Splunk ITSI

itsi_event_grouping

salinasaritha
New Member

I have 2 alerts open alert and clear alert. both are triggering at different timestamps but they are unable to group into single episode.  what is the root cause

Labels (1)
Tags (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @salinasaritha 

We will need a lot more information to be get to the bottom of this. How are you generating these alerts? Do these come from a Notable Event Aggregation Policy (NEAP) to group them? What steps have you taken so far to investigate this? Are both notables reaching the NEAP?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

0 Karma

salinasaritha
New Member

Hi @livehybrid ,

yes they come from Notable Event Aggregation Policy (NEAP. they are reaching Neap and those are having common criteria as alertname and split by alertname in the neappolicy

0 Karma

skramp
SplunkTrust
SplunkTrust

Thanks for your request. As you have mentioned you have some alerts, I assume those alerts you can also find in the index itsi_tracked_alerts, right? If so, you want to "bundle" those alerts somehow by a specific criteria. You are right, therefore a NEAP is needed. You can ie say you want to bundle the same alerts by hostname. Do you already have a NEAP which should do this or what was your idea to archive this?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...