Investigate episodes in ITSI

After you finish triaging episodes, begin your investigation. Use the available fields on an episode to assess the urgency, contributing KPIs, and review the impacted services and entities.

Select an episode to open its details and learn more about the issue. The episode details provide a summary of what happened, the impact on environment objects such as services and entities, a list of suspected root causes, with recommended next steps. Additionally, you can view alert grouping criteria, events from different source applications, reference links and associated tickets, and user comments before beginning your investigation.

  • Use the Overview tab to view the AI-generated summary of the episode, which provides a quick overview of what happened. It also includes an urgency score, a suspected root cause analysis, and recommended next steps. You can review the evidence supporting the AI-generated summary, along with trends identified across data sources such as alerts and logs. The overview also highlights the services, KPIs, and entities impacted by the episode. Select an impacted service or KPI to open it in Service Analyze for further investigation.

  • Use the Events Timeline tab to see a chronological timeline of all notable events within the episode.
  • Review Similar episodes to view a list of episodes with similar characteristics, and identify recurring patterns or related incidents.

  • Review Dashboard to view a high level summary of episode information.

  • Review Activity to see the recent investigation activity on the episode, including status changes, comments, and data from externalintegrations, such as work notes from associated ServiceNow tickets.

  • Review Instructions to view instructions set for your team, configured in aggregation policies.

  • Review the Common Fields tab to see the fields that are common across all notable events in the episode.

Additionally, you can also add additional tabs by selecting Add tab to customize the data for your team's use cases.

Note: If service level permissions are enabled for Episode Review, you only see the events you have permission to view in the All Events tab. If there are any events you do not have permission to view, the number of events you see is less than the number in the episode event count.

Understand AI generated episode analysis

You can also view AI generated episode summary information on the Overview tab. To generate episode analyses with AI, configure an Event iQ Diagnose action rule to generate AI episode summaries. You can also run an Event iQ Diagnose analysis on an episode manually from the Actions menu. For more information, see Use Event iQ Diagnose to analyze episodes with AI. The following image displays an example of the episode information generated by AI.

The AI generated information includes:

  • Key details regarding impacted services, KPIs, and entities to facilitate root cause analysis
  • Summary: narrative description of the episode including key event times and links to impacted services, KPIs, and entities.
  • Suspected root causes: list of potential root causes identified by AI in order to facilitate troubleshooting, including links to relevant resources. For each root cause, view recommended actions for troubleshooting.
  • Trends across alerts and logs: timeline of key sequence of events related to the episode.
  • Evidence: lists notable events, service KPIs and entities, change events, log data, and similar episodes in your environment that have been checked by AI to generate the episode summary.

Provide feedback to improve the accuracy of the AI algorithm in identifying the episode root causes and troubleshooting recommendations by selecting the thumbs up or down icons. For episodes with an existing analysis, itoa_analysts can manually regenerate an episode summary for an episode on the Episode Review dashboard by selecting the regenerate icon.

Additionally, view the affected services and KPI values directly in the Service Analyzer to identify the root cause affecting the health of your services and applications. Once you identify the one or more entities causing issues, use entity thresholding powered by machine learning to set proper thresholds to monitor entity performance. For more information, see Create entity thresholds with AI thresholding.

See a timeline of individual events

When viewing event details for an episode (a group of events), you can use the Events Timeline to see when individual events occurred. The timeline gives you a detailed look into the notable events contained within each episode and lets you perform a more granular root cause analysis. Colored bars (according to severity) represent individual events.

Use the Sort for and Group by menus to change how events are organized in the timeline, depending on what kind of analysis you want to do.

Sort for

The Sort for menu determines how events are sorted in the timeline.

Setting Description
Alarm state analysis Sorts events according to severity, with the most recent, most severe events appearing first. This view focuses on the changing state of the episode and is useful for assessing what is currently broken.
Root cause analysis Sorts events according to when the first event occurred. The exclamation mark identifies the first event in the group to experience a state change (the first event that was no longer "normal" within the context of the group). This view focuses on the cause of the episode and is useful for root cause analysis.

Group by

The Group by menu determines how events are grouped in the timeline.

Setting Description
Event type Groups events according to event type, which is the field generated by the values of the event identifier fields specified in the correlation search.
Entity Groups events according to the entity they are associated with.

Select an event type or entity name to open a separate table with all the events in that row. Click Edit Columns to add, remove, and reorder columns.

EventsTable.png

Analyze common fields

View the common fields of all the notable events within an episode and analyze their different values. Common fields can be useful in root cause analysis as you investigate why certain events are grouped as part of the same episode.

Use the slider to filter by the most common fields in the episode. The fields are displayed in alphabetical order.

Commonfieldsslider.png

Investigate similar episodes

Go to the Similar Episodes tab to find out if a problem that's similar or identical to the one you're currently investigating has occurred in the past, and to see how it was resolved.

Select a time range to determine how far back to look for similar episodes. For example, if you remember a similar problem occurring a few months ago, you might set the time range to Last 3 months.

Under Show episodes with similar event fields, select the fields that are most important to you so that ITSI only looks at these fields when comparing to other episodes. The fields you choose are used to analyze and evaluate similarity. For example, if you choose the field host, ITSI displays episodes that came from the same host as the current episode. By default, episodes are compared based on title.

Hover over the Similarity Match for each episode to see the matching event fields. If you see an episode with a high similarity match, open it to investigate what actions were taken to resolve the issue. For example, check the Activity tab to see what actions the analyst took while working on the issue. Look at the Comments tab to see if the analyst left any notes on how they resolved the problem. Open any linked tickets to get even more context about the episode from an external system.

The itsi_event_management_similar_episodes_tickets_lookup macro appends ticketing data when calculating similar episodes, and looks back 30 days by default. Update the default look back period in the macro by updating the search macro.

Note: Selected fields become lost when you navigate away from an episode. However, if you click Actions > Share episode and copy the link, all selected fields are preserved in the linked episode.