I am trying to figure out how I can track the timestamp whenever I changed the status of any recently opened investigation so that I can have the control of that, I have checked the ES audit section, specifically the Investigation Overview but there is anything similar to this.
I also checked the _audit index but not sure if the investigation roles are tracked there which in turn would be a really good option to observe.
Thanks
IIRC, investigations are stored in the KV Store.
Hello @richgalloway,
Thanks so much for replying back,
Well I checked that information but there is no record to track whenever I change the status in the investigation feature.
I was thinking that maybe with the audit index but I will need to look it closely.
Thanks,