Splunk ITSI

Episodes not creating after upgrading ITSI to latest version 4.17.1

Ka21
Loves-to-Learn

Hi Team,

we facing issue in our environment, as Episodes are not generating after upgrading of ITSI 4.17.1 version.
And everything is enabled (Services, Correlation searches, NEAP policies) and even though it is not creating.
ITSI_event_grouping is enabled and Rules engine is working fine.

Please provide solution for this.

Labels (1)
0 Karma

Abhishek-Nanda
New Member

@Ka21  is this fixed? You found any solution?

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise Security 8.0!

Join us on Wednesday, November 20 to learn about Splunk Enterprise Security 8.0!To enhance SOC efficiency, ...

Mastering Threat Hunting

Register to watch Mastering Threat Hunting on Monday, November 18Join us for an insightful talk where we dive ...

Upcoming Community Maintenance: 10/28

Howdy folks, just popping in to let you know that the Splunk Community site will be in read-only mode ...