A 911 PSAP analyst has a red syslog line in Search and a tracked item on Analyst Queue after a correlation search ran. Which object is the Notable Event they triage?
Select an answer to reveal the explanation.
Short Explanation
A notable is the case on the queue, not every scary line in the log. Correlation searches (or a manual action) create that tracked object so 911 analysts can own it. Raw syslog is evidence; the notable is the work item.
Full Explanation
In Splunk Enterprise Security, a Notable Event (ES 7) or finding (ES 8) is the tracked incident object created when a correlation search's notable adaptive response fires, or when an analyst creates one manually. That object is what Incident Review / Analyst Queue displays with owner, status, and disposition. A raw interesting event in Search is not a notable until that framework creates one, and neither the search's title nor a data-model acceleration job is the triage object.