Splunk Dev

Need to download all the incidents from Enterprise security for i.e. - how many Incidents get generated for which use case (Correlation search name) with urgency level field

Ymitt2
Engager

I need some guidance, If someone can guide me to get the result for following query
- “Need to download all the incidents from Enterprise security for i.e. - how many Incidents get generated for which use case (Correlation search name) with urgency level/Owner name/status field”

I tried this “| es_notable_events” but not getting the same result (getting different – different count after running search and from Incident review tab )

Tags (1)
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...