Hello, Hope you are doing well! I have updated exiting correlation alert in Splunk as notable event which previously used to send email notification to 'x'. I have selected 'Default Owner' as 'leave as system default' (i.e. unassigned) but still when it trigger alerts in Splunk - Incident Review page, it showing owner as 'x' (same as email owner) not as default owner i.e. unassigned. Can someone help me with this? Thanks in advance!
... View more