I am trying to be able to show the results of the drilldown search of a notable without having to leave the event/case page.
I am able to grab the drilldown search and send it back to Splunk using the 'run_query' command and receive the information but regardless of what fields I put in the "display" field of the command nothing shows up in the widget and attempting to create a new artifact with the data throws errors around it not being correctly formatted Json.
Does anyone have a best practice to show the results of a SPL query within Splunk SOAR within the event that it was run on?