Hi,
I was wondering how we could download the specific notables into csv or text format from incident review panel in Splunk Enterprise Security.
Click on the "Actions" button for that notable and select "Download notable events".
In the "Download Notable Events" dialog box, select the format you want to use for the download (CSV or Text).
you need admin privilege
Not sure you can from that Incident Review dashboard. You should be able to export from a regular search using index=notable. Just specify time frame and fields you need.