Hi,
Good day to you!
I quickly wanted to understand whether the Splunk notables will reflect with delay in timestamp on incident dashboard when they moved from "Dev" to "Prod" stage?
I often see bulk notables triggering with lag in time (assume today is 18th, alerts reflect with 17th or before dates) whenever SOC team pushes new use-case to Production queue (status: new)
Happy to know some context/knowledge around this
Cheers,
Can someone have a look at this query and assist please