<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk ES Correlation Search Not Firing [When it should] in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-ES-Correlation-Search-Not-Firing-When-it-should/m-p/536146#M10125</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes the search runs every 5 minutes, and looks back 1 hour. Today it should have generated three unique alerts.&lt;/P&gt;&lt;P&gt;Its been running for a couple days at this point, and the base search has matched 10 + events. We've received 0 though.&lt;/P&gt;</description>
    <pubDate>Sun, 17 Jan 2021 15:42:23 GMT</pubDate>
    <dc:creator>BrianKJr</dc:creator>
    <dc:date>2021-01-17T15:42:23Z</dc:date>
    <item>
      <title>Splunk ES Correlation Search Not Firing [When it should]</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-ES-Correlation-Search-Not-Firing-When-it-should/m-p/536128#M10123</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So I am working on a CS for Enterprise Security that&amp;nbsp; -- when run manually -- it returns results; however, when its scheduled to run it does not return anything.&lt;/P&gt;&lt;P&gt;I've looked in the _internal index and found that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;0 suppressions are taking effect&lt;/LI&gt;&lt;LI&gt;0 results are returned&lt;/LI&gt;&lt;LI&gt;All searches are ran successfully&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I've looked in the notable's index and confirmed that 0 alerts are firing.&lt;/P&gt;&lt;P&gt;The CS is running as ADMIN within the application context of Enterprise Security.&lt;/P&gt;&lt;P&gt;This is the search:&lt;/P&gt;&lt;P&gt;index=cylance_protect sourcetype=threat&lt;BR /&gt;| eval FirstFound=split('First Found'," ")&lt;BR /&gt;| eval FirstFoundDate=mvindex(FirstFound,0)&lt;BR /&gt;| eval FirstFoundDate_epoch=strptime(FirstFoundDate, "%m/%d/%Y")&lt;BR /&gt;| eval currentTime=now()&lt;BR /&gt;| eval currentTime=strftime(currentTime, "%m/%d/%Y")&lt;BR /&gt;| eval currentTime_epoch=strptime(currentTime, "%m/%d/%Y")&lt;BR /&gt;| eval CreatedDaysAgo=(currentTime_epoch-FirstFoundDate_epoch)/86400&lt;BR /&gt;| eval CreatedDaysAgo=round(CreatedDaysAgo)&lt;BR /&gt;| search CreatedDaysAgo &amp;lt; 2&lt;BR /&gt;| table _time FirstFound CreatedDaysAgo DeviceName Tenant user action "Cylance Score" signature "Detected By" "Ever Run" "File Name" file_path file_hash&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are the eval statements causing this issue? I used the above logic to ONLY return 'new' Cylance detections within the last 1 day.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 20:53:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-ES-Correlation-Search-Not-Firing-When-it-should/m-p/536128#M10123</guid>
      <dc:creator>BrianKJr</dc:creator>
      <dc:date>2021-01-16T20:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Correlation Search Not Firing [When it should]</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-ES-Correlation-Search-Not-Firing-When-it-should/m-p/536130#M10124</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/57499"&gt;@BrianKJr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The problem may be the time range setting on your correlation search. Are you using the same time-range on manual testing? Maybe you should increase time-range on your correlation search.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 21:15:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-ES-Correlation-Search-Not-Firing-When-it-should/m-p/536130#M10124</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-16T21:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Correlation Search Not Firing [When it should]</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-ES-Correlation-Search-Not-Firing-When-it-should/m-p/536146#M10125</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes the search runs every 5 minutes, and looks back 1 hour. Today it should have generated three unique alerts.&lt;/P&gt;&lt;P&gt;Its been running for a couple days at this point, and the base search has matched 10 + events. We've received 0 though.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2021 15:42:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-ES-Correlation-Search-Not-Firing-When-it-should/m-p/536146#M10125</guid>
      <dc:creator>BrianKJr</dc:creator>
      <dc:date>2021-01-17T15:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Correlation Search Not Firing [When it should]</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-ES-Correlation-Search-Not-Firing-When-it-should/m-p/536373#M10130</link>
      <description>&lt;P&gt;After further troubleshooting the time range WAS the issue due to API schedule for threats being forwarded to Splunk.. The API through Cylance / Splunk will need to be looked at because its not sending logs as often as it should be.&lt;/P&gt;&lt;P&gt;The solution for the interim is to extend the time range from 2 hours to 12 hours.&lt;/P&gt;&lt;P&gt;Thanks for responding &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 18:51:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-ES-Correlation-Search-Not-Firing-When-it-should/m-p/536373#M10130</guid>
      <dc:creator>BrianKJr</dc:creator>
      <dc:date>2021-01-19T18:51:55Z</dc:date>
    </item>
  </channel>
</rss>

