I have a correlation search creating notable events.
In the index=itsi_tracked_alerts, I see one event for a given event_id.
But on the Episode review, I see the event being member of several Episodes...
...ist of several episodes with status "New" is obtained. However, in the ITSI GUI, in the Episode Review tab, a search for all new episodes over all time returns no results. How is this possible? Any c...
I need to create report to find how many notable events have been correlated within Episode review and have been successfully mapped with Incidents in SNOW. In addition which are the f...
I'm very new to Splunk and ITSI. We have created a service for VMware VMs. The Service has several KPIs like memory and CPU. A few of the VMs have CPUs in Critical status. Episode Review shows 0 episodes...
Episode page is not loading any data inITSI app version 4.0.3, We see below errors:
JSON parsing of _raw field= failed with the following error, so skipping event:
JSON parsing of _raw f...
Hi Community , We have integrated our itsi cluster to servicenow and tickets are creating fine. but recently observed a strange behavior from splunk itsi that . episodes generated inepisod...
Hello SPLUNK Community! I need to do some Excel analysis on the EpisodesinITSI, breaking them up by various parameters. I might be able to create a SPLUNK dashboard to do this sort of thing, b...
I have a NEAP that points back to the correlation search. It breaks on "normal" severity. And the action is to close on break. But the episode review lists it as "new" not "closed"....
...bsp; If I do not want to explicitly name the windows service in the base search how do I include the service name, here ServiceName, beside the entity_title=host in the later created ITSIepisod...