Hi @srauhala_splunk , I have checked the ITSI Event Analytics Dashboard. I see Java 11 is installed. Additionally I see below errors as well. Rules engine status is 1. But episodes are are in sync in the search head members and also it is not getting updated properly. 12:02:00,629 ERROR [itsi_re(reId=ypQe)] [main] TaskManager:297 - Status=Failed, FunctionName=SetupSplunkServices, ErrorMessage="no protocol: ", StackTrace=java.net.MalformedURLException: no protocol: at java.base/java.net.URL.<init>(URL.java:645) at java.base/java.net.URL.<init>(URL.java:541) at java.base/java.net.URL.<init>(URL.java:488) at com.splunk.itsi.event.management.sdk.SplunkServiceUtils.getService(SplunkServiceUtils.java:53) at com.splunk.itsi.rule.engine.core.TaskManager.setup(TaskManager.java:1205) at com.splunk.itsi.rule.engine.core.TaskManager.<init>(TaskManager.java:295) at com.splunk.itsi.search.chunk.RulesEngineSearch.main(RulesEngineSearch.java:49) ERROR [itsi_re(reId=OuPx,reMode=RealTime)] [itsiruleengine-akka.actor.default-dispatcher-2] CommonUtils:331 - FunctionName=isAnyClusterInRollingRestartOrUpgrade, Status=Failed, ErrorMessage="Skipping cluster rolling restart status check. Unable to get cluster config due to exception calling REST endpoint".
... View more