Splunk ITSI

What's the step between correlation searches and episode reviews?

keesling
Engager

I've "Opened in Search" one of my episode review searches, then typed ctrl-shift-e to view the "expanded search string".  Doing this, I found that the event count, along with other data, was obtained via lookup on itsi_notable_group_system_lookup (among other itsi tables).  I then expanded the search string for one of my notable event searches, but find no indication that this search writes to those tables.  What step(s) am I missing between the notable event search and the episode review search?  I'm trying to determine how the episode grouping is done, which appears to happen between the NE search and the episode review search.

Labels (1)
0 Karma

esnyder_splunk
Splunk Employee
Splunk Employee

@keesling can you take a look at the following resources and see if they answer your question? 

CC @eduncan if you have any other knowledge to impart. 

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...