Hi, Not sure if this is what wou want, but is this not already an option in the Incident Review Settings page? When I enable this I am required to set a disposition other than the default of "undetermined". ** This is in Splunk ES 7.3.0 and it should have been added in ES 7.2
... View more