Splunk ITSI

What's the step between correlation searches and episode reviews?

keesling
Engager

I've "Opened in Search" one of my episode review searches, then typed ctrl-shift-e to view the "expanded search string".  Doing this, I found that the event count, along with other data, was obtained via lookup on itsi_notable_group_system_lookup (among other itsi tables).  I then expanded the search string for one of my notable event searches, but find no indication that this search writes to those tables.  What step(s) am I missing between the notable event search and the episode review search?  I'm trying to determine how the episode grouping is done, which appears to happen between the NE search and the episode review search.

Labels (1)
0 Karma

esnyder_splunk
Splunk Employee
Splunk Employee

@keesling can you take a look at the following resources and see if they answer your question? 

CC @eduncan if you have any other knowledge to impart. 

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...