Knowledge Management

Getting an error message as the rule has a malformed related_searches definition?

LRathinakumar
Explorer

Hello all,

I am getting an continuous error as the rule has a malformed related_searches definition. i have checked the lookup file as well and everything found normal but i am still getting the error. Is there any inconsistency in the query. The below is the query is used for alerting.

 

index=wineventlog source="*WinEventLog:Security" EventCode=4688
[
| inputlookup tools.csv WHERE discovery_or_attack=attack
| stats values(filename) as search ]
| transaction host maxpause=5m
| where eventcount>=4
| fields _raw closed_txn field_match_sum linecount

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share the exact text of the error message and what you are doing when the message appears.   Please also share the savedsearches.conf stanza for the correlation search.

---
If this reply helps you, Karma would be appreciated.
0 Karma

LRathinakumar
Explorer

Hi @richgalloway 

 

Thank you for the reply.

 

Please find the error that was displayed frequently in messages column.

 

LRathinakumar_0-1668533223113.png

 

and i can't get the savedsearch.conf stanza as we are using the splunk cloud.

Thank you

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If that correlation search was provided by a Splunk app then contact Splunk Cloud Support to have them re-install the app or correct the savedsearches.conf entry.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...