Getting Data In

Is there a way to Rename ES Correlation search?

VK18
Explorer

Hi Team.

I'm looking for a way to rename a correlation search that has been created with the wrong format. The CS is currently disabled but I don't see a way to actually rename it.

If i delete it from Saved searches, Will it remove all notables which got created from this custom CS created?

Regards
Varun

 

0 Karma

javiergn
Super Champion

Hi @VK18 , please let us know if any of the previous answers helped so that we can close the thread.

 

Regards,

Javier

0 Karma

javiergn
Super Champion

Hi @VK18 ,

 

You can rename a Correlation Search label (but not the actual saved search stanza within savedsearches.conf) from Settings > Searches, reports and alerts > Find your search there > Then click on advanced edit > look for the field "action.correlationsearch.label".

Edit that value and the actual label you see when going to the Correlation Searches page will be updated.

If you want to edit both the search name and its correlation search label you have to do it through the savedsearches.conf file but sometimes is easier to just clone it with a different name from the GUI (including permissions) and then simply delete the old one.

Let me know if that helps.

Regards,

J

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi @VK18 ,

you cannot rename a Correlation Search, you can clone it with another name and eventually delete the previous, don't delete original CSs, only custom.

if you're speaking of CSs from ES and its modules, I hint to clone them in your own app not in ES ot its modules, to have more control on the customized CSs, this is an approach hinted by Splunk PS.

You can also find CSs in [Settings > Searches, Reports and Alerts].

If you delete a CS, Notables will not be deleted because they are written in the notable index.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Technically, you can edit your .conf files and rename the search there. But if your environment is a search-head cluster manually editing local settings can cause some unexpected results due to replication so I'd advise against it.

Since notables are events I wouldn't expect them to magically disappear just because you deleted a search.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...