Hi,
According to the Splunk Docs page How urgency is assigned to notable events in Splunk Enterprise Security if I assign an asset Medium priority and High severity in the related Correlation Search (CS) it should register as a High Notable, however it still persists to register as a Medium causing me to up the Severity to Critical. Has there been a change in how ES operates where the table as written no longer works or is there something wrong with the ES instance? Also its Splunk Cloud
Hi @ebs,
Did you check if your Urgency Lookup is modified?
Is this issue got resolved? we are facing similar issue where priority is unknown and severity is critical, according to matrix it should trigger high notables but its triggering low and medium notables also.