Splunk ITSI

Splunk IT Service Intelligence: Why am I getting message 'IT Service Intelligence upgrade has failed' after upgrade to 2.2.0?

thilleso
Path Finder

Hi,

We've updated IT Service Intelligence from 2.1.0 to 2.2.0 according to the documentation (I don't have enough karma points to post links, but using the latest ITSI documentation), and at step 7, a message "IT Service Intelligence upgrade has completed successfully" in Splunk Web should appear. The problem is that we get the message "IT Service Intelligence upgrade has failed".
I've tried restarting Splunk from CLI several times, but always the same message appears.

However, all the new functionality from 2.2 is present, and in the Manage Apps console, ITSI is listed with version 2.2.0. All previously configured services, KPIs, deep-dives and so on are also functioning like normal.

So right now, it seems ITSI has upgraded okey, but Splunk doesn't seem to agree with itself. Have anyone experienced the same issue?

Info about our environment:
- Search Head: Linux CentOS 7, Splunk Enterprise 6.3
- Indexer: Linux CentOS 7, Splunk Enterprise 6.3

Thanks!

0 Karma
1 Solution

thilleso
Path Finder

Update: Found a ITSI python prosess running wild on the server, probably locking down some process used by 2.1.0. After killing it and restarting Splunk, the update successfully message appeared.

View solution in original post

0 Karma

thilleso
Path Finder

Update: Found a ITSI python prosess running wild on the server, probably locking down some process used by 2.1.0. After killing it and restarting Splunk, the update successfully message appeared.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...