I have a "normal" dashboard created that pulls together some ITSI data for my end users. In the table of the dashboard, I want to make it so the drill-down link will direct users to the ITSIEpisod...
I have a correlation search creating notable events.
In the index=itsi_tracked_alerts, I see one event for a given event_id.
But on the Episode review, I see the event being member of several Episodes...
Hi All, We have installed splunk ITSI 4.15.0 on search head clusters. We are facing challenges in creating episodes and we are seeing the below error: ERROR [itsi_re(reId=Tksg,reMode=Preview)] [m...
Episode page is not loading any data inITSI app version 4.0.3, We see below errors:
JSON parsing of _raw field= failed with the following error, so skipping event:
JSON parsing of _raw f...
Hi Team, we facing issue in our environment, as Episodes are not generating after upgrading of ITSI 4.17.1 version. And everything is enabled (Services, Correlation searches, NEAP policies) a...
I'm very new to Splunk and ITSI. We have created a service for VMware VMs. The Service has several KPIs like memory and CPU. A few of the VMs have CPUs in Critical status. Episode Review shows 0 episodes...
...ist of several episodes with status "New" is obtained. However, in the ITSI GUI, in the Episode Review tab, a search for all new episodes over all time returns no results. How is this possible? Any c...
I need to create report to find how many notable events have been correlated within Episode review and have been successfully mapped with Incidents in SNOW. In addition which are the f...