This Story runs when Splunk Correlated Alert fires off in Splunk ES. It will auto-assign a notable event to the progress status, owner, and comment of your choosing.
Tines
How it works
Import this story to your tenant, from where you can adapt it to meet your unique needs.
Import