Splunk ITSI

Normal/Clearing event getting same timestamp as original event

FeatureCreeep
Path Finder

I have an alert that can clear in the same minute that it originally fired.  When the correlation search runs, both events are in it, the alert and the clearing alert.  The correlation search creates notable events for each but uses the current time for the _time for the notable events and not the _time from the original alerts.  Since both alerts are converted into notable events during the same correlation search run, they get the exact same timestamp.  This causes ITSI to not definitely know the correct order of the events and it sometimes thinks the Normal/Clear event came BEFORE the original alert.

This seems odd to me.  I would have imagined that ITSI would use the original event time as the _time for the notable event but it doesn't.

Any ideas on how to address?   

Labels (3)
0 Karma
1 Solution

KendallW
Contributor

Hi @FeatureCreeep try setting the 'param.is_use_event_time' in alert_actions.conf as discussed in this doc:
https://lantern.splunk.com/Observability/Product_Tips/IT_Service_Intelligence/Configuring_notable_ev... 

View solution in original post

0 Karma

KendallW
Contributor

Hi @FeatureCreeep try setting the 'param.is_use_event_time' in alert_actions.conf as discussed in this doc:
https://lantern.splunk.com/Observability/Product_Tips/IT_Service_Intelligence/Configuring_notable_ev... 

0 Karma

FeatureCreeep
Path Finder

Exactly what I needed!  Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...