Splunk Enterprise

itsi episodes count updating though resolved

iamvinaykumar
Engager

Hi Community ,

We have integrated our itsi cluster to servicenow and tickets are creating fine.  but recently observed a strange behavior from splunk itsi  that . episodes generated in episode review will create servicenow incident . once issue resolves episode will get resolved .

 

But when the same issue happens with same node  , resolved episode count gets increased , instead of creating new notable event and a new episode. itsi logs  doesnot provide much details about this , please help check why .

 

Best regards

Vinay

vi323056@wipro.com

Labels (1)
0 Karma

iamvinaykumar
Engager

Thanks !! found a way to resolve it 🙂

0 Karma

seths
New Member

1. Try moving the event to closed state instead of the Resolved.
2. You can even check your actions rules for the breaking of episode it should have the states mentioned to break the episode.

3. Also check if the CorrelationID it should change for new Episodes.

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...