Splunk ITSI

How can we extract a list of open episodes in splunk itsi?

ManjunathN
Engager

Hi,

How can we extract a list of open episodes in splunk itsi.Please 

Thanks!

Labels (1)
0 Karma

skramp
SplunkTrust
SplunkTrust

This post is old but unanswered. I did it this way: 

index=itsi_grouped_alerts 
| lookup itsi_notable_group_user_lookup event_identifier_hash as itsi_group_id 
| search status=1
0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...