Getting Data In

Is there a way to Rename ES Correlation search?

VK18
Explorer

Hi Team.

I'm looking for a way to rename a correlation search that has been created with the wrong format. The CS is currently disabled but I don't see a way to actually rename it.

If i delete it from Saved searches, Will it remove all notables which got created from this custom CS created?

Regards
Varun

 

0 Karma

javiergn
Super Champion

Hi @VK18 , please let us know if any of the previous answers helped so that we can close the thread.

 

Regards,

Javier

0 Karma

javiergn
Super Champion

Hi @VK18 ,

 

You can rename a Correlation Search label (but not the actual saved search stanza within savedsearches.conf) from Settings > Searches, reports and alerts > Find your search there > Then click on advanced edit > look for the field "action.correlationsearch.label".

Edit that value and the actual label you see when going to the Correlation Searches page will be updated.

If you want to edit both the search name and its correlation search label you have to do it through the savedsearches.conf file but sometimes is easier to just clone it with a different name from the GUI (including permissions) and then simply delete the old one.

Let me know if that helps.

Regards,

J

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi @VK18 ,

you cannot rename a Correlation Search, you can clone it with another name and eventually delete the previous, don't delete original CSs, only custom.

if you're speaking of CSs from ES and its modules, I hint to clone them in your own app not in ES ot its modules, to have more control on the customized CSs, this is an approach hinted by Splunk PS.

You can also find CSs in [Settings > Searches, Reports and Alerts].

If you delete a CS, Notables will not be deleted because they are written in the notable index.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Technically, you can edit your .conf files and rename the search there. But if your environment is a search-head cluster manually editing local settings can cause some unexpected results due to replication so I'd advise against it.

Since notables are events I wouldn't expect them to magically disappear just because you deleted a search.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...