Splunk IT Service Intelligence

Splunk ITSI Services,KPI base searches,Corr search , Aggregation policy all missing after setting up SH and Indexer Cluster

New Member

Hi All,
Recently i upgraded my standalone env to SH and Indexer cluster one major thing i notice is all my previous works like Services,entities,correlation search,notable event aggregation policies are missing.
Basically it's set back to default.

Where and how can i restore my previous work ?

0 Karma

Splunk Employee
Splunk Employee

Hi, @prafullwt , which version did you upgrade from and to which version?
Maybe it is being migrated. Did you see any errors with the following search?
index=_internal sourcetype="itsi_internal_log" source="*itsi_upgrade*"

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!