Hi Team,
Requirement : ES incident/Alerts should be mark as True Positive or False Positive as verdict .
Please help how I can fulfill this requirement,.
Is there any custom field configuration or any drop down list can be configured ?