Hi Splunk Answers,
I understand that notable events can be assigned severity as well as being assigned to different analysts.
Is it possible to update an event with comments. This would be useful so the analyst working on the event can enter useful information before assigning to another analyst.
You do this by entering by editing the event and entering only a comment. Leave the other fields empty and it not change those items (will leave the status, urgency and owner unchanged).