Known issues in Splunk IT Service Intelligence

IT Service Intelligence (ITSI) has the following known issues and workarounds.

Service Templates

Date filed Issue number Description
2026-07-2 ITSI-45498

In a Service Template, manually editing a KPI that uses AI-recommended adaptive thresholds unlinks the recommendation, and Revert changes then fails without restoring the previous configuration. Saving the template after a failed Revert can propagate the unintended thresholds to every linked service.

Workaround: Do not save the template after Revert fails. Discard the unsaved changes using the page-level Cancel action, or reload or navigate away from the page. Then reopen the template and reapply only the changes you intend. If you already saved, regenerate the AI recommendation or manually restore your known-good threshold values. There is no way to selectively undo a single threshold change in the affected UI.

5.0.1

Notable Events

Date filed Issue number Description
2026-06-28 ITSI-45422

An event that occurred before a maintenance window began but is indexed after the window opens can be tagged as impacted by that window and suppressed. A problem that started before maintenance can therefore be hidden instead of surfaced for triage. This depends on indexing lag, so it affects deployments where events can arrive materially later than the time they occurred.

Workaround: None. To identify affected episodes, compare the episode start and end times against the maintenance window interval. An episode that ended before the window started is suppressed in error and still needs triage.

5.0.1

Event Analytics

Date filed Issue number Description Release version
2026-07-13 ITSI-45600 Upgrade handler does not move the earliest or latest SPL's to the input box.

Workaround:

After you upgrade an ITSI 5.0.0 connection from version 1 to version 2, complete the following steps:

  1. On the alert configuration page, enable throttling, and then select Save.

  2. Go to the Searches, Reports, and Alerts page. Locate the saved search named DATA_INTEGRATION_CS-<connection_name>, where <connection_name> is the name of your connection.

  3. Select Edit, and then select Advanced Edit. For alert.suppress.fields, enter event_fingerprint.

  4. Save your changes.

5.0
2026-07-20 ITSI-45693 EventiQ Diagnose may appear unavailable on Splunk Enterprise when the user can run ITSI actions, but does not have read access to the Splunk Cloud Connect app.

Workaround:

  1. Go to Settings then Apps then Manage Apps.

  2. Find Splunk Cloud Connect in the list of installed apps.

  3. You can search for either:

    1. Splunk Cloud Connect

    2. splunk_cloud_connect

  4. Select Permissions for the Splunk Cloud Connect app. In the role permissions table, grant read access to each ITSI role whose users need EventiQ Diagnose. Common roles include: itoa_admin, itoa_team_admin, itoa_analyst. EventiQ users require only read access for this workaround.

  5. Select Save. Ask affected users to sign out of Splunk and sign back in. Refresh Episode Review and confirm that the EventiQ Diagnose action is available.

5.0