Knowledge Management

Correlation searches in the "Use Case Library"

Abdulkareem
Engager

Has anyone attempted to enable all the correlation searches in the "Use Case Library" for enterprise security?

There are over 1,000 correlation searches.

Will this impact the performance of the Search Head (SH) and indexer?
If I have 1,000 EPS, what hardware resources would be required? Alternatively, what minimum hardware resources are needed to enable all the correlation searches in the use case library?

Thank you.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Abdulkareem ,

none will never enable al the available CS because you have to enable only the ones that have data to run, there's no sense to enable all the CS you have!

then, between the ones with data, you have to choose the ones to enable based on your infrastructure.

Remeber that every search in Splunk takes a CPU and release it when finishes, so you have to analyze your data, define the CS to enable and then designe the infrastructure to run your searches, Splunk ES requires at least 16 CPUs and 64 GB RAM, but the resources depen on the number of users and the number of CSs.

Second approach is to start with a standard configuration: (16/32 CPUs and 64/128 GB RAM), enable all the searches for your data and see if the resuorces are sufficient or not.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...