Hi all, Since the redesign of the new Incident Review page, we appear to have lost the ability to search for Notables using a ShortID. With the old dashboard this was achieved by selecting Associations from the filters and entering the ShortID you were looking for, but the new Incident Review dashboard appears to have taken this functionality away.
Is there any way to achieve this?
Found my answer here
Customize Incident Review in Splunk Enterprise Security - Splunk Documentation