Troubleshoot upgrading AI Toolkit in Splunk Enterprise Security
Following are some issues that you might see when using the AI Toolkit (AITK) in Splunk Enterprise Security:
Machine learning models not displayed upon upgrade
Issue: Splunk Enterprise Security version 8.7 is compatible with Splunk AI Toolkit (AITK) version 6.0.2 and Python Scientific Computing (PSC) version 3.3.3. However, after upgrading to AITK 6.0.2, you can't view machine learning models by default. The Machine learning models table on the Machine learning audit dashboard is empty and custom searches that list machine learning models stop working.
Cause: The list_models capability must be turned on for roles that need the ability to list machine learning models.
Solution: You must have the list_models capability turned on to view available machine learning models when you upgrade to AITK version 6.0.2. The Audit - MLTK models saved search is configured to run under the admin namespace, so you must turn on the list_models capability for the admin user.