I am looking to include certain fields that are in the contributing events for a certain Correlation Search/Notable. The documentation I found: https://docs.splunk.com/Documentation/ES/latest/Admin/Customizenotables This basically says you can add additional fields, but this will apply to all Notables in Incident Review.
My question is if other notables that have different correlation searches don't include an additional field what happens?
Does it just not get displayed in that Notable or does it list the field with a null value in the Incident Review Dashboard?
... View more