Splunk ITSI

ITSI Episodes Data Inconsistent

krunoslav
Engager

Hello,

When fetching the episodes from ITSI via REST (https://hostname:8089/servicesNS/fsspl06/itsi/event_management_interface/notable_event_group?filter={"status":"1","severity":{"$gte":"3"}}) a list of several episodes with status "New" is obtained. However, in the ITSI GUI, in the Episode Review tab, a search for all new episodes over all time returns no results. How is this possible? Any clues on how to debug this? Thanks

Labels (2)
Tags (2)
0 Karma

eduncan
Splunk Employee
Splunk Employee

If you are sure that even in the itsi_summary index that the groupid's for the ones retrieved via rest are NOT there, then I'd open a support case.

0 Karma

eduncan
Splunk Employee
Splunk Employee

Need more info on your filter.  What is set for Status Filter and Severity Filter?

0 Karma

krunoslav
Engager

In ITSI GUI the Status is set to New and the severity is not set

0 Karma

eduncan
Splunk Employee
Splunk Employee

Also if you search the. index=itsi_grouped_alerts do you see the groupID of the same episodes you got from the REST API?

 

0 Karma

krunoslav
Engager

No, the episodes returned via REST are not found in the index.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...