I'm looking to provide two separate ES incident review views: one for rules that are live, and another for new rules that are still being tested. I already know I can pre-populate the search box on the incident review dashboard, and then add a new link in the ES navigation bar, but I'm wondering what the best practice is for how to actually filter the notables: Should I prefix all of my non-prod correlation searches with "Dev"? Should I eval in a "prod_status" field? Should I put in an automatic lookup that maps rule_title to dev/test/prod? What's the best approach for making searches easy to separate, and simple to graduate from dev to test to prod?