In Splunk Enterprise Security , Incident Review Dashboard , I am adding 2 different Investigation Option to the notables by clicking on "Add Event to Investigation".
Now , my requirement is to find out the metrics of each Invegistation Option. For example , How many notables exist with a particular investigation Option. Is it possible?