nerdexam
Splunk

SPLK-3002 · Question #15

Which index contains ITSI Episodes?

The correct answer is B. itsi_grouped_alerts. B is the correct answer because ITSI episodes are stored in the itsi_grouped_alerts index. This index contains notable events that have been grouped together based on predefined aggregation policies. Episodes help you reduce alert noise and focus on resolving incidents faster.

Event Analytics and Episode Review

Question

Which index contains ITSI Episodes?

Options

  • Aitsi_tracked_alerts
  • Bitsi_grouped_alerts
  • Citsi_notable_archive
  • Ditsi_summary

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    91% (29)
  • C
    3% (1)

Explanation

B is the correct answer because ITSI episodes are stored in the itsi_grouped_alerts index. This index contains notable events that have been grouped together based on predefined aggregation policies. Episodes help you reduce alert noise and focus on resolving incidents faster.

Topics

#episodes#itsi_grouped_alerts#indexes#episode storage

Community Discussion

No community discussion yet for this question.

Full SPLK-3002 Practice