Splunk Enterprise Security

Splunk ESM - The contributing events drill-down search is not the same as my correlation rules "Notable action" drill-down search

New Member

I've changed an existing correlation search and it's drill-down in the adaptive response actions, but when the notable gets created and you click on the contributing events "View Details." the old drill-down search is used in the new tab search and not the new one.

0 Karma