I created a new Correlation Search that needs to generate notable, so in the "Adaptive Response Actions" I added the "Notable" with all information.
Doing a manual search with the same time span as the correlation search, I've got the expected outputs. The problem is that the correlation search doesn't create the same number of notables.
For example: in a range time of 4 hours, the correlation search has generated 4 notables, instead, doing the manual search I've got 28 events.
Doing the search "index=_internal sourcetype=scheduler" in the same time range, I found the 28 events generated by the correlation search, of which, 24 with these parameters:
result_count=0 alert_actions="" suppressed=0 status=success
and 4 with these parameters:
result_count=1 alert_actions="notable,risk" suppressed=0 status=success
Why, if I do the manual search (the same as the correlation search) I've got 28 results, instead the correlation search generated only 4 notables?
... View more