ITSI upgrades require careful planning. The general sequence is: backup ITSI, upgrade Splunk Enterprise first, then upgrade the ITSI app. After upgrading, run the ITSI Health Check and Upgrade Readiness dashboards to verify that all services, KPIs, and entities migrated correctly.
When migrating ITSI between environments (e.g., from on-premises to cloud), use the backup/restore utility to export configuration, then import it into the target environment. Adjust entity rules and base searches that reference environment-specific indexes or sourcetypes. Maintenance windows should be configured during migration to suppress false alerts.