Dear Elastic Team, we have started to work with your SIEM module. We have defined many detection rules. Signals generated based on these rules can be simply closed (signal.status: "Closed").
We would -of course - like to close signals with many another statuses or sub-statuses, e.g. False Positive, Low Impact, Duplicate etc. How can we do that? Based on these statuses/sub-statuses we would like to create dashboards with signal statistics. thank you in advance. Jan