Splunk IT Service Intelligence

What's the step between correlation searches and episode reviews?

keesling
Engager

I've "Opened in Search" one of my episode review searches, then typed ctrl-shift-e to view the "expanded search string".  Doing this, I found that the event count, along with other data, was obtained via lookup on itsi_notable_group_system_lookup (among other itsi tables).  I then expanded the search string for one of my notable event searches, but find no indication that this search writes to those tables.  What step(s) am I missing between the notable event search and the episode review search?  I'm trying to determine how the episode grouping is done, which appears to happen between the NE search and the episode review search.

Labels (1)
0 Karma

esnyder_splunk
Splunk Employee
Splunk Employee

@keesling can you take a look at the following resources and see if they answer your question? 

CC @eduncan if you have any other knowledge to impart. 

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...