Splunk Enterprise

ITSI install on Splunk enterprise

Xiaorq
Explorer

Dear Team, 

We have obtained the ITSI installation package "splunk-it-service-intelligence-4193. spl" and installed it according to the installation guide on the official website“ https://docs.splunk.com/Documentation/ITSI/4.20.0/Install/Install ”.

In the end, the Splunk Enterprise platform only has the ITEM app. What is the reason for this? Please provide technical support.

Thank you.

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @Xiaorq 

It looks like you have a regular ingest license, plus the ITSI Internal license (this is for sourcetype=itsi_* - Used for internal ITSI metadata etc) however it doesnt look like you have the actual ITSI License which unlocks ITSI to be used. I see you are on a Sales Trial license - did the sales team provide you an additional ITSI license? I would recommend reaching out to them to check they've given you the correct license(s) to run ITSI.

Check out https://www.youtube.com/watch?v=SUQpN8Re66g which might help too.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @Xiaorq 

Just to check is it IT Essentials Work (ITEW) that you see installed?

If you install ITSI but do not apply the ITSI License to your environment then I believe it reverts to ITEW (see https://splunk.my.site.com/customer/s/article/ITSI-app-reverted-to-IT-Essential-Work-IT-W-and-does-n...)

Please can you confirm if you have installed your ITSI specific license? The install location depends on your environment configuration/architecture - please see https://docs.splunk.com/Documentation/ITSI/4.20.0/Install/InstallDD for more info.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Xiaorq
Explorer

2025-04-14 21:48:49,293 INFO [root] [itsi_license_checker] [do_run] Modular input is starting... 2025-04-14 21:48:49,551 INFO [itsi.license_checker.SplunkLicensesAPI] [splunk_licenses_api] [is_license_dependent] Checking is license dependent : License manager uri : self : 2025-04-14 21:48:49,551 INFO [root] [itsi_license_checker] [do_run] Modular input is running... 2025-04-14 21:48:49,558 INFO [itsi.license_checker.ItsiInternalLicensesGroupFactory] [itsi_internal_licenses_group_factory] [_get_active_subgroup] Active license group: Enterprise 2025-04-14 21:48:49,638 INFO [itsi.license_checker.ItsiInternalLicensesGroupFactory] [itsi_internal_licenses_group_factory] [_get_active_subgroup] Non ITSI internal licenses in active group: [<license.License object at 0x7f3317aa22e0>] 2025-04-14 21:48:49,639 INFO [itsi.license_checker.ItsiInternalLicensesGroupFactory] [itsi_internal_licenses_group_factory] [get_license_group] Active subgroup: Production 2025-04-14 21:48:49,647 INFO [itsi.license_checker.LicenseManager] [license_manager] [manage_license_expiration_signaling_license] No real ITSI license is installed 2025-04-14 21:48:49,647 INFO [root] [itsi_license_checker] [do_run] Modular input completed successfully 2025-04-14 21:48:49,647 INFO [root] [modular_input] [execute] Modular input: itsi_license_checker exit normally. 2025-04-14 21:49:49,277 INFO [root] [itsi_license_checker] [do_run] Modular input is starting... Splunk Enterprise Sales Trial 307,200 MB 2025年5月22日 上午2:59:59 有效 IT Service Intelligence Internals *DO NOT COPY* 102,400,000 MB 2038年1月18日 下午10:14:07 有效 The above informations are logs and licenses. Please help confirm: Can the ITSI run normally? Thank you.

0 Karma

Xiaorq
Explorer
2025-04-14 21:48:49,293 INFO [root] [itsi_license_checker] [do_run] Modular input is starting...
2025-04-14 21:48:49,551 INFO [itsi.license_checker.SplunkLicensesAPI] [splunk_licenses_api] [is_license_dependent] Checking is license dependent : License manager uri : self :
2025-04-14 21:48:49,551 INFO [root] [itsi_license_checker] [do_run] Modular input is running...
2025-04-14 21:48:49,558 INFO [itsi.license_checker.ItsiInternalLicensesGroupFactory] [itsi_internal_licenses_group_factory] [_get_active_subgroup] Active license group: Enterprise
2025-04-14 21:48:49,638 INFO [itsi.license_checker.ItsiInternalLicensesGroupFactory] [itsi_internal_licenses_group_factory] [_get_active_subgroup] Non ITSI internal licenses in active group: [<license.License object at 0x7f3317aa22e0>]
2025-04-14 21:48:49,639 INFO [itsi.license_checker.ItsiInternalLicensesGroupFactory] [itsi_internal_licenses_group_factory] [get_license_group] Active subgroup: Production
2025-04-14 21:48:49,647 INFO [itsi.license_checker.LicenseManager] [license_manager] [manage_license_expiration_signaling_license] No real ITSI license is installed
2025-04-14 21:48:49,647 INFO [root] [itsi_license_checker] [do_run] Modular input completed successfully
2025-04-14 21:48:49,647 INFO [root] [modular_input] [execute] Modular input: itsi_license_checker exit normally.
2025-04-14 21:49:49,277 INFO [root] [itsi_license_checker] [do_run] Modular input is starting...
2025-04-14 21:49:49,531 INFO [itsi.license_checker.SplunkLicensesAPI] [splunk_licenses_api] [is_license_dependent] Checking is license dependent : License manager uri : self :
2025-04-14 21:49:49,531 INFO [root] [itsi_license_checker] [do_run] Modular input is running...
2025-04-14 21:49:49,538 INFO [itsi.license_checker.ItsiInternalLicensesGroupFactory] [itsi_internal_licenses_group_factory] [_get_active_subgroup] Active license group: Enterprise
2025-04-14 21:49:49,618 INFO [itsi.license_checker.ItsiInternalLicensesGroupFactory] [itsi_internal_licenses_group_factory] [_get_active_subgroup] Non ITSI internal licenses in active group: [<license.License object at 0x7f57146e22e0>]
2025-04-14 21:49:49,618 INFO [itsi.license_checker.ItsiInternalLicensesGroupFactory] [itsi_internal_licenses_group_factory] [get_license_group] Active subgroup: Production
2025-04-14 21:49:49,626 INFO [itsi.license_checker.LicenseManager] [license_manager] [manage_license_expiration_signaling_license] No real ITSI license is installed
2025-04-14 21:49:49,626 INFO [root] [itsi_license_checker] [do_run] Modular input completed successfully
2025-04-14 21:49:49,626 INFO [root] [modular_input] [execute] Modular input: itsi_license_checker exit normally.

 

Splunk Enterprise Sales Trial 307,200 MB 2025年5月22日 上午2:59:59 有效

IT Service Intelligence Internals *DO NOT COPY* 102,400,000 MB 2038年1月18日 下午10:14:07 有效

 

 

The above informations are logs and licenses. Please help confirm: Can the ITSI run normally?

Thank you.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Xiaorq 

It looks like you have a regular ingest license, plus the ITSI Internal license (this is for sourcetype=itsi_* - Used for internal ITSI metadata etc) however it doesnt look like you have the actual ITSI License which unlocks ITSI to be used. I see you are on a Sales Trial license - did the sales team provide you an additional ITSI license? I would recommend reaching out to them to check they've given you the correct license(s) to run ITSI.

Check out https://www.youtube.com/watch?v=SUQpN8Re66g which might help too.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

isoutamo
SplunkTrust
SplunkTrust

Actually ITSI and IT Essential Work are same product (only one download package). The only difference is that ITSI needs official license to enable those additional features. You could say that ITEW is just sales tool for ITSI 😉

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...