- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk ITSI episode review status not correct.
digithead1
Loves-to-Learn
10-27-2020
12:11 PM
I have a NEAP that points back to the correlation search. It breaks on "normal" severity. And the action is to close on break. But the episode review lists it as "new" not "closed". But the "activity" tab indicates a bulk action by the default splunk user and status=closed. Is this a rules engine issue with not being able to reach an indexer cluster or a bug?
