<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk ES correlation searches problem in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-correlation-searches-problem/m-p/418389#M5115</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have figured out a strange behavior of Splunk correlation searches. I'm using Splunk Enterprise version 7.0.1 and ES version 4.7.4.&lt;BR /&gt;
I created a new app to store my custom correlation searches and ensured that it is accepted by Enterprise Security by naming it TA-custom-correlation-searches.&lt;BR /&gt;
Inside that app I created under local a savedsearches.conf configuration with the following content.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#comment1

[Threat - correlation_search_1 - Rule] 
configuration1=... 
configuration2=... 
....

#comment2
#comment3
#comment4
#comment5

[Threat - corelation_search_2 - Rule] 
configuration1=... 
configuration2=... 
....

#comment6
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Both correlation searches work as expected. At this point everything is fine.&lt;BR /&gt;
Now, I disable both correlation searches in the ES app under Content Management and afterwards I took a look into my savedsearches.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#comment1

[Threat - correlation_search_1 - Rule] 
configuration1=...
configuration2=...
....


[Threat - corelation_search_2 - Rule]
configuration1=...
configuration2=...
....

#comment6
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk deleted all comments between the two correlation searches.&lt;BR /&gt;
Did somebody figure out the same issue?&lt;BR /&gt;
Thank you for your help.&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
Patrick&lt;/P&gt;</description>
    <pubDate>Fri, 25 May 2018 07:44:03 GMT</pubDate>
    <dc:creator>BAPA157</dc:creator>
    <dc:date>2018-05-25T07:44:03Z</dc:date>
    <item>
      <title>Splunk ES correlation searches problem</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-correlation-searches-problem/m-p/418389#M5115</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have figured out a strange behavior of Splunk correlation searches. I'm using Splunk Enterprise version 7.0.1 and ES version 4.7.4.&lt;BR /&gt;
I created a new app to store my custom correlation searches and ensured that it is accepted by Enterprise Security by naming it TA-custom-correlation-searches.&lt;BR /&gt;
Inside that app I created under local a savedsearches.conf configuration with the following content.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#comment1

[Threat - correlation_search_1 - Rule] 
configuration1=... 
configuration2=... 
....

#comment2
#comment3
#comment4
#comment5

[Threat - corelation_search_2 - Rule] 
configuration1=... 
configuration2=... 
....

#comment6
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Both correlation searches work as expected. At this point everything is fine.&lt;BR /&gt;
Now, I disable both correlation searches in the ES app under Content Management and afterwards I took a look into my savedsearches.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#comment1

[Threat - correlation_search_1 - Rule] 
configuration1=...
configuration2=...
....


[Threat - corelation_search_2 - Rule]
configuration1=...
configuration2=...
....

#comment6
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk deleted all comments between the two correlation searches.&lt;BR /&gt;
Did somebody figure out the same issue?&lt;BR /&gt;
Thank you for your help.&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
Patrick&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 07:44:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-correlation-searches-problem/m-p/418389#M5115</guid>
      <dc:creator>BAPA157</dc:creator>
      <dc:date>2018-05-25T07:44:03Z</dc:date>
    </item>
  </channel>
</rss>

