New features in Splunk IT Service Intelligence
This version has these new and changed features.
General
| New feature or enhancement | Description | Release Version |
|---|---|---|
| Java Support Update | IT Service Intelligence 5.0.1 requires Java 17 (minimum) and supports up to Java 21. Java 8 and Java 11 are no longer supported. See Java Requirements. | 5.0.1 |
| Security hardening | Splunk IT Service Intelligence 5.0.1 includes extensive security hardening across Event Analytics, Episode Review, data integrations, Glass Tables, Entity Detail, Service Sandbox, and role-based access controls. This release addresses a large set of internally validated vulnerabilities through input validation, fail-closed handling, safer URL and SPL boundaries, and corrected collection permissions. Customer-visible outcomes include:
|
5.0.1 |
Event Analytics
| New feature or enhancement | Description | Version |
|---|---|---|
| NEAP prioritization always enabled | Starting in ITSI 5.0.1, Notable Event Aggregation Policy prioritization is always enabled. When more than one policy matches an event, only the highest-priority matching policy or tied policies process the event. The previous feature flag and opt-out behavior are removed. Review policy priorities before upgrade. | 5.0.1 |
| EventIQ Detect default when switching grouping mode | Selecting Dynamic grouping no longer enables EventIQ Detect automatically. A prior explicit enabled state is remembered when switching modes. | 5.0.1 |
| Service Discovery SPL | Read-only SPL pipelines may begin with a pipe. Commands that write data or are classified as risky remain blocked. | 5.0.1 |
| Similar Episodes over Splunk Cloud Connect | Vectorized Similar Episodes is supported over Splunk Cloud Connect for eligible Splunk Cloud deployments. | 5.0.1 |
| Episode Review saved view permissions | Users with effective write permission on a saved Episode Review view can save changes and overwrite the existing view. Users with read-only permission can save a new view but cannot overwrite an existing saved view. | 5.0.1 |
| Glass Table saved-search preservation | Glass Table save operations preserve ds.savedSearch and other legitimate non-KPI data sources. |
5.0.1 |
| KPI alert tag merge | KPI alerts receive the union of inherited and service-owned tag values instead of last-write overwrite. | 5.0.1 |
| Splunk 10.5 KPI backfill compatibility | KPI backfill works on Splunk Enterprise 10.5 without broadly allowing customer risky SPL. | 5.0.1 |
| Improved event management experience (Event iQ Detect and Diagnose) |
ITSI now includes a more streamlined event management experience for your alerts and episodes. Event iQ Detect and Event iQ Diagnose leverages AI to provide automated episode summarization, troubleshooting insights, and root cause analysis. Additionally, receive recommendations for high-quality grouping fields to correlate alerts into episodes. This feature bridges the gap between detection and resolution by providing context-rich insights. See Automate event correlation with Event iQ Detect in ITSI and Use Event iQ Diagnose to analyze episodes with AI. |
5.0 |
| Episode Review enhancements |
The Episode Review interface has undergone a comprehensive user experience overhaul to streamline troubleshooting. Enhancements include a modernized layout for faster triage, ability to configure custom tabs to align with team workflows, advanced filtering capabilities, and AI-generated insights for faster troubleshooting. See Investigate episodes in ITSI. Additionally, you now have greater customization options for the Episode Review dashboard that help to surface the most important episode information. See Customize Episode Review in ITSI. |
5.0 |
| Enhanced episode summaries | Receive additional details about episodes that enhance your troubleshooting experience. When you select an episode from the Episode Review dashboard, you can now view information about the affected services, the suspected root cause, and relevant trends across your logs. For more information, see Investigate episodes in ITSI. | 5.0 |
| Flexible alert aggregation | Assign a priority value to notable event aggregation policies. ITSI evaluate alerts against these policies in descending order and stops at the first matching policy, ensuring an alert is grouped using the highest ranking policy and into only one episode. See Configure priority for aggregation policies in ITSI. | 5.0 |
| Alert enrichment | Apply the new Default CMDB CI Enrichment Policyenrichment policy to any data integration connection to enrich your alerts with additional context to facilitate troubleshooting. See Overview of enrichment policies in ITSI. | 5.0 |
Data integrations
| New feature or enhancement | Description | Version |
|---|---|---|
| ITSI MCP tools for AI-assisted investigation | ITSI exposes six read-oriented MCP tools through Splunk MCP Server for AI-assisted episode investigation: list episodes, episode details, impacted objects, external links, similar episodes, and stored episode summarization. See Use IT Service Intelligence with Splunk MCP Server. | 5.0.1 |
| ServiceNow work note parameter | The ServiceNow alert-action work-note parameter is work_notes. Update custom action payloads or integrations that use the former worknotes name. |
5.0.1 |
| Alerts Connection migration improvements | v1-to-v2 Alerts Connection migration preserves throttling and field mappings. v2 defaults use event fingerprint grouping. | 5.0.1 |
| Content Pack improvements | The Content Library experience is updated with a modernized interface for managing content pack installation and upgrades. See Overview of content pack management in ITSI. | 5.0 |
| New data integrations |
ITSI now supports alert ingestion from 4 additional monitoring platforms:
Each integration includes pre-built field mappings that automatically normalize third-party alerts into ITSI's unified alert format. See Available data integrations in ITSI. |
5.0 |
Third-Party Library Upgrades
| Supported Platform or Library | Upgraded Version | Release Version |
|---|---|---|
fast-uri |
3.1.2 | 5.0.1 |
svgo |
3.3.2 | 5.0.1 |
jsonata |
2.1.0 | 5.0.1 |
js-yaml |
4.1.1 | 5.0.1 |
brace-expansion |
1.1.13 | 5.0.1 |
immutable |
3.8.3 | 5.0.1 |
lodash |
4.17.21 | 5.0.1 |
dompurify |
3.4.0 | 5.0.1 |
Service Insights
| New feature or enhancement | Description |
|---|---|
| Enhanced RBAC for services and episodes |
Services and episodes (using NEAPs) can now be shared across teams, cross-team service dependencies can be established, and episodes carry an explicit owner team. Granular, role-based capability checks now apply to mutating actions, giving teams clearer separation of duties and reducing cross-team noise.
|
| Schedule recurring maintenance windows | Use advanced scheduling capabilities when defining maintenance windows for your knowledge objects. Clone existing maintenance windows, create multi-day maintenance windows, and extend maintenance windows to external configuration items (CIs). In addition, synchronize maintenance schedules and outages directly from ServiceNow to eliminate manual configuration and reduce false positives. See: |
| Improved KPI and service tagging | You can now apply structured key-value tags to services, service templates, and service sandbox services. Use this enhanced metadata model to easily organize, search, and manage large service inventories. See Add tags to a service in ITSI. |
| ITSI Admin Console | ITSI now provides a centralized Admin Console that surfaces key administrative settings directly in the UI, facilitating ease of access for common configuration changes. See Use the ITSI Advanced Configuration page. |