Dear Elastic Team, we have started to work with your SIEM module. We have defined many detection rules. Signals generated based on these rules can be simply closed (signal.status: "Closed").
We would -of course - like to close signals with many another statuses or sub-statuses, e.g. False Positive, Low Impact, Duplicate etc. How can we do that? Based on these statuses/sub-statuses we would like to create dashboards with signal statistics. thank you in advance. Jan
we get on tickets from other community members, the higher the feature usually rises in our backlog to work on.