Getting Data In

Is there a way to Rename ES Correlation search?

VK18
Explorer

Hi Team.

I'm looking for a way to rename a correlation search that has been created with the wrong format. The CS is currently disabled but I don't see a way to actually rename it.

If i delete it from Saved searches, Will it remove all notables which got created from this custom CS created?

Regards
Varun

 

0 Karma

javiergn
Super Champion

Hi @VK18 , please let us know if any of the previous answers helped so that we can close the thread.

 

Regards,

Javier

0 Karma

javiergn
Super Champion

Hi @VK18 ,

 

You can rename a Correlation Search label (but not the actual saved search stanza within savedsearches.conf) from Settings > Searches, reports and alerts > Find your search there > Then click on advanced edit > look for the field "action.correlationsearch.label".

Edit that value and the actual label you see when going to the Correlation Searches page will be updated.

If you want to edit both the search name and its correlation search label you have to do it through the savedsearches.conf file but sometimes is easier to just clone it with a different name from the GUI (including permissions) and then simply delete the old one.

Let me know if that helps.

Regards,

J

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi @VK18 ,

you cannot rename a Correlation Search, you can clone it with another name and eventually delete the previous, don't delete original CSs, only custom.

if you're speaking of CSs from ES and its modules, I hint to clone them in your own app not in ES ot its modules, to have more control on the customized CSs, this is an approach hinted by Splunk PS.

You can also find CSs in [Settings > Searches, Reports and Alerts].

If you delete a CS, Notables will not be deleted because they are written in the notable index.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Technically, you can edit your .conf files and rename the search there. But if your environment is a search-head cluster manually editing local settings can cause some unexpected results due to replication so I'd advise against it.

Since notables are events I wouldn't expect them to magically disappear just because you deleted a search.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...