With this query I can see the notable events that are currently active.
But not everyone has been alerted even if they are active.
I would like to know what the query would be to see those that the tool has alerted in the last month
| search NOT `suppression`
| fields rule_name urgency
| stats count(eval(urgency="low")) as low count(eval(urgency="medium")) as medium count(eval(urgency="high")) as high count(eval(urgency="critical")) as britical by rule_name