I am trying to assign custom tags to notable events so that they can be triaged by certain analysts, i.e., tier 1. I have a cron scheduled search created and it is set to create notable events; this works fine. I then setup a corresponding tag for that search_name but when I try to filter by the tag name in the tag field in the Incident Review dashboard it does not show up.
scheduled search (search name is _triage_test) that is working and generates a notable:
index=snort signature="test rule"
tag (tag name is _use_case_test) that is not working:
Any ideas? Thanks.