I am trying to update an incident that was created by an alert action from Splunk ITSI. But, everytime the alert gets triggered, a new incident is getting created instead of updating the existing incident. I tried everything mentioned in the link given below:
Please guide as to what needs to be done to update a previously created incident? Should I need to get the status of the incident from ServiceNow and use that in the search query when I try to update the incident?
It would be great if you could help me with any documentation or a video reference that could help me in performing this activity of updating an incident that was created already.