Knowledge Management

Correlation searches in the "Use Case Library"

Abdulkareem
Engager

Has anyone attempted to enable all the correlation searches in the "Use Case Library" for enterprise security?

There are over 1,000 correlation searches.

Will this impact the performance of the Search Head (SH) and indexer?
If I have 1,000 EPS, what hardware resources would be required? Alternatively, what minimum hardware resources are needed to enable all the correlation searches in the use case library?

Thank you.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Abdulkareem ,

none will never enable al the available CS because you have to enable only the ones that have data to run, there's no sense to enable all the CS you have!

then, between the ones with data, you have to choose the ones to enable based on your infrastructure.

Remeber that every search in Splunk takes a CPU and release it when finishes, so you have to analyze your data, define the CS to enable and then designe the infrastructure to run your searches, Splunk ES requires at least 16 CPUs and 64 GB RAM, but the resources depen on the number of users and the number of CSs.

Second approach is to start with a standard configuration: (16/32 CPUs and 64/128 GB RAM), enable all the searches for your data and see if the resuorces are sufficient or not.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...