Splunk IT Service Intelligence

Correlation searches not creating episodes

Splunk Employee
Splunk Employee

Splunk Version:7.2.6 --> SH cluster with 3 nodes
ITSI Version: 4.2.0

Issue:
Sometimes the episodes are not generating with NEAP and showing duplicate episodes

Tags (2)
0 Karma

Splunk Employee
Splunk Employee

Hi,

This is a known issue. Please refer below link:

  • Implemented the workaround to fix the episode generation:

https://docs.splunk.com/Documentation/ITSI/4.2.0/ReleaseNotes/Knownissues

  • Implemented below workaround to fix the itsi rule engine:

1) Open or create a local copy of "commands.conf" at $SPLUNK_HOME/etc/apps/SA-ITOA/local.
2) Add the following stanza:

[itsirulesengine]
command.arg.1=-J-Xmx1024M # reduced to 1024MB for 32 bit JDK/JRE

https://docs.splunk.com/Documentation/ITSI/4.4.0/ReleaseNotes/Knownissues#Notable_Events

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!