Known issues in Splunk IT Service Intelligence
IT Service Intelligence (ITSI) has the following known issues and workarounds.
Service Templates
| Date filed | Issue number | Description | |
|---|---|---|---|
| 2026-07-2 | ITSI-45498 |
In a Service Template, manually editing a KPI that uses AI-recommended adaptive thresholds unlinks the recommendation, and Revert changes then fails without restoring the previous configuration. Saving the template after a failed Revert can propagate the unintended thresholds to every linked service. Workaround: Do not save the template after Revert fails. Discard the unsaved changes using the page-level Cancel action, or reload or navigate away from the page. Then reopen the template and reapply only the changes you intend. If you already saved, regenerate the AI recommendation or manually restore your known-good threshold values. There is no way to selectively undo a single threshold change in the affected UI. |
5.0.1 |
Notable Events
| Date filed | Issue number | Description | |
|---|---|---|---|
| 2026-06-28 | ITSI-45422 |
An event that occurred before a maintenance window began but is indexed after the window opens can be tagged as impacted by that window and suppressed. A problem that started before maintenance can therefore be hidden instead of surfaced for triage. This depends on indexing lag, so it affects deployments where events can arrive materially later than the time they occurred. Workaround: None. To identify affected episodes, compare the episode start and end times against the maintenance window interval. An episode that ended before the window started is suppressed in error and still needs triage. |
5.0.1 |
Event Analytics
| Date filed | Issue number | Description | Release version |
|---|---|---|---|
| 2026-07-13 | ITSI-45600 | Upgrade handler does not move the earliest or latest SPL's to the input box.
Workaround: After you upgrade an ITSI 5.0.0 connection from version 1 to version 2, complete the following steps:
|
5.0 |
| 2026-07-20 | ITSI-45693 | EventiQ Diagnose may appear unavailable on Splunk Enterprise when the user can run ITSI actions, but does not have read access to the Splunk Cloud Connect app.
Workaround:
|
5.0 |