Requirement 1 :
Eg : I have a correlation search which generates , 2000 events with in 24 hours with the same Title "Important- Password Expiration Notice".
-- I shouldn't have 2000 notable events created in the Incident Review Dashboard. I should have only 1 notable event.
-- If the Title is different , then a notable event should be created.
I have tested updating Window duration as 24 hours and Fields to group by with "Title" field name , but it is working incorrectly.
It is not generating a notable event , if the Title is different.
Requirement 2 :
Is there a way , I can update the existing notable event.
Eg : Existing Notable event Title : Important- Password Expiration Notice
Existing Field value : abcuser@company.com
It should append the new value to existing field.
--abcuser@company.com
--xyzuser@compay.com