Setting up a new ES install and looking at Content Management. It looks like there are a lot of Disabled items, mostly correlation search.
Are there any guidelines for which of these to enable?
Is enabling all of them a bad idea?
Yes, enabling them all is a bad idea. That is why they are disabled by default. One should enable the correlation searches that fit your data and Splunk use cases.
Yes, enabling them all is a bad idea. That is why they are disabled by default. One should enable the correlation searches that fit your data and Splunk use cases.
Thank you for the clarification.