<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212392#M1229</link>
    <description>&lt;P&gt;In our Splunk Enterprise Security instance, I can't enable the default correlation searches that come with it.&lt;/P&gt;

&lt;P&gt;I'm logged as Administrator in Splunk.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jan 2017 14:44:48 GMT</pubDate>
    <dc:creator>Yaichael</dc:creator>
    <dc:date>2017-01-03T14:44:48Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212392#M1229</link>
      <description>&lt;P&gt;In our Splunk Enterprise Security instance, I can't enable the default correlation searches that come with it.&lt;/P&gt;

&lt;P&gt;I'm logged as Administrator in Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 14:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212392#M1229</guid>
      <dc:creator>Yaichael</dc:creator>
      <dc:date>2017-01-03T14:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212393#M1230</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;can you provide some details: What's happening when you try to enable them ? Is there an error message ?  What version and OS are you running ? Do you have a Splunk license ?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 14:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212393#M1230</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2017-01-03T14:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212394#M1231</link>
      <description>&lt;P&gt;Hi mdessus,&lt;/P&gt;

&lt;P&gt;Thanks for the reply.&lt;/P&gt;

&lt;P&gt;In the Actions column of the correlation searches, there is no toggle menu or button to enable the correlation. No, there is no error message being displayed, at least. I'm running ESS v4.5.1 on Windows. Yes, I have a Splunk license.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 15:05:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212394#M1231</guid>
      <dc:creator>Yaichael</dc:creator>
      <dc:date>2017-01-03T15:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212395#M1232</link>
      <description>&lt;P&gt;So, when you go to &lt;EM&gt;ES app / Configure / Content Management&lt;/EM&gt;, there is nothing in the Actions column, in any pages ?&lt;BR /&gt;
Have you done the ES setup ? &lt;BR /&gt;
Do you have any errors when you go to &lt;EM&gt;Settings / Monitoring Console / Health Check&lt;/EM&gt; ?&lt;BR /&gt;
Any specific errors when you search  &lt;EM&gt;index=_&lt;/EM&gt;* ?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 15:13:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212395#M1232</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2017-01-03T15:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212396#M1233</link>
      <description>&lt;P&gt;When I follow the mentioned path, in the Actions column of a correlation search, I can only see the action "Disabled".&lt;/P&gt;

&lt;P&gt;I did the Splunk Enterprise Security Post-Install Configuration.&lt;/P&gt;

&lt;P&gt;No, there are no errors in the Monitoring Console.&lt;/P&gt;

&lt;P&gt;There was a Data Model that wasn't being found, but shared it through all the apps, and that fixed the issue, but other than that, there are no errors.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 17:58:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212396#M1233</guid>
      <dc:creator>Yaichael</dc:creator>
      <dc:date>2017-01-03T17:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212397#M1234</link>
      <description>&lt;P&gt;Hi mdessus,&lt;/P&gt;

&lt;P&gt;I found the issue. ESS doesn't provide the edit_correlationsearches capability by default to the admin user.&lt;/P&gt;

&lt;P&gt;Sorry for the bother and thanks for the help.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 19:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212397#M1234</guid>
      <dc:creator>Yaichael</dc:creator>
      <dc:date>2017-01-03T19:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212398#M1235</link>
      <description>&lt;P&gt;Hum... it used to !&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 21:44:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212398#M1235</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2017-01-03T21:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212399#M1236</link>
      <description>&lt;P&gt;Umm maybe something went wrong in the installation?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2017 12:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212399#M1236</guid>
      <dc:creator>Yaichael</dc:creator>
      <dc:date>2017-01-04T12:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212400#M1237</link>
      <description>&lt;P&gt;Just to clarify, the ess_admin role gets the edit_correlationsearches capability assignment and the admin role should be inheriting the ess_admin role. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:16:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212400#M1237</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2020-09-29T12:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why can't I enable the default correlation searches as an admin user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212401#M1238</link>
      <description>&lt;P&gt;Thanks for the comment, ekost!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 19:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-can-t-I-enable-the-default/m-p/212401#M1238</guid>
      <dc:creator>Yaichael</dc:creator>
      <dc:date>2017-01-05T19:30:19Z</dc:date>
    </item>
  </channel>
</rss>

