Hi Splunkers,I'm here again asking for help with the alert manager app.I'm trying the "auto-resolve" feature combined with "append incident with the same title".
I would like that all incidents with new appended events to be automatically closed at time "last_event + ttl"
What I'm seeing now is an automatic closure at time "open time + ttl" even if there are new events for the same incident.
Here below a simple example:Auto-close = enabledAppend new incidents = enabled
Search = my searchTTL = 11mIncident creation time = 13:00:00 Appended events time = 13:05:00 , 13:10:00
Auto close time = 13:00:00 + 11m = 13:11:00Desidered auto close time = 13:10:00 + 11m = 13:21:00
Thanks in advance for your support.