Splunk IT Service Intelligence

Can we send Stats details to ITSI Notable events

New Member

I have a query and the output is formatted using stats command, can we send the result to ITSI notable events.

Tags (1)
0 Karma

Splunk Employee
Splunk Employee

You should be able to, as long as your stats command preserve the necessary fields (like _time, source, host,...) and the fields you use for the entity mapping.

0 Karma