Anybody out there had experience trying to correlate events with Splunk.
A scenario would be like this:
(Source : A Event XXX) + (Source : B Event YYY) = ( Result : kick off an event using a scipt )
Is correlation supported with Splunk?
This is something I am trying to accomplish altogether by creating my own app with saved searches. This helps seggregate the correlated data I want/need while making it easily accessible for all other parties. The app piece is purely optional, but when you do a saved search, you can kick off a script or an alert, base on your own choosing.