Customize episode severities in ITSI
An episode's severity in IT Service Intelligence (ITSI) is determined by the severities of the individual notable events within the episode. If you configure additional severities in the itsi_notable_event_severity.conf configuration file, those severities also apply to the available severities in correlation searches and aggregation policies.
The following default severities are available for episodes:
Edit episode severities
An episode's severity is determined by the severities of the individual notable events within the episode. You can customize episode and event severities to match an existing workflow in your organization. In the configuration file below that governs episode severities, "color" is the default color displayed in Episode Review, while "light color" applies to prominent mode.
- Only users with file system access, such as system administrators, can edit episode and event severities using configuration files.
- Review the steps in How to edit a configuration file in the Splunk Enterprise Admin Manual.
- You can have configuration files with the same name in your default, local, and app directories. Read Where you can place (or find) your modified configuration files in the Splunk Enterprise Admin Manual.
Never change or copy the configuration files in the default directory. The files in the default directory must remain intact and in their original location. Make changes to the files in the local directory.
- Open or create a local itsi_notable_event_severity.conf file at
- Add, modify, or remove severities as necessary depending on the existing workflow in your organization.
 color = #AED3E5 lightcolor = #E3F0F6 label = Info default = 1  color = #99D18B lightcolor = #DCEFD7 label = Normal  color = #FFE98C lightcolor = #FFF4C5 label = Low  color = #FCB64E lightcolor = #FEE6C1 label = Medium  color = #F26A35 lightcolor = #FBCBB9 label = High  color = #B50101 lightcolor = #E5A6A6 label = Critical
Customize episode statuses in ITSI
Modify episode fields through the REST API
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.5.0 Cloud only, 4.5.1 Cloud only, 4.6.0 Cloud only, 4.6.1 Cloud only, 4.6.2 Cloud only, 4.7.0, 4.7.1, 4.7.2, 4.7.3, 4.7.4, 4.8.0 Cloud only, 4.8.1 Cloud only, 4.9.0, 4.9.1, 4.9.2, 4.9.3, 4.9.4, 4.9.5, 4.9.6, 4.10.0 Cloud only, 4.10.1 Cloud only, 4.10.2 Cloud only, 4.10.3 Cloud only, 4.10.4 Cloud only, 4.11.0, 4.11.1, 4.11.2, 4.11.3, 4.11.4, 4.11.5, 4.12.0 Cloud only, 4.12.1 Cloud only, 4.13.0