Splunk Enterprise

itsi episodes count updating though resolved

iamvinaykumar
Engager

Hi Community ,

We have integrated our itsi cluster to servicenow and tickets are creating fine.  but recently observed a strange behavior from splunk itsi  that . episodes generated in episode review will create servicenow incident . once issue resolves episode will get resolved .

 

But when the same issue happens with same node  , resolved episode count gets increased , instead of creating new notable event and a new episode. itsi logs  doesnot provide much details about this , please help check why .

 

Best regards

Vinay

vi323056@wipro.com

Labels (2)
0 Karma

iamvinaykumar
Engager

Thanks !! found a way to resolve it 🙂

0 Karma

seths
New Member

1. Try moving the event to closed state instead of the Resolved.
2. You can even check your actions rules for the breaking of episode it should have the states mentioned to break the episode.

3. Also check if the CorrelationID it should change for new Episodes.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...