is the correct answer because ITSI episodes are stored in the itsi_grouped_alerts index. This index
contains notable events that have been grouped together based on predefined aggregation policies.
Episodes help you reduce alert noise and focus on resolving incidents faster. Reference: [Overview of
episodes in ITSI]
"The itsi_grouped_alerts index is the index that contains live episode data. Each time a correlation search runs and updates an episode, itsi_grouped_alerts houses a new entry for the episode. It is this index you will search over to look for open episodes attached to your service."
source: https://lantern.splunk.com/Observability/Product_Tips/IT_Service_Intelligence/Bringing_episode_data_into_service_scores
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
8b5c1e8
2 months agoBaba111222
1 year, 4 months agootb_282
2 years, 2 months ago