Splunk IT Service Intelligence

Alerts showing late in Episode Review

New Member

itsitrackedalerts showing the correct time of events, however itsigroupedalerts showing event after 15-20 min. Which is resulting in a late view of alerts in Episode Review?

index=itsigroupedalerts sourcetype="itsinotable:group" Garbage Collection "f7a3cdb2c5a1bf1108305ea0"
5/28/20
9:16:38.000 AM

{ [-]
ArchiveMon: NO

ConfigurationItem: GOE Hybris Admin Europe 2
CustomUrl: http://monspkprdci05:8000/en-US/app/itsi/dynatrace
dashboard?form.kpi=Garbage Collection&form.service=hybadm&form.region=eu2

IsStartForAutomation: false

SupportGroupName: GOEAOTAAccenture

aggregated: true
alert
value: 2

automation: FALSE

count: 2

index=itsigroupedalerts sourcetype="itsinotable:group" Garbage Collection "f7a3cdb2c5a1bf1108305ea0"
5/28/20
9:04:17.769 AM

{ [-]
ArchiveMon: NO

ConfigurationItem: GOE Hybris Admin Europe 2
CustomUrl: http://monspkprdci05:8000/en-US/app/itsi/dynatrace
dashboard?form.kpi=Garbage Collection&form.service=hybadm&form.region=eu2

IsStartForAutomation: false

SupportGroupName: GOEAOTAAccenture

aggregated: true
alert
value: 1

automation: FALSE

count: 2

Labels (1)
0 Karma