Splunk ITSI

Normal/Clearing event getting same timestamp as original event

FeatureCreeep
Path Finder

I have an alert that can clear in the same minute that it originally fired.  When the correlation search runs, both events are in it, the alert and the clearing alert.  The correlation search creates notable events for each but uses the current time for the _time for the notable events and not the _time from the original alerts.  Since both alerts are converted into notable events during the same correlation search run, they get the exact same timestamp.  This causes ITSI to not definitely know the correct order of the events and it sometimes thinks the Normal/Clear event came BEFORE the original alert.

This seems odd to me.  I would have imagined that ITSI would use the original event time as the _time for the notable event but it doesn't.

Any ideas on how to address?   

Labels (3)
0 Karma
1 Solution

KendallW
Contributor

Hi @FeatureCreeep try setting the 'param.is_use_event_time' in alert_actions.conf as discussed in this doc:
https://lantern.splunk.com/Observability/Product_Tips/IT_Service_Intelligence/Configuring_notable_ev... 

View solution in original post

0 Karma

KendallW
Contributor

Hi @FeatureCreeep try setting the 'param.is_use_event_time' in alert_actions.conf as discussed in this doc:
https://lantern.splunk.com/Observability/Product_Tips/IT_Service_Intelligence/Configuring_notable_ev... 

0 Karma

FeatureCreeep
Path Finder

Exactly what I needed!  Thanks!

0 Karma
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...