Splunk IT Service Intelligence

What's the step between correlation searches and episode reviews?


I've "Opened in Search" one of my episode review searches, then typed ctrl-shift-e to view the "expanded search string".  Doing this, I found that the event count, along with other data, was obtained via lookup on itsi_notable_group_system_lookup (among other itsi tables).  I then expanded the search string for one of my notable event searches, but find no indication that this search writes to those tables.  What step(s) am I missing between the notable event search and the episode review search?  I'm trying to determine how the episode grouping is done, which appears to happen between the NE search and the episode review search.

Labels (1)
0 Karma

Splunk Employee
Splunk Employee

@keesling can you take a look at the following resources and see if they answer your question? 

CC @eduncan if you have any other knowledge to impart. 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...