<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Grouping aggregation events into episode. Splunk and solarwinds Integration in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483396#M1827</link>
    <description>&lt;P&gt;I'm not able to generate episode with or without  smart mode.&lt;BR /&gt;
I see entries in index="itsi_tracked_alerts"&lt;/P&gt;

&lt;P&gt;Every minutes i see in internal logs:&lt;/P&gt;

&lt;P&gt;index=_internal  itsi_event_grouping&lt;/P&gt;

&lt;P&gt;02-10-2020 00:38:30.664 +0100 INFO  StreamedSearch - Streamed search search starting: search_id=remote_server01_rt_1581291503.609, server=server01, active_searches=3, search='rtlitsearch (index=_internal itsi_event_grouping)  | fields keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"', remote_ttl=600, apiStartTime='MIN_TIME', apiEndTime='MIN_TIME', savedsearch_name=""&lt;/P&gt;

&lt;P&gt;How can i check in different way  that itsi_event_grouping saved search is running?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:04:19 GMT</pubDate>
    <dc:creator>pedro_77</dc:creator>
    <dc:date>2020-09-30T04:04:19Z</dc:date>
    <item>
      <title>Grouping aggregation events into episode. Splunk and solarwinds Integration</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483394#M1825</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I'm trying to build dashboard in ITSI with active alarms from Solarwinds and other monitoring tools. I'm retrieving alarms from Solar via API (solarwinds addon). One of the next step is to use aggregation policy. I've noticed that whatever i type in 'split events by field' form no episodes are created.&lt;/P&gt;
&lt;P&gt;For example i use below fields:&lt;BR /&gt;include events: EvenType *&lt;BR /&gt;split events by field: orig_AlertActiveID (or AlertActiveID)&lt;/P&gt;
&lt;P&gt;Also noticed that when i'm trying to use smart mode, ITSI cannot find any event, even if re-run analyze for 30 days.&lt;/P&gt;
&lt;P&gt;How can i troubleshoot this further?&lt;BR /&gt;Thanks&lt;BR /&gt;Piotr&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 00:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483394#M1825</guid>
      <dc:creator>pedro_77</dc:creator>
      <dc:date>2020-06-07T00:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping aggregation events into episode. Splunk and solarwinds Integration</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483395#M1826</link>
      <description>&lt;P&gt;Would you check if itsi_event_grouping saved search is running? Are you able to generate episodes without enabling smart mode?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:08:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483395#M1826</guid>
      <dc:creator>szhou_splunk</dc:creator>
      <dc:date>2020-09-30T04:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping aggregation events into episode. Splunk and solarwinds Integration</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483396#M1827</link>
      <description>&lt;P&gt;I'm not able to generate episode with or without  smart mode.&lt;BR /&gt;
I see entries in index="itsi_tracked_alerts"&lt;/P&gt;

&lt;P&gt;Every minutes i see in internal logs:&lt;/P&gt;

&lt;P&gt;index=_internal  itsi_event_grouping&lt;/P&gt;

&lt;P&gt;02-10-2020 00:38:30.664 +0100 INFO  StreamedSearch - Streamed search search starting: search_id=remote_server01_rt_1581291503.609, server=server01, active_searches=3, search='rtlitsearch (index=_internal itsi_event_grouping)  | fields keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"', remote_ttl=600, apiStartTime='MIN_TIME', apiEndTime='MIN_TIME', savedsearch_name=""&lt;/P&gt;

&lt;P&gt;How can i check in different way  that itsi_event_grouping saved search is running?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483396#M1827</guid>
      <dc:creator>pedro_77</dc:creator>
      <dc:date>2020-09-30T04:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping aggregation events into episode. Splunk and solarwinds Integration</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483397#M1828</link>
      <description>&lt;P&gt;You can go to Settings -&amp;gt; Searches, reports and alerts -&amp;gt; Search for "itsi_event_grouping" for all apps. And you can verify if itsi_event_grouping is running or failed.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483397#M1828</guid>
      <dc:creator>szhou_splunk</dc:creator>
      <dc:date>2020-09-30T04:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping aggregation events into episode. Splunk and solarwinds Integration</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483398#M1829</link>
      <description>&lt;P&gt;i see:&lt;BR /&gt;
status is enabled&lt;BR /&gt;
Next Scheduled Time: none&lt;BR /&gt;
Alerts: 0&lt;BR /&gt;
Sharing: global&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 00:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483398#M1829</guid>
      <dc:creator>pedro_77</dc:creator>
      <dc:date>2020-02-10T00:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping aggregation events into episode. Splunk and solarwinds Integration</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483399#M1830</link>
      <description>&lt;P&gt;Would you click the "View Recent" link see if it is running?&lt;BR /&gt;
Also check if the index itsi_grouped_alerts has events.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483399#M1830</guid>
      <dc:creator>szhou_splunk</dc:creator>
      <dc:date>2020-09-30T04:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping aggregation events into episode. Splunk and solarwinds Integration</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483400#M1831</link>
      <description>&lt;P&gt;in Action tab there is no recent view for this search&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 00:52:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483400#M1831</guid>
      <dc:creator>pedro_77</dc:creator>
      <dc:date>2020-02-10T00:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping aggregation events into episode. Splunk and solarwinds Integration</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483401#M1832</link>
      <description>&lt;P&gt;How about Activities -&amp;gt; Jobs , and search for itsi_event_grouping?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:08:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483401#M1832</guid>
      <dc:creator>szhou_splunk</dc:creator>
      <dc:date>2020-09-30T04:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping aggregation events into episode. Splunk and solarwinds Integration</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483402#M1833</link>
      <description>&lt;P&gt;There is no itsi_event_grouping in JOBS&lt;BR /&gt;
In search there is no itsi_event_grouping search as scheduled. Next Scheduled Time filed is empty.&lt;BR /&gt;
I did test installation on Centos and problem is the same. No  itsi_event_grouping search as job or scheduled search.&lt;/P&gt;

&lt;P&gt;On Linux java version:  is openjdk version "1.8.0_242"&lt;BR /&gt;
OpenJDK Runtime Environment (build 1.8.0_242-b08)&lt;BR /&gt;
OpenJDK 64-Bit Server VM (build 25.242-b08, mixed mode)&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:05:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483402#M1833</guid>
      <dc:creator>pedro_77</dc:creator>
      <dc:date>2020-09-30T04:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping aggregation events into episode. Splunk and solarwinds Integration</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483403#M1834</link>
      <description>&lt;P&gt;On Windows even worse, in Notable Event Aggregation Policy in preview windows i  have error :&lt;/P&gt;

&lt;P&gt;Error in 'itsirulesengine' command: External search command exited unexpectedly with non-zero error code 1.&lt;/P&gt;

&lt;P&gt;java version "1.8.0_241"&lt;BR /&gt;
Java(TM) SE Runtime Environment (build 1.8.0_241-b07)&lt;BR /&gt;
Java HotSpot(TM) Client VM (build 25.241-b07, mixed mode, sharing&lt;/P&gt;

&lt;P&gt;echo %JAVA_HOME%&lt;BR /&gt;
C:\Program Files (x86)\Java\jre1.8.0_241\&lt;/P&gt;

&lt;P&gt;AV disabled&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Grouping-aggregation-events-into-episode-Splunk-and-solarwinds/m-p/483403#M1834</guid>
      <dc:creator>pedro_77</dc:creator>
      <dc:date>2020-09-30T04:05:24Z</dc:date>
    </item>
  </channel>
</rss>

