I am also trying to create some custom correlation searches and notables from my daily reports.
Steps I followed to make this:
1. In ES ==> ES ==> Configure ==> Content Mgmt ==> Create New Content ==> Correlation Searches
2. While creating the correlation searches, I added the name of the new notable (assuming that this would create new notable) and scheduled and saved it.
The query runs fine and gives the output in tabular format. Its creating the notables but I am not able to see the contributing events/error event.
As you mentioned above, could you advise on the format needed to make an event in the notable index and have particular fields.
Also, I am unable to find Correlation Search Editor to make it (Configuration » Custom Searches)
... View more