<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: correlation search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/correlation-search/m-p/391843#M167435</link>
    <description>&lt;P&gt;Thanks for posting. Could you give us some more context for your query? You have a much better chance of getting your question answered if you provide more information about your issue. Plus, it will help guide future community users who are facing a similar problem. &lt;/P&gt;</description>
    <pubDate>Tue, 25 Sep 2018 23:21:31 GMT</pubDate>
    <dc:creator>mstjohn_splunk</dc:creator>
    <dc:date>2018-09-25T23:21:31Z</dc:date>
    <item>
      <title>correlation search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/correlation-search/m-p/391842#M167434</link>
      <description>&lt;P&gt;hello every body  ,&lt;/P&gt;

&lt;P&gt;How to search to correlate  there use case please   : &lt;/P&gt;

&lt;P&gt;Detection of access to basic hash files passwords,&lt;BR /&gt;
connections from multiple IPs to the same accounts,&lt;BR /&gt;
Unauthorized device on the network,&lt;BR /&gt;
Logs deleted from source&lt;BR /&gt;
Please ?&lt;/P&gt;

&lt;P&gt;I want a request in the general framework and I will try to adapt my data.&lt;/P&gt;

&lt;P&gt;Thank in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 15:16:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/correlation-search/m-p/391842#M167434</guid>
      <dc:creator>ALLIACOM</dc:creator>
      <dc:date>2018-09-25T15:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: correlation search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/correlation-search/m-p/391843#M167435</link>
      <description>&lt;P&gt;Thanks for posting. Could you give us some more context for your query? You have a much better chance of getting your question answered if you provide more information about your issue. Plus, it will help guide future community users who are facing a similar problem. &lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 23:21:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/correlation-search/m-p/391843#M167435</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-09-25T23:21:31Z</dc:date>
    </item>
  </channel>
</rss>

