<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ES (Enterprise Security)  | Correlation Searches | Cannot Remove in Security</title>
    <link>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68372#M13977</link>
    <description>&lt;P&gt;Hi - Am having problems removing a "correlation search".  Have tried this via the SE UI from inside the editor and within the "correlation searches" list/page.  Can't find a delete or remove button or anything else.  Am on Splunk 5.02 with ES 2.4 app. Any ideas?&lt;/P&gt;

&lt;P&gt;Thanks... Al&lt;/P&gt;</description>
    <pubDate>Thu, 19 Sep 2013 16:55:42 GMT</pubDate>
    <dc:creator>aportela_work</dc:creator>
    <dc:date>2013-09-19T16:55:42Z</dc:date>
    <item>
      <title>ES (Enterprise Security)  | Correlation Searches | Cannot Remove</title>
      <link>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68372#M13977</link>
      <description>&lt;P&gt;Hi - Am having problems removing a "correlation search".  Have tried this via the SE UI from inside the editor and within the "correlation searches" list/page.  Can't find a delete or remove button or anything else.  Am on Splunk 5.02 with ES 2.4 app. Any ideas?&lt;/P&gt;

&lt;P&gt;Thanks... Al&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2013 16:55:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68372#M13977</guid>
      <dc:creator>aportela_work</dc:creator>
      <dc:date>2013-09-19T16:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: ES (Enterprise Security)  | Correlation Searches | Cannot Remove</title>
      <link>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68373#M13978</link>
      <description>&lt;P&gt;Unfortunately, deletion of correlation searches is not supported from the UI yet.&lt;/P&gt;

&lt;P&gt;If the correlation search is one that is shipped with ES, then I don't recommend attempting to remove it. Instead, just disable it.&lt;/P&gt;

&lt;P&gt;If the correlation search is a custom one, then the way to delete one is to find the instance in savedsearches.conf (should be under a local directory) and remove it manually. Restart Splunk after you prune the entry from the conf file.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2013 20:03:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68373#M13978</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2013-09-19T20:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: ES (Enterprise Security)  | Correlation Searches | Cannot Remove</title>
      <link>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68374#M13979</link>
      <description>&lt;P&gt;hey, we found the solution, and below explains the process:&lt;BR /&gt;
.&lt;BR /&gt;
If the Correlated Search was called "Non-standard Access Detect" ... &lt;BR /&gt;
and was created/configured with the "Access" domain assigned ... &lt;BR /&gt;
the search will part of the SA-AccessProtection app ...&lt;BR /&gt;&lt;BR /&gt;
... So, will want to look for a search title that appends the domain and search names.&lt;BR /&gt;
That is where we found a place to delete the specific Correlated Search.&lt;/P&gt;

&lt;P&gt;Hurrah &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2013 23:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68374#M13979</guid>
      <dc:creator>aportela_work</dc:creator>
      <dc:date>2013-09-19T23:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: ES (Enterprise Security)  | Correlation Searches | Cannot Remove</title>
      <link>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68375#M13980</link>
      <description>&lt;P&gt;Thanks for looking into this.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2013 23:26:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68375#M13980</guid>
      <dc:creator>aportela_work</dc:creator>
      <dc:date>2013-09-19T23:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: ES (Enterprise Security)  | Correlation Searches | Cannot Remove</title>
      <link>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68376#M13981</link>
      <description>&lt;P&gt;Forget to elaborate:&lt;BR /&gt;
Can find/delete this Correlated Search like any regular search; from the "Searches and Reports" page of the Manager  UI.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2013 23:29:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68376#M13981</guid>
      <dc:creator>aportela_work</dc:creator>
      <dc:date>2013-09-19T23:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: ES (Enterprise Security)  | Correlation Searches | Cannot Remove</title>
      <link>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68377#M13982</link>
      <description>&lt;P&gt;You can do something like: &lt;/P&gt;

&lt;P&gt;index=notable | head 10 | delete &lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 23:52:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68377#M13982</guid>
      <dc:creator>kausar</dc:creator>
      <dc:date>2016-09-27T23:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: ES (Enterprise Security)  | Correlation Searches | Cannot Remove</title>
      <link>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68378#M13983</link>
      <description>&lt;P&gt;There is no way to delete a correlation searches if you are on a single instance stopping splunk then removing the files from disk is going to be your best bet; how ever if you are using search head clustering or splunk cloud you can use the REST API to delete the object. This is not a supported method but it will act as a heavy handed approach.&lt;/P&gt;

&lt;P&gt;In my case I had users delete the saved searches out from under ES so I am only going to show the removal of the correlation search config object.&lt;/P&gt;

&lt;P&gt;First you need to URL encode the stanza you want to target.&lt;/P&gt;

&lt;P&gt;Stanza in the file &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Network - AWS CloudTrail Logging - Rule]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Url encoded version&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Network%20-%20AWS%20CloudTrail%20Logging%20-%20Rule
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;From the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/RESTREF/RESTconf"&gt;REST API docs&lt;/A&gt; we want to view the object first&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="https://&amp;lt;host&amp;gt;:&amp;lt;mPort&amp;gt;/services/configs/conf-correlationsearches/{stanza}" target="test_blank"&gt;https://&amp;lt;host&amp;gt;:&amp;lt;mPort&amp;gt;/services/configs/conf-correlationsearches/{stanza}&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For my example the curl call would be&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;curl -k -u admin:changeme &lt;A href="https://localhost:8089/services/configs/conf-correlationsearches/Network%20-%20AWS%20CloudTrail%20Logging%20-%20Rule" target="test_blank"&gt;https://localhost:8089/services/configs/conf-correlationsearches/Network%20-%20AWS%20CloudTrail%20Logging%20-%20Rule&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should return the XML for the object if you see "In handler 'conf-correlationsearches': Could not find object id=" STOP and check your URL encoding for your object.&lt;/P&gt;

&lt;P&gt;If you see your object there then you only need to make a delete request for my example that would be.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;curl -k -u admin:changeme --request DELETE &lt;A href="https://localhost:8089/services/configs/conf-correlationsearches/Network%20-%20AWS%20CloudTrail%20Logging%20-%20Rule" target="test_blank"&gt;https://localhost:8089/services/configs/conf-correlationsearches/Network%20-%20AWS%20CloudTrail%20Logging%20-%20Rule&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then run your first call to the conf-correlationsearches endpoint again and you should see something like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;response&amp;gt;
  &amp;lt;messages&amp;gt;
    &amp;lt;msg type="ERROR"&amp;gt;
 In handler 'conf-correlationsearches': Could not find object id=Network - AWS CloudTrail Logging - Rule&amp;lt;/msg&amp;gt;
  &amp;lt;/messages&amp;gt;
&amp;lt;/response&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That should be it; a restart of splunk is recommended but you can do a debug/refresh.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2017 15:15:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/ES-Enterprise-Security-Correlation-Searches-Cannot-Remove/m-p/68378#M13983</guid>
      <dc:creator>clynch4283</dc:creator>
      <dc:date>2017-01-10T15:15:59Z</dc:date>
    </item>
  </channel>
</rss>

