<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security: How to backup and version control correlation searches used in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-backup-and-version-control/m-p/643592#M11519</link>
    <description>&lt;P&gt;You might like &lt;A href="https://splunkbase.splunk.com/app/6895" target="_blank"&gt;https://splunkbase.splunk.com/app/6895&lt;/A&gt; to track changes to your knowledge objects. It's no effort, doesn't require git or anything else, and works equally well on-prem and in cloud.&lt;/P&gt;&lt;P&gt;And it sounds like you should probably have a look at&amp;nbsp;my ES Choreographer app: &lt;A href="https://splunkbase.splunk.com/app/6309" target="_blank"&gt;https://splunkbase.splunk.com/app/6309&lt;/A&gt; as presented at .conf21 &lt;A href="https://conf.splunk.com/files/2021/recordings/SEC1441A.mp4" target="_blank"&gt;https://conf.splunk.com/files/2021/recordings/SEC1441A.mp4&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 May 2023 09:54:52 GMT</pubDate>
    <dc:creator>gabriel_vasseur</dc:creator>
    <dc:date>2023-05-17T09:54:52Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: How to backup and version control correlation searches used?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-backup-and-version-control/m-p/492433#M8405</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;
&lt;P&gt;I've looked around for a little and but was trying to find out if there was a way to backup and do version control with comments on saved correlation searches.&lt;/P&gt;
&lt;P&gt;We have multiple users that have access to our content in ES and wanted to do a well-documented version control/ backup of searches used in correlation search. We are currently doing this via private git instance but wanted to explore possibilities through Splunk.&lt;/P&gt;
&lt;P&gt;I've found some guidance using index=_internal from below but didn't get too far working with different source types within the index.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/525792/is-there-an-audit-log-that-tracks-changes-to-conte.html" target="_blank" rel="noopener"&gt;https://answers.splunk.com/answers/525792/is-there-an-audit-log-that-tracks-changes-to-conte.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 11:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-backup-and-version-control/m-p/492433#M8405</guid>
      <dc:creator>claxpum0n</dc:creator>
      <dc:date>2023-05-17T11:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to backup and version control correlation searches used</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-backup-and-version-control/m-p/492434#M8406</link>
      <description>&lt;P&gt;Have you looked at the apps for this?&lt;/P&gt;

&lt;P&gt;&lt;A href="https://github.com/paychex/Splunk.Conf19/"&gt;FN1315 - Cover Your Assets: Protect Your Knowledge Objects from Yourself (and Others) - A Paychex story&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/4182/"&gt;Git Version Control for Splunk&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/4355/"&gt;VersionControl For Splunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;There are pro's and con's to each solution, the last one is my version. It allows a user to restore via a dashboard but is likely the most complex of the mentioned solutions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 03:07:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-backup-and-version-control/m-p/492434#M8406</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2019-11-22T03:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to backup and version control correlation searches used</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-backup-and-version-control/m-p/527873#M9436</link>
      <description>&lt;P&gt;Splunk version 8.1 allows you to comment SPL searches. Maybe you could use that as a way to track changes.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=sN03YNKZeBM" target="_blank"&gt;https://www.youtube.com/watch?v=sN03YNKZeBM&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Search/Addcommentstosearches" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Search/Addcommentstosearches&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 10:36:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-backup-and-version-control/m-p/527873#M9436</guid>
      <dc:creator>securitypaul</dc:creator>
      <dc:date>2020-11-04T10:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to backup and version control correlation searches used</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-backup-and-version-control/m-p/643592#M11519</link>
      <description>&lt;P&gt;You might like &lt;A href="https://splunkbase.splunk.com/app/6895" target="_blank"&gt;https://splunkbase.splunk.com/app/6895&lt;/A&gt; to track changes to your knowledge objects. It's no effort, doesn't require git or anything else, and works equally well on-prem and in cloud.&lt;/P&gt;&lt;P&gt;And it sounds like you should probably have a look at&amp;nbsp;my ES Choreographer app: &lt;A href="https://splunkbase.splunk.com/app/6309" target="_blank"&gt;https://splunkbase.splunk.com/app/6309&lt;/A&gt; as presented at .conf21 &lt;A href="https://conf.splunk.com/files/2021/recordings/SEC1441A.mp4" target="_blank"&gt;https://conf.splunk.com/files/2021/recordings/SEC1441A.mp4&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 09:54:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-backup-and-version-control/m-p/643592#M11519</guid>
      <dc:creator>gabriel_vasseur</dc:creator>
      <dc:date>2023-05-17T09:54:52Z</dc:date>
    </item>
  </channel>
</rss>

