Hi @gcusello First case query its working. but urgency field i don't see any severity. all alerts urgency field is empty only. but in the rule we set under Adaptive response actions--> notable -->severity value. (Ex High, Medium, Low, informational) we have 40+ indexes so i want to each alert for Search Name, Index, Urgency, count. hope you can able to share right info.
... View more