Security & the Enterprise
Much secured. So patch!

Splunk ES Content Management Enable All

mikefg
Communicator

Setting up a new ES install and looking at Content Management. It looks like there are a lot of Disabled items, mostly correlation search.

Are there any guidelines for which of these to enable?

Is enabling all of them a bad idea?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, enabling them all is a bad idea.  That is why they are disabled by default.  One should enable the correlation searches that fit your data and Splunk use cases.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Yes, enabling them all is a bad idea.  That is why they are disabled by default.  One should enable the correlation searches that fit your data and Splunk use cases.

---
If this reply helps you, Karma would be appreciated.

mikefg
Communicator

Thank you for the clarification.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...