SPLK-3002 Exam QuestionsBrowse all questions from this exam

SPLK-3002 Exam - Question 41


Which index contains ITSI Episodes?

Show Answer
Correct Answer: BC

The index that contains ITSI Episodes is 'itsi_grouped_alerts'. This index holds live episode data and updates whenever a correlation search runs, thus storing new entries for episodes.

Discussion

2 comments
Sign in to comment
otb_282Option: B
Mar 14, 2023

B. itsi_grouped_alerts

Baba111222Option: B
Jan 23, 2024

"The itsi_grouped_alerts index is the index that contains live episode data. Each time a correlation search runs and updates an episode, itsi_grouped_alerts houses a new entry for the episode. It is this index you will search over to look for open episodes attached to your service." source: https://lantern.splunk.com/Observability/Product_Tips/IT_Service_Intelligence/Bringing_episode_data_into_service_scores