[Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/IndexOverview, B is the correct answer because ITSI episodes are stored in the itsi_grouped_alerts index. This index contains notable events that have been grouped together based on predefined aggregation policies. Episodes help you reduce alert noise and focus on resolving incidents faster. References: [Overview of episodes in ITSI]]
Submit