<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tuning ES to environment in Security</title>
    <link>https://community.splunk.com/t5/Security/Tuning-ES-to-environment/m-p/565323#M15566</link>
    <description>&lt;P&gt;How are you tuning ES to your environment?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you overwriting the correlation searches that ship with ES or are you making copies of them and modifying the copies?&lt;/P&gt;&lt;P&gt;When there is an update for ES, are you having to go correlation search by correlation search, line by line to comparing them to see what changed?&lt;/P&gt;&lt;P&gt;What about ES Content Updates?&lt;/P&gt;</description>
    <pubDate>Tue, 31 Aug 2021 12:46:09 GMT</pubDate>
    <dc:creator>wgawhh5hbnht</dc:creator>
    <dc:date>2021-08-31T12:46:09Z</dc:date>
    <item>
      <title>Tuning ES to environment</title>
      <link>https://community.splunk.com/t5/Security/Tuning-ES-to-environment/m-p/565323#M15566</link>
      <description>&lt;P&gt;How are you tuning ES to your environment?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you overwriting the correlation searches that ship with ES or are you making copies of them and modifying the copies?&lt;/P&gt;&lt;P&gt;When there is an update for ES, are you having to go correlation search by correlation search, line by line to comparing them to see what changed?&lt;/P&gt;&lt;P&gt;What about ES Content Updates?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 12:46:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Tuning-ES-to-environment/m-p/565323#M15566</guid>
      <dc:creator>wgawhh5hbnht</dc:creator>
      <dc:date>2021-08-31T12:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Tuning ES to environment</title>
      <link>https://community.splunk.com/t5/Security/Tuning-ES-to-environment/m-p/565324#M15567</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156786"&gt;@wgawhh5hbnht&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;tuning an ES environment isn't a job to ask in Community but it requires Splunk Professional Services or at least a Training on ES Administration!&lt;/P&gt;&lt;P&gt;Anyway,&amp;nbsp;the most important tuning is to see if there are problems on resources when Scheduled Searches are executed; then you have to see if there are queues in Indexing.&lt;/P&gt;&lt;P&gt;You can check all using the Splunk Monitoring Console.&lt;/P&gt;&lt;P&gt;About the other questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;make always a copy of Correlation Searches and modify them,&lt;/LI&gt;&lt;LI&gt;updates in Correlation Searches are always documented in the Release Notes, so you don't need to check them row by row, but you can see the release notes,&lt;/LI&gt;&lt;LI&gt;ES Content Updates are other Use Cases already available for the users.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 14:28:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Tuning-ES-to-environment/m-p/565324#M15567</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-08-31T14:28:31Z</dc:date>
    </item>
  </channel>
</rss>

