Where is the data from the Splunk Enterprise Security (ES) Investigation Panel stored?
In the previous version, it seemed to be stored in a KV lookup, but I can't find it in the current 7.x version.
I understand that the Notable index holds information related to incidents from the Incident Review Dashboard.
How can we map Splunk Notables and their Investigations together to generate a comprehensive report in the current 7.x ES version?