Hi Community,
I have ingested the two entity with same IOCs data at the same time with different severity level fields. The raw log search shows both entries, but in UDM Search, only the latest entry is visible.
Is this expected behavior?
What should happen when I ingest the same entity with different severity levels and different interval start times?
Will both entries be visible in the dashboard, or will only the latest entity be visible?
My concern is that when similar entities are ingested, only the latest entry should be visible in the dashboard. Do I need to use the window.last function if the latest entry is not being considered?







