Hi All,
in siem search, i want to filter out only events that are flagged as alerts from all events that is populated when queried. this result will be used in dashboards. how to find the difference between an event is an alert from UDM fields.
thanks
