Getting Data In

Is there a way to Rename ES Correlation search?

VK18
Explorer

Hi Team.

I'm looking for a way to rename a correlation search that has been created with the wrong format. The CS is currently disabled but I don't see a way to actually rename it.

If i delete it from Saved searches, Will it remove all notables which got created from this custom CS created?

Regards
Varun

 

0 Karma

javiergn
Super Champion

Hi @VK18 , please let us know if any of the previous answers helped so that we can close the thread.

 

Regards,

Javier

0 Karma

javiergn
Super Champion

Hi @VK18 ,

 

You can rename a Correlation Search label (but not the actual saved search stanza within savedsearches.conf) from Settings > Searches, reports and alerts > Find your search there > Then click on advanced edit > look for the field "action.correlationsearch.label".

Edit that value and the actual label you see when going to the Correlation Searches page will be updated.

If you want to edit both the search name and its correlation search label you have to do it through the savedsearches.conf file but sometimes is easier to just clone it with a different name from the GUI (including permissions) and then simply delete the old one.

Let me know if that helps.

Regards,

J

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi @VK18 ,

you cannot rename a Correlation Search, you can clone it with another name and eventually delete the previous, don't delete original CSs, only custom.

if you're speaking of CSs from ES and its modules, I hint to clone them in your own app not in ES ot its modules, to have more control on the customized CSs, this is an approach hinted by Splunk PS.

You can also find CSs in [Settings > Searches, Reports and Alerts].

If you delete a CS, Notables will not be deleted because they are written in the notable index.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Technically, you can edit your .conf files and rename the search there. But if your environment is a search-head cluster manually editing local settings can cause some unexpected results due to replication so I'd advise against it.

Since notables are events I wouldn't expect them to magically disappear just because you deleted a search.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...