I worked with Splunk Professional Services consultants for ITSI 4.4.5 and covered this example and another where if the episode was open for x time and the severity was high. But the first event even being high did not satisfy the severity condition until the time did. Then it took another event of "high" to meet the second after the the time. But what if no other events arrive? Consultants recommended submitting a enhancement request as this is the way the developer currently coded the application. They have a lot of work on their ITSI solution to be more robust like HP OMi and other more advanced event monitoring systems.
... View more