Are Splunk IT Service Intelligence (ITSI) notableeventaggregationpolicies stored in a .conf file? If so, where is it? the only thing that I see documented is how to view via the GUI.
Hi,
In ITSI > NotableEventAggregationPolicies > Action Rules, "Run a script" can no longer be executed.
The work that triggered the event to occur - Splunk Core Version Up (8.2.7 > 9...
...plunk. From what I can tell so far, it seems that Splunk would not be a good choice to use as an event manager. Am I correct? The Splunk IT Service Intelligence looks very exciting and appears to be t...
...een created. Multiple aggregationpolicies can be created with filtering criteria that capture the same set or subset of events. If the same notableevents are captured by more than one policy, the a...
HI,
I have dedicated serach head forITSI on windows OS. I have ITSI version 4.0.4 and I have installed Java SE Development Kit 8. But when itry to create notableeventaggregationpolicies then m...
We are facing some issue while creating ticket, For the first run of correlation, notableevents are generating and grouping it into Episode, however, Its creating multiple(for each events in t...
...earches to gather together the like alerts into groups, such as db garbage collection, MQ queue depth, etc. Along with the Correlation searches, I created the NotableEventAggregationpolicies we are u...
...ost and whole cluster by ITSINotableEventAggregationPolicies.
Below is what I managed to achieve.
Test 1: A very simple service model, one KPI counting number of alive nodes. I know, how m...