Has anyone attempted to enable all the correlation searches in the "Use Case Library" for enterprise security?
There are over 1,000 correlation searches.
Will this impact the performance of the Search Head (SH) and indexer?
If I have 1,000 EPS, what hardware resources would be required? Alternatively, what minimum hardware resources are needed to enable all the correlation searches in the use case library?
Thank you.
Hi @Abdulkareem ,
none will never enable al the available CS because you have to enable only the ones that have data to run, there's no sense to enable all the CS you have!
then, between the ones with data, you have to choose the ones to enable based on your infrastructure.
Remeber that every search in Splunk takes a CPU and release it when finishes, so you have to analyze your data, define the CS to enable and then designe the infrastructure to run your searches, Splunk ES requires at least 16 CPUs and 64 GB RAM, but the resources depen on the number of users and the number of CSs.
Second approach is to start with a standard configuration: (16/32 CPUs and 64/128 GB RAM), enable all the searches for your data and see if the resuorces are sufficient or not.
Ciao.
Giuseppe