Splunk ITSI

Splunk ITSI - Netcool Integration (kvstore_to_json.py question)

lloydknight
Builder

Hello Splunkers,

So I'm planning to follow the Splunk Blog link below:
https://www.splunk.com/blog/2018/05/17/ingest-netcool-alerts-into-splunk-itsi-event-analytics.html

Already checked the prerequisites.
My questions are:

  1. Has anybody tried the link and encountered any issue?
  2. So kvstore_to_json.py is involved. It says in the blog that:

6.b. Restore the aggregation policy on the ITSI server via the kvstore_to_json.py command line utility. When prompted for the version of the backup, enter 2.6.

I'm just concerned on this part as I have already encountered an issue in upgrading Splunk ITSI before from the earliest version up to 3. Filed a ticket and the ticket was actually not resolved.

How does this restore aggregation policy work? Are there any possible impact or risk on this?

Much appreciated!

-Lloyd

0 Karma

mwiser_splunk
Splunk Employee
Splunk Employee

Lloyd - the restore basically auto-creates the agg policy for you from the backup. If I read your question correctly and you already have unresolved KV store issues - I would prioritize fixing those or creating a manual aggregation policy based on the guidance here https://docs.splunk.com/Documentation/ITSI/4.3.1/Configure/HowtocreateAggregationPolicies rather than doing the KV store import.

0 Karma
Get Updates on the Splunk Community!

Let’s Talk Terraform

If you’re beyond the first-weeks-of-a-startup stage, chances are your application’s architecture is pretty ...

Cloud Platform | Customer Change Announcement: Email Notification is Available For ...

The Notification Team is migrating our email service provider. As the rollout progresses, Splunk has enabled ...

Save the Date: GovSummit Returns Wednesday, December 11th!

Hey there, Splunk Community! Exciting news: Splunk’s GovSummit 2024 is returning to Washington, D.C. on ...