Hello,
Hello, we are on ES 7.3.2. We are noticing there is difference in count of Notable alerts visible under "Incident Review" page versus to the number of events in the notable index for that same time period.
For example, Our Incident Review page when filtered to show all notables for previous month' time range shows 4648 notable alerts generated. Screenshot attached. But, if check index=notable for previous months' time range, it shows 4653 events. Likewise, we are seeing this difference for every month. Ideally both numbers should match.
How to find out what is causing this mismatch and what is the reason exactly?
Thanks for responding. Time range is exactly same. We ended up opening a support case for this. The cause was found to be duplicate events in index=notable for a particular correlation search . What is causing these duplicates is under investigation.
A couple of things -