Splunk IT Service Intelligence

How to consolidate all the alerts from ITSI?


Hello Splunkers, We have a requirement where we need to get the consolidated list of alerts in ITSI that  was generated and need to get status of alerts (closed or still active)

When i run the below query  index="itsi_grouped_alerts" source="XXXX" sourcetype = itsi_notable:group, i don't see any status of the alerts.

Is there any way where we can have all the alerts from ITSI listed with status

Labels (3)
Tags (1)
0 Karma

Splunk Employee
Splunk Employee


Try something like this: 

| tstats latest(_time) as _time latest(alert_level) as alert_level latest(itsi_group_severity) as itsi_group_severity latest(itsi_group_status) as itsi_group_status  where index=itsi_grouped_alerts AND NOT itsi_group_status::5 earliest=-24h latest=now by itsi_group_id 



0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...