Splunk ITSI

Splunk ITSI Correlation Episode Snow

mdcap
Loves-to-Learn

I need to create report to find how many notable events have been  correlated within Episode review and have been successfully mapped with Incidents in SNOW. 

In addition which are the fields within itsi_tracked_alerts,  itsi_grouped_alerts etc or any other default indexes of ITSI  which will help in writing successful query to find how many events have been correlated and finally incident is created in SNOW.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...