Splunk ITSI

Where to find "Detected Anomaly" notable events in ITSI

vl951f
Path Finder

Our ITSI is showing some "Detected Anomaly" for the kpi "Index Usage".

vl951f_0-1632772612938.png

 

Where and how can I find the notable events for those "Detected Anomaly"?

I didn't find then in index=itsi_tracked_alerts.

Thanks

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise Security 8.0!

Join us on Wednesday, November 20 to learn about Splunk Enterprise Security 8.0!To enhance SOC efficiency, ...

Mastering Threat Hunting

Register to watch Mastering Threat Hunting on Monday, November 18Join us for an insightful talk where we dive ...

Upcoming Community Maintenance: 10/28

Howdy folks, just popping in to let you know that the Splunk Community site will be in read-only mode ...