All Apps and Add-ons

Alert Manager - auto resolve if "append incident with the same title" is enabled

Path Finder

Hi Splunkers,
I'm here again asking for help with the alert manager app.
I'm trying the "auto-resolve" feature combined with "append incident with the same title".

I would like that all incidents with new appended events to be automatically closed at time "last_event + ttl"

What I'm seeing now is an automatic closure at time "open time + ttl" even if there are new events for the same incident.

Here below a simple example:
Auto-close = enabled
Append new incidents = enabled

Search = my search
TTL = 11m
Incident creation time = 13:00:00 
Appended events time = 13:05:00 , 13:10:00

Auto close time = 13:00:00 + 11m = 13:11:00
Desidered auto close time = 13:10:00 + 11m = 13:21:00

Thanks in advance for your support.

Labels (3)
0 Karma
Get Updates on the Splunk Community!

tag as datamodel attribute

I'm confused a bit. I use CIM datamodels.The "tag" field is both a filter for choosing events applicable to a ...

Index with one sourcetype - search performance / best practices

Hello,I have created a few indexes, each containing data only from one source with one sourcetype.<BR />From a ...

Can you customize Additional Fields in Notable Events?

Is there a way to customize which additional fields to show for which Notable event /Co-relation search ...