I have a couple searches that trigger in Incident Review and I want to group them up by count. And than let the drill down show me the detailed information of each event. Does anyone know how to group them?
From what I been playing with. There isn't really a way to use the correlation search and stats to group information you want to seen when you expand the event, but you can have the search and group them by a count and break them down by different types. You do this by throttling with the fields to group by.
I have a feeling you can do it different but I was able to get a count of events and with the drill down see the information I wanted to see with the drill down information.
This is not a UI feature in ES Incident Review.
Not sure how this is an answer.