Hi SMEs,
Seeking advice on how i can create a rule/correlation search to detect some RHEL known vulnerabilities (CVEs)
Splunk is not a vulnerability scanner. It can index and report on results produced by dedicated vulnerability tools, but doesn't detect vulnerabilities on its own. That's not to say a Splunk query can't find anything with the right data (like, for instance, a running telnetd process) it's just typically not done that way.
If you have a specific vulnerability you need help detecting then post a new question and perhaps someone can help with it.