Splunk ITSI

ITSI - Episode Review - 1 KPI

arthurva
Explorer

I'm very new to Splunk and ITSI. We have created a service for VMware VMs. The Service has several KPIs like memory and CPU. A few of the VMs have CPUs in Critical status. Episode Review shows 0 episodes. Is it possible to have the specific servers show up in Episode Review?

0 Karma

arthurva
Explorer

I'm stuck doing something on the first link.

...but we’re going to wind up modifying it slightly so we’ll duplicate the existing rule and make our modifications to the copy...

How do you duplicate it? I don't see that option.

0 Karma

szhou_splunk
Splunk Employee
Splunk Employee

There is an "Edit" dropdown in "Actions" column and you can click "Clone" from the dropdown to duplicate it.
Generally, in order to show these events in Episode Review, you need to create some of correlation searches that generate the events, and use Notable Event Aggregation Policy (Under Configuration dropdown manual) to include these events for that Policy, then you will see these events(got grouped into Episode by similarity) in Episode Review.

0 Karma

arthurva
Explorer

I'll start reading them. Thank you.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...