I am wondering if there is a way to have the urgency of the events just to be how you have it set in the Adaptive Response Actions?
I don't want Incident Review to make it for me. I want to be able to set it myself either with the correlation search or in the Notable Adaptive Response Actions.
See the following answers post:
https://answers.splunk.com/answers/481263/how-does-splunk-define-and-assign-urgency-in-splun.html
I looked through that and have tried that but still not working correctly. I am trying to have that be bypassed and have whatever I put into the notable event adaptive response actions to show up in the Incident Review.