Splunk ITSI

ITSI Notable event Aggregation policy not working as intended

PotatoDataUser
Explorer

I am using Splunk ITSI's notable event aggregation policy to handle the alerts being generated by my correlation searches.

I have a rule in there saying 

status "does not match" Resolved

PotatoDataUser_0-1759231150054.png

but the rule triggers even when the alert groups status is "Resolved"
Causing a lot of duplicate comments and system usage.

PotatoDataUser_1-1759231261631.png


I used the default status field that splunk provides in ITSI and even the default dropdown for "Resolved".
There are no other fields in my search with the title "status", theres stuff like change_status if that matter.

Did anyone else run into something like this, any ideas on how to fix it and get it to fire only once.

TIA

Labels (1)
0 Karma

srauhala_splunk
Splunk Employee
Splunk Employee

Maybe you could try using itsi_group_status insted of status. i.e. itsi_group_status does not match 4

 

/Seb

0 Karma

srauhala_splunk
Splunk Employee
Splunk Employee

Jikes! 

Does not sound fun! I also had some odd behaviour in NEAP's trying to act on the stateful fields of an episode. 

The status of an notable event will be managed by the correlation search (Notable Events: Status: dynamic or static). Then you have an additional option to control the status of the episode in the NEAP under "Episode Severity". Are all these dynamic or static? 

Secondly and independent of notable events the episode status can change from user actions, which will not trigger any new notable event (except for status closed). 

So in summary try to verify if the NEAP picks up the status from the correlation search / NEAP Episode Status or from itsi_notable_group_user_lookup. 

You might be better off managing a custom status field. 

/SEb

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...