Knowledge Management

Correlation searches in the "Use Case Library"

Abdulkareem
Engager

Has anyone attempted to enable all the correlation searches in the "Use Case Library" for enterprise security?

There are over 1,000 correlation searches.

Will this impact the performance of the Search Head (SH) and indexer?
If I have 1,000 EPS, what hardware resources would be required? Alternatively, what minimum hardware resources are needed to enable all the correlation searches in the use case library?

Thank you.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Abdulkareem ,

none will never enable al the available CS because you have to enable only the ones that have data to run, there's no sense to enable all the CS you have!

then, between the ones with data, you have to choose the ones to enable based on your infrastructure.

Remeber that every search in Splunk takes a CPU and release it when finishes, so you have to analyze your data, define the CS to enable and then designe the infrastructure to run your searches, Splunk ES requires at least 16 CPUs and 64 GB RAM, but the resources depen on the number of users and the number of CSs.

Second approach is to start with a standard configuration: (16/32 CPUs and 64/128 GB RAM), enable all the searches for your data and see if the resuorces are sufficient or not.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...