Using the ESCU app viewing an Analytic Story searches, selecting the "Configure in ES" erroneously adds "- Rule to the end of the address. EX) "https:///en-US/app/SplunkEnterpriseSecuritySuite/correlation_search_edit?search=ESCU - Process Execution via WMI - Rule - Rule" instead of "https:///en-US/app/SplunkEnterpriseSecuritySuite/correlation_search_edit?search=ESCU - Process Execution via WMI - Rule".
The page returned display the Top Splunk navigation bars and the text "ESCU Context". Looking for insight, configuration error, resolution
This has been identified as bug