Correlation searches not creating episodes

Splunk Version:7.2.6 --> SH cluster with 3 nodes
ITSI Version: 4.2.0

Sometimes the episodes are not generating with NEAP and showing duplicate episodes

This is a known issue. Please refer below link:

  • Implemented the workaround to fix the episode generation:


  • Implemented below workaround to fix the itsi rule engine:

1) Open or create a local copy of "commands.conf" at $SPLUNK_HOME/etc/apps/SA-ITOA/local.
2) Add the following stanza:

command.arg.1=-J-Xmx1024M # reduced to 1024MB for 32 bit JDK/JRE


