Hi,
I would like to know about the triggered notable events from CS without accessing the incident review dashboard, as we are experiencing a significant number of notables being triggered consistently. How can we identify the source of noise from a specific correlation search?
Hi @AL3Z,
You can check directly from notable index, but using notable macro is much easier.
`notable` | timechart count by rule_name