Hi,
I have created an advance threat protection incidents Correlation Search which is generating notable events how I can make it to reduce the notables which it is generating.
Thanks
If you are getting duplicate alerts for the same ATP incidents, look into throttling the results based on the same field values.
Check out this page for more information. https://docs.splunk.com/Documentation/ES/7.0.2/Tutorials/ScheduleCorrelationSearch#:~:text=Set%20up%...