Hello,
I'm trying to add an email alert as an Adaptive Response Action to a built-in correlation search in Enterprise security, when I add it, it gives me an error.
Any help would be appreciated.
Thank You
Hi, @SplunkSanc simply try to save your correlation search with a sorter name it would solve this error.
--------------------------------------------------------
If this helps your like will be appreciated😊
Hi @SplunkSanc,
Which built-in correlation search are you trying to add an email alert to?
(I can try to replicate it on my end)
Also, which version of Splunk Enterprise are you running?
Look forward to hearing from you!
V/R,
nwuest