<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correlation searches in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-searches/m-p/480659#M7702</link>
    <description>&lt;P&gt;Whats your splunk core and ES version? The searches do get updated (if there is an update, in the default/savedsearches.conf of the respective app). However, if you had overwritten them and have a copy in your local/savedsearches.conf, you would need to validate/reconcile them.&lt;/P&gt;</description>
    <pubDate>Wed, 06 May 2020 09:32:30 GMT</pubDate>
    <dc:creator>lakshman239</dc:creator>
    <dc:date>2020-05-06T09:32:30Z</dc:date>
    <item>
      <title>Correlation searches</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-searches/m-p/480658#M7701</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I upgraded my Splunk ES and i could notice that for some reason the "Out Of The Box" correlation searches are not getting upgraded to their newer version.&lt;/P&gt;
&lt;P&gt;Does anyone know why?&lt;/P&gt;
&lt;P&gt;Do i have to manually upgrade every correlation search?&lt;/P&gt;
&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 16:31:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-searches/m-p/480658#M7701</guid>
      <dc:creator>astatrial</dc:creator>
      <dc:date>2020-06-07T16:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation searches</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-searches/m-p/480659#M7702</link>
      <description>&lt;P&gt;Whats your splunk core and ES version? The searches do get updated (if there is an update, in the default/savedsearches.conf of the respective app). However, if you had overwritten them and have a copy in your local/savedsearches.conf, you would need to validate/reconcile them.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 09:32:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-searches/m-p/480659#M7702</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2020-05-06T09:32:30Z</dc:date>
    </item>
  </channel>
</rss>

