<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple event_id is created in itsi_tracked_alerts from correlation searches in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/Multiple-event-id-is-created-in-itsi-tracked-alerts-from/m-p/387750#M673</link>
    <description>&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Is your search returning more than 1 event when it runs ?&lt;BR /&gt;
If it does, maybe massage your events, like using a  "|dedup " or "| head 1" to trim them before the notables are created.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;If your events results are unique but get indexed twice&lt;BR /&gt;
check the _indextime of the notable events, to figure when they were created.&lt;BR /&gt;
Check if you have a useack=true enable in the outputs.conf of your search-head (it can cause the forwarder to attempt to send the same events multiple time in case of network failure)&lt;BR /&gt;
check if you are not cloning your data to 2 sets of indexers&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Thu, 24 Oct 2019 23:00:40 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2019-10-24T23:00:40Z</dc:date>
    <item>
      <title>Multiple event_id is created in itsi_tracked_alerts from correlation searches</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Multiple-event-id-is-created-in-itsi-tracked-alerts-from/m-p/387749#M672</link>
      <description>&lt;P&gt;Need help in understanding Notable event, I am using correlation search to create Notable event, where my search has “time_range and schedule as 5min” which return single result(ie single event)&lt;/P&gt;

&lt;P&gt;However I am able to see 2 event_id within itsi_tracked_alerts index for same search thus resulting into Notable event count 2 in Episode review in ITSI.&lt;/P&gt;

&lt;P&gt;index=itsi_tracked_alerts sourcetype="itsi_notable:event" project=”abc” :- 2 event with 2 different event_id.&lt;/P&gt;

&lt;P&gt;Correlation serach:---- generates only 1 event.&lt;/P&gt;

&lt;P&gt;I am not sure why 2 event are created in “itsi_tracked_alerts” for project “abc”. Where according to correlation serach it should only generate 1 event id. &lt;/P&gt;

&lt;P&gt;Please help&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:40:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Multiple-event-id-is-created-in-itsi-tracked-alerts-from/m-p/387749#M672</guid>
      <dc:creator>bpratap</dc:creator>
      <dc:date>2020-09-30T00:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple event_id is created in itsi_tracked_alerts from correlation searches</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Multiple-event-id-is-created-in-itsi-tracked-alerts-from/m-p/387750#M673</link>
      <description>&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Is your search returning more than 1 event when it runs ?&lt;BR /&gt;
If it does, maybe massage your events, like using a  "|dedup " or "| head 1" to trim them before the notables are created.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;If your events results are unique but get indexed twice&lt;BR /&gt;
check the _indextime of the notable events, to figure when they were created.&lt;BR /&gt;
Check if you have a useack=true enable in the outputs.conf of your search-head (it can cause the forwarder to attempt to send the same events multiple time in case of network failure)&lt;BR /&gt;
check if you are not cloning your data to 2 sets of indexers&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 24 Oct 2019 23:00:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Multiple-event-id-is-created-in-itsi-tracked-alerts-from/m-p/387750#M673</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2019-10-24T23:00:40Z</dc:date>
    </item>
  </channel>
</rss>

