<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security: What is the distinction between savedsearch and correlation search? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282646#M2360</link>
    <description>&lt;P&gt;savedsearch is the search knowledge object for the notable. the correlationsearch.conf stanza goes with that and ES needs it for all the notable like settings. hooks to active responses, title, links for drill down etc.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Feb 2017 19:42:32 GMT</pubDate>
    <dc:creator>starcher</dc:creator>
    <dc:date>2017-02-08T19:42:32Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: What is the distinction between savedsearch and correlation search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282645#M2359</link>
      <description>&lt;P&gt;Trying to figure out why the Splunk Enterprise Security App has a savedsearch and a correlation search for brute force seems redundant but probably missing a key distinction. Can someone give me some guidance?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 19:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282645#M2359</guid>
      <dc:creator>jgbricker</dc:creator>
      <dc:date>2017-02-08T19:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: What is the distinction between savedsearch and correlation search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282646#M2360</link>
      <description>&lt;P&gt;savedsearch is the search knowledge object for the notable. the correlationsearch.conf stanza goes with that and ES needs it for all the notable like settings. hooks to active responses, title, links for drill down etc.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 19:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282646#M2360</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2017-02-08T19:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: What is the distinction between savedsearch and correlation search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282647#M2361</link>
      <description>&lt;P&gt;Okay so to clarify further, I would need both if I were adding my own detections into the ES framework? I didn't see that in the documentation.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 19:46:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282647#M2361</guid>
      <dc:creator>jgbricker</dc:creator>
      <dc:date>2017-02-08T19:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: What is the distinction between savedsearch and correlation search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282648#M2362</link>
      <description>&lt;P&gt;Yes, you would need stanzas in both if you were to add your own correlation searches. However, I'd recommend that you use the content management page to create the searches so that the proper attributes are saved in the proper locations. Starting in 4.6.0, only savedsearches.conf references are needed. &lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 20:04:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282648#M2362</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2017-02-08T20:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: What is the distinction between savedsearch and correlation search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282649#M2363</link>
      <description>&lt;P&gt;Yes and the GUI based create process handles all that for you.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/ES/4.6.0/Tutorials/CorrelationSearch"&gt;http://docs.splunk.com/Documentation/ES/4.6.0/Tutorials/CorrelationSearch&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 20:05:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282649#M2363</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2017-02-08T20:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: What is the distinction between savedsearch and correlation search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282650#M2364</link>
      <description>&lt;P&gt;Okay, it does appear that when i add a correlation search via the UI (Content Management &amp;gt; Create Content) a savedsearch is created automatically. Doesn't this mean Splunk has to search for the same thing twice to do all the things it needs to do for ES. Perhaps I'm still confused here.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 20:07:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282650#M2364</guid>
      <dc:creator>jgbricker</dc:creator>
      <dc:date>2017-02-08T20:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: What is the distinction between savedsearch and correlation search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282651#M2365</link>
      <description>&lt;P&gt;No, the search isn't performed twice, it's just a detail about how the search is stored.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 20:42:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-What-is-the-distinction-between/m-p/282651#M2365</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2017-02-08T20:42:24Z</dc:date>
    </item>
  </channel>
</rss>

