Hi,
Our team has recently upgraded to ES 8, we use to have a dashboard that linked notables to closure comments for review.
Since the upgrade to ES 8 we have not been able to review notes in bulk in association to a particular finding. The notes are stored within the KV store lookup 'mc_notes', however this table only displays the notes and not the finding it is associated with.
What would be the best way of linking notes with a particular finding, and what would be the SPL for this search.
Thanks.