How can I monitor if all correlations open incidents into "Incident Reviews" in Splunk ES correctly?
You can run the following search for your time period [ e.g. last 24 hours] to look at all correlation searches that fired and created notables/incidents in the IR dashboard.
`notable` | stats count by source
If you are happy with the answer, could you pls accept so we can close the tracking?