Splunk ITSI

Normal/Clearing event getting same timestamp as original event

FeatureCreeep
Path Finder

I have an alert that can clear in the same minute that it originally fired.  When the correlation search runs, both events are in it, the alert and the clearing alert.  The correlation search creates notable events for each but uses the current time for the _time for the notable events and not the _time from the original alerts.  Since both alerts are converted into notable events during the same correlation search run, they get the exact same timestamp.  This causes ITSI to not definitely know the correct order of the events and it sometimes thinks the Normal/Clear event came BEFORE the original alert.

This seems odd to me.  I would have imagined that ITSI would use the original event time as the _time for the notable event but it doesn't.

Any ideas on how to address?   

Labels (3)
0 Karma
1 Solution

KendallW
Contributor

Hi @FeatureCreeep try setting the 'param.is_use_event_time' in alert_actions.conf as discussed in this doc:
https://lantern.splunk.com/Observability/Product_Tips/IT_Service_Intelligence/Configuring_notable_ev... 

View solution in original post

0 Karma

KendallW
Contributor

Hi @FeatureCreeep try setting the 'param.is_use_event_time' in alert_actions.conf as discussed in this doc:
https://lantern.splunk.com/Observability/Product_Tips/IT_Service_Intelligence/Configuring_notable_ev... 

0 Karma

FeatureCreeep
Path Finder

Exactly what I needed!  Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...