Is there a way to search all ES Investigations for a specific artifact or IOC that may be documented in the notes?
Are you referring to these notes?
https://docs.splunk.com/Documentation/ES/6.4.1/User/Addtoaninvestigation#Add_a_note_to_an_investigat...
I don't think there's a way to search for content within the notes, but only to search for the name/title of the notes. That sounds like a good idea though. Perhaps submit it to https://ideas.splunk.com/
Are you referring to these notes?
https://docs.splunk.com/Documentation/ES/6.4.1/User/Addtoaninvestigation#Add_a_note_to_an_investigat...
I don't think there's a way to search for content within the notes, but only to search for the name/title of the notes. That sounds like a good idea though. Perhaps submit it to https://ideas.splunk.com/
Added as an Idea.
Yes, those notes or any threat detection in a notable associated to an investigation would be useful.