Splunk IT Service Intelligence

Splunk ITSI Correlation Episode Snow

mdcap
Loves-to-Learn

I need to create report to find how many notable events have been  correlated within Episode review and have been successfully mapped with Incidents in SNOW. 

In addition which are the fields within itsi_tracked_alerts,  itsi_grouped_alerts etc or any other default indexes of ITSI  which will help in writing successful query to find how many events have been correlated and finally incident is created in SNOW.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...