Make alert.digest_mode configurable in Splunk correlation searches
Splunk Enteprise 7.2.x
In the current Resilient Splunk app, when you 'Create Resilient Incident' as a Response Action on a correlation search directly (and not part of a notable event), events are getting messed up because the $result.foo$ tokens...