<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Define: Time to Triage in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-does-Splunk-calculate-Time-to-Triage/m-p/600066#M208889</link>
    <description>&lt;P&gt;Example:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Mean-Time-To-Triage/m-p/568484" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/Mean-Time-To-Triage/m-p/568484&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This is specifically related to Splunk ES and Notable Events (NE). We assume that TTT is the time that an NE fires how long until it is next modified, e.g. the status is changed. We want to confirm this.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jun 2022 03:06:07 GMT</pubDate>
    <dc:creator>-Chris-</dc:creator>
    <dc:date>2022-06-02T03:06:07Z</dc:date>
    <item>
      <title>How does Splunk calculate Time to Triage?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-does-Splunk-calculate-Time-to-Triage/m-p/600023#M208867</link>
      <description>&lt;P&gt;How does Splunk calculate Time to Triage, what data does it use? e.g. time an event occurred and time the event was put modified or put in pending etc.?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 15:26:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-does-Splunk-calculate-Time-to-Triage/m-p/600023#M208867</guid>
      <dc:creator>-Chris-</dc:creator>
      <dc:date>2022-06-01T15:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Define: Time to Triage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-does-Splunk-calculate-Time-to-Triage/m-p/600056#M208883</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246367"&gt;@-Chris-&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it isn't so clear for me what you mean with "Time to triage"&lt;/P&gt;&lt;P&gt;if you mean the time that Splunk need to index a log, it's very low and depends on the time requested to transfer data from Universal Forwarder to Indexer, then it depends on the queue that you can monitor using the Monitor Console.&lt;/P&gt;&lt;P&gt;It's possible to modify data only before indexing, during the parsing phase, after data are uneditable, and they are pending only if there are queues that you can see using the Monitor Console.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 10:52:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-does-Splunk-calculate-Time-to-Triage/m-p/600056#M208883</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-01T10:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: Define: Time to Triage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-does-Splunk-calculate-Time-to-Triage/m-p/600066#M208889</link>
      <description>&lt;P&gt;Example:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Mean-Time-To-Triage/m-p/568484" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/Mean-Time-To-Triage/m-p/568484&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This is specifically related to Splunk ES and Notable Events (NE). We assume that TTT is the time that an NE fires how long until it is next modified, e.g. the status is changed. We want to confirm this.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 03:06:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-does-Splunk-calculate-Time-to-Triage/m-p/600066#M208889</guid>
      <dc:creator>-Chris-</dc:creator>
      <dc:date>2022-06-02T03:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Define: Time to Triage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-does-Splunk-calculate-Time-to-Triage/m-p/600199#M208939</link>
      <description>&lt;P&gt;More investigation looks like it uses a field called "duration"? But we&amp;nbsp;&lt;SPAN&gt;can't see how it is calculated or what process steps influence the duration. i.e update timestamps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 03:41:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-does-Splunk-calculate-Time-to-Triage/m-p/600199#M208939</guid>
      <dc:creator>-Chris-</dc:creator>
      <dc:date>2022-06-02T03:41:46Z</dc:date>
    </item>
  </channel>
</rss>

