I need some guidance, If someone can guide me to get the result for following query
- “Need to download all the incidents from Enterprise security for i.e. - how many Incidents get generated for which use case (Correlation search name) with urgency level/Owner name/status field”
I tried this “| es_notable_events
” but not getting the same result (getting different – different count after running search and from Incident review tab )