<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ITSI - Episode Review - 1 KPI in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394549#M767</link>
    <description>&lt;P&gt;I'm stuck doing something on the first link.&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;...but we’re going to wind up modifying it slightly so we’ll duplicate the existing rule and make our modifications to the copy...&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;How do you duplicate it? I don't see that option.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Feb 2019 16:50:57 GMT</pubDate>
    <dc:creator>arthurva</dc:creator>
    <dc:date>2019-02-22T16:50:57Z</dc:date>
    <item>
      <title>ITSI - Episode Review - 1 KPI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394546#M764</link>
      <description>&lt;P&gt;I'm very new to Splunk and ITSI. We have created a service for VMware VMs. The Service has several KPIs like memory and CPU. A few of the VMs have CPUs in Critical status. Episode Review shows 0 episodes. Is it possible to have the specific servers show up in Episode Review?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 00:58:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394546#M764</guid>
      <dc:creator>arthurva</dc:creator>
      <dc:date>2019-02-22T00:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI - Episode Review - 1 KPI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394547#M765</link>
      <description>&lt;P&gt;By default, these won't create episodes. &lt;/P&gt;

&lt;P&gt;There is a great blog series that will show you how to configure the alerting for ITSI:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2019/01/18/a-blueprint-for-splunk-itsi-alerting-step-1.html"&gt;https://www.splunk.com/blog/2019/01/18/a-blueprint-for-splunk-itsi-alerting-step-1.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2019/02/01/a-blueprint-for-splunk-itsi-alerting-step-2.html"&gt;https://www.splunk.com/blog/2019/02/01/a-blueprint-for-splunk-itsi-alerting-step-2.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2019/02/08/a-blueprint-for-splunk-itsi-alerting-step-3.html"&gt;https://www.splunk.com/blog/2019/02/08/a-blueprint-for-splunk-itsi-alerting-step-3.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2019/02/14/a-blueprint-for-splunk-itsi-alerting-step-4.html"&gt;https://www.splunk.com/blog/2019/02/14/a-blueprint-for-splunk-itsi-alerting-step-4.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;BR /&gt;
Chris.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 01:02:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394547#M765</guid>
      <dc:creator>chrisyounger</dc:creator>
      <dc:date>2019-02-22T01:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI - Episode Review - 1 KPI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394548#M766</link>
      <description>&lt;P&gt;I'll start reading them. Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 01:05:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394548#M766</guid>
      <dc:creator>arthurva</dc:creator>
      <dc:date>2019-02-22T01:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI - Episode Review - 1 KPI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394549#M767</link>
      <description>&lt;P&gt;I'm stuck doing something on the first link.&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;...but we’re going to wind up modifying it slightly so we’ll duplicate the existing rule and make our modifications to the copy...&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;How do you duplicate it? I don't see that option.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:50:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394549#M767</guid>
      <dc:creator>arthurva</dc:creator>
      <dc:date>2019-02-22T16:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI - Episode Review - 1 KPI</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394550#M768</link>
      <description>&lt;P&gt;There is an "Edit" dropdown in "Actions" column and you can click "Clone" from the dropdown to duplicate it.&lt;BR /&gt;
Generally, in order to show these events in Episode Review, you need to create some of correlation searches that generate the events, and use Notable Event Aggregation Policy (Under Configuration dropdown manual) to include these events for that Policy, then you will see these events(got grouped into Episode by similarity) in Episode Review.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2019 03:29:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-Episode-Review-1-KPI/m-p/394550#M768</guid>
      <dc:creator>szhou_splunk</dc:creator>
      <dc:date>2019-03-03T03:29:04Z</dc:date>
    </item>
  </channel>
</rss>

