Hello:
Can anyone help me in finding the Incident review logs? Will it be there in the Indexer or the Search heads? I tried doing an ssh to both Indexer and search heads, but couldn't find the incident_review.csv file.
Thanks
Bipin
in es apps search tab in searching window just search for `notable`. you will get all the deatils.
Newer versions of ES no longer store the Incident Review data in a lookup file. It is now kept in the KV store. The collection name is "es_notable_events". You can view this in search using inputlookup:
| inputlookup append=t es_notable_events