening Splunk IT Service Intelligence 5.0.1 includes extensive security hardening across Event Analytics, Episode Review, data integrations, Glass Tables, Entity Detail, Service Sandbox, and role-based access controls. This release addresses a large set of internally validated vulnerabilities through input validation, fail-closed handling, safer URL and SPL boundaries, and corrected collection permissions. Customer-visible outcomes include:
  • Episode Review: Safer shared URL state, sort and time handling, export and configuration filenames, ticket and instruction link rendering, and risky dashboard search enforcement. Stored-search Run Search shortcuts are removed; copy SPL into Search for explicit execution.
  • Data integrations, associations, enrichments, and mappings: Identifier validation and malformed-record resilience so invalid records are rejected or skipped before SPL is built.
  • Glass Tables, Entity Detail, and Service Sandbox: Input boundaries and fail-closed behavior for stored identifiers and malformed persisted records.
  • RBAC: The itoa_user role retains read access but no longer has direct KV Store write or delete access to five notable-event collections. Bundled AI saved searches are writable only by administrative roles.
  • Notable Event Aggregation Policies and correlation searches: Risky-command enforcement and malformed-policy containment so invalid policies do not crash routing or execute unsafe SPL.
5.0.1

Event Analytics

New feature or enhancement Description Version
NEAP prioritization always enabled Starting in ITSI 5.0.1, Notable Event Aggregation Policy prioritization is always enabled. When more than one policy matches an event, only the highest-priority matching policy or tied policies process the event. The previous feature flag and opt-out behavior are removed. Review policy priorities before upgrade. 5.0.1
EventIQ Detect default when switching grouping mode Selecting Dynamic grouping no longer enables EventIQ Detect automatically. A prior explicit enabled state is remembered when switching modes. 5.0.1
Service Discovery SPL Read-only SPL pipelines may begin with a pipe. Commands that write data or are classified as risky remain blocked. 5.0.1
Similar Episodes over Splunk Cloud Connect Vectorized Similar Episodes is supported over Splunk Cloud Connect for eligible Splunk Cloud deployments. 5.0.1
Episode Review saved view permissions Users with effective write permission on a saved Episode Review view can save changes and overwrite the existing view. Users with read-only permission can save a new view but cannot overwrite an existing saved view. 5.0.1
Glass Table saved-search preservation Glass Table save operations preserve ds.savedSearch and other legitimate non-KPI data sources. 5.0.1
KPI alert tag merge KPI alerts receive the union of inherited and service-owned tag values instead of last-write overwrite. 5.0.1
Splunk 10.5 KPI backfill compatibility KPI backfill works on Splunk Enterprise 10.5 without broadly allowing customer risky SPL. 5.0.1
Improved event management experience (Event iQ Detect and Diagnose)

ITSI now includes a more streamlined event management experience for your alerts and episodes.

Event iQ Detect and Event iQ Diagnose leverages AI to provide automated episode summarization, troubleshooting insights, and root cause analysis. Additionally, receive recommendations for high-quality grouping fields to correlate alerts into episodes. This feature bridges the gap between detection and resolution by providing context-rich insights.

See Automate event correlation with Event iQ Detect in ITSI and Use Event iQ Diagnose to analyze episodes with AI.
5.0
Episode Review enhancements

The Episode Review interface has undergone a comprehensive user experience overhaul to streamline troubleshooting. Enhancements include a modernized layout for faster triage, ability to configure custom tabs to align with team workflows, advanced filtering capabilities, and AI-generated insights for faster troubleshooting. See Investigate episodes in ITSI.

Additionally, you now have greater customization options for the Episode Review dashboard that help to surface the most important episode information. See Customize Episode Review in ITSI.
5.0
Enhanced episode summaries Receive additional details about episodes that enhance your troubleshooting experience. When you select an episode from the Episode Review dashboard, you can now view information about the affected services, the suspected root cause, and relevant trends across your logs. For more information, see Investigate episodes in ITSI. 5.0
Flexible alert aggregation Assign a priority value to notable event aggregation policies. ITSI evaluate alerts against these policies in descending order and stops at the first matching policy, ensuring an alert is grouped using the highest ranking policy and into only one episode. See Configure priority for aggregation policies in ITSI. 5.0
Alert enrichment Apply the new Default CMDB CI Enrichment Policy​enrichment policy to any data integration connection to enrich your alerts with additional context to facilitate troubleshooting. See Overview of enrichment policies in ITSI. 5.0

Data integrations

New feature or enhancement Description Version
ITSI MCP tools for AI-assisted investigation ITSI exposes six read-oriented MCP tools through Splunk MCP Server for AI-assisted episode investigation: list episodes, episode details, impacted objects, external links, similar episodes, and stored episode summarization. See Use IT Service Intelligence with Splunk MCP Server. 5.0.1
ServiceNow work note parameter The ServiceNow alert-action work-note parameter is work_notes. Update custom action payloads or integrations that use the former worknotes name. 5.0.1
Alerts Connection migration improvements v1-to-v2 Alerts Connection migration preserves throttling and field mappings. v2 defaults use event fingerprint grouping. 5.0.1
Content Pack improvements The Content Library experience is updated with a modernized interface for managing content pack installation and upgrades. See Overview of content pack management in ITSI. 5.0
New data integrations

ITSI now supports alert ingestion from 4 additional monitoring platforms:

  • Dynatrace

  • Zabbix

  • Oracle Enterprise Manager

  • Datadog

Each integration includes pre-built field mappings that automatically normalize third-party alerts into ITSI's unified alert format. See Available data integrations in ITSI.

5.0

Third-Party Library Upgrades

Supported Platform or Library Upgraded Version Release Version
fast-uri 3.1.2 5.0.1
svgo 3.3.2 5.0.1
jsonata 2.1.0 5.0.1
js-yaml 4.1.1 5.0.1
brace-expansion 1.1.13 5.0.1
immutable 3.8.3 5.0.1
lodash 4.17.21 5.0.1
dompurify 3.4.0 5.0.1

Service Insights

New feature or enhancement Description
Enhanced RBAC for services and episodes

Services and episodes (using NEAPs) can now be shared across teams, cross-team service dependencies can be established, and episodes carry an explicit owner team. Granular, role-based capability checks now apply to mutating actions, giving teams clearer separation of duties and reducing cross-team noise.

  • Cross-team service and episode dependency management improves coordination across departments, supports service sharing, and lets shared services be added as dependencies in services owned by other teams. For more information, see Share a service to a different team and Sharing episodes with other teams using NEAPs.

  • The owner and shared teams logic is retained across Service Analyzer, Health Score, Glass Tables, Deep Dive, and KPI base-search dependents. It provides clearer visibility into related services and episodes while reducing cross-team noise.

  • Governance and security enhancements for large enterprise environments include read-only access for shared teams, owner team control, team-scoped episode filtering, and a team-scoped assignee picker. Episode actions are now governed by four new fine-grained capabilities replacing execute_notable_event_action, see Take action on an episode.

  • Backup and restore now accounts for team structure during partial object backups by automatically selecting dependent services and teams. See Create a partial backup.

Schedule recurring maintenance windows Use advanced scheduling capabilities when defining maintenance windows for your knowledge objects. Clone existing maintenance windows, create multi-day maintenance windows, and extend maintenance windows to external configuration items (CIs). In addition, synchronize maintenance schedules and outages directly from ServiceNow to eliminate manual configuration and reduce false positives. See:
Improved KPI and service tagging You can now apply structured key-value tags to services, service templates, and service sandbox services. Use this enhanced metadata model to easily organize, search, and manage large service inventories. See Add tags to a service in ITSI.
ITSI Admin Console ITSI now provides a centralized Admin Console that surfaces key administrative settings directly in the UI, facilitating ease of access for common configuration changes. See Use the ITSI Advanced Configuration page.