The events are sent to the notable index via a summary indexing alert action. Below is a sample of a correlation searches alert action that summary indexes the results:
[Endpoint - Host Sending Excessive Email - Rule]
action.summary_index = 1
action.summary_index._name = notable
action.summary_index.ttl = 1p
Manually running the search interactively won't trigger the alert actions (that is something that the scheduler does).