In Splunk Enterprise I have alerts. Now I want to create Servicenow incidents by adding the alert action using ITSI Notable Events.
Following are my questions:
Whether the above approach is d...
Hi,
We have observed slowness inITSI notable events and searches. In notable events we its taking time to complete the search and show the alert description. We checked o/s performance issues. C...
....com/Documentation/ITSI/2.5.1/User/CreateMulti-KPIAlerts. This creates correlated searches that ultimately create "Notable events" but what about email alerts?
I see the benefit of Multi-KPIAlerts b...
...OT create Notable Events. This happens throughout the day but at random times. Most of the time Notable Events are created but there are times when business critical alerts are missed.
Trying to replicate thresholds from a legacy tool inITSI that are configured over time periods
How would you create a KPI which alerts if CPU is over 95% for 15 minutes?
gratzi
Hello Fellow Splunkers! The goal is to create ServiceNow Incidents/Events exclusively from Splunk Enterprise alerts using the Custom Alert action (we do not have Splunk ES or Splunk ITSI*). I...