when i upgrade ES to 8.0.2 i missed the "Short ID " button in the Additional Field, also i can't search about the case id instead of time
Thank you for your reply, i found the solution, it's supported you find follow the below approach.
The "Short ID" button might be missing due to changes in the interface or settings during the upgrade. According to the Upgrade Splunk Enterprise Security - Splunk Documentation
When you upgrade the Splunk Enterprise Security app to versions 7.0.0 or higher, the short IDs for notables that were created prior to the upgrade are not displayed on the Incident Review page. As a workaround, you can recreate all the short IDs that were available prior to the upgrade.
On top of what @kiran_panchavat mentioned, once we generate the Short IDs, we can also add in Incident Review Dashboard as a custom field - https://www.splunk.com/en_us/blog/security/modifying-the-incident-review-page.html#:~:text=To%20conf....
Thank you for your reply, i found the solution, it's supported you find follow the below approach.