You configured SIEM agent to retrieve CloudSOC History logs using
--elastica_app INVESTIGATE --app Elastica
However, you notice not all the CloudSOC History Logs are exported.
-severity all in your query as the agent exports logs of error, critical, and warning levels, but not informational by default.