I am trying to create a new finding-based detection to group findings together when the risk score exceeds a threshold, similar to the RBA concept.
However, I am encountering an issue: when the finding (notable) is created, no Entity appears in the Incident Review dashboard, even though the fields risk_object, normalized_risk_object, and risk_object_type have values.
Has anyone experienced the same issue?