Splunk IT Service Intelligence

How to define the filtering criteria to exclude the hosts so that the ticket will bot be created for them?

ManjunathN
Engager

Hi,

We have created the aggregation policies and configure the action rules to create a ticket.

We have a requirement to prevent the ticket getting created for few of the hosts.

How to define the filtering criteria to exclude the hosts so that the ticket will bot be created for them?

and will the episodes get created in this case? Please clarify. Thanks.

Labels (1)
0 Karma

lperini_splunk
Splunk Employee
Splunk Employee

I think you can limit the hosts in the Action Rules, something like that AND the number of events on the episode = 1 then trigger the create servicenow incident

 

lperini_splunk_0-1664458683559.png

 

0 Karma

ManjunathN
Engager

@lperini_splunk  we tried to use the below option but ticket creation got stopped for the entire kpi and for other hosts too ,then we had to revert it back. So we could not understand what was the mistake made.

Host must be a field from the correlation search right? and do we need to give fqdn of the server as host value or just a server name or ip address is enough?

also please let us know if there are any other option.

Thanks!

 

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...