Knowledge Management

Correlation searches in the "Use Case Library"

Abdulkareem
Engager

Has anyone attempted to enable all the correlation searches in the "Use Case Library" for enterprise security?

There are over 1,000 correlation searches.

Will this impact the performance of the Search Head (SH) and indexer?
If I have 1,000 EPS, what hardware resources would be required? Alternatively, what minimum hardware resources are needed to enable all the correlation searches in the use case library?

Thank you.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Abdulkareem ,

none will never enable al the available CS because you have to enable only the ones that have data to run, there's no sense to enable all the CS you have!

then, between the ones with data, you have to choose the ones to enable based on your infrastructure.

Remeber that every search in Splunk takes a CPU and release it when finishes, so you have to analyze your data, define the CS to enable and then designe the infrastructure to run your searches, Splunk ES requires at least 16 CPUs and 64 GB RAM, but the resources depen on the number of users and the number of CSs.

Second approach is to start with a standard configuration: (16/32 CPUs and 64/128 GB RAM), enable all the searches for your data and see if the resuorces are sufficient or not.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...