How are Notable Events configured in Splunk Enterprise Security?
During an investigation.
As part of an audit.
Via an Adaptive Response Action in a regular search.
Via an Adaptive Response Action in a correlation search.
Wildcards are not efficient