Hello Splunk Community,
My organization has recently upgraded to Splunk ES 5.2.2. I have been trying to create a custom sequence template and test the concept. I have followed the directions outlined in this documentation link: https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Sequencecorrelationsearches
My custom sequence template is enabled, sequence analysis is turned on via general settings:
However, I do not see a a "next scheduled time" applied to my template.
I have also attempted to manually force an invocation of this macro through the following:
execute_sequence_template(template_name, true)
I get 1 record result returned (which I expect). However, there is no sequence event created through the notable events page.
I also do not see any errors or warn messages within the _internal logs for my custom sequence template.
Is this a bug with version 5.2.2?
Hello,
I am facing similer issue. Do you found any resolution?
Hello,
I am facing similer issue. Do you found any resolution?