Security & the Enterprise
Much secured. So patch!

Splunk ES Content Management Enable All

mikefg
Communicator

Setting up a new ES install and looking at Content Management. It looks like there are a lot of Disabled items, mostly correlation search.

Are there any guidelines for which of these to enable?

Is enabling all of them a bad idea?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, enabling them all is a bad idea.  That is why they are disabled by default.  One should enable the correlation searches that fit your data and Splunk use cases.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Yes, enabling them all is a bad idea.  That is why they are disabled by default.  One should enable the correlation searches that fit your data and Splunk use cases.

---
If this reply helps you, Karma would be appreciated.

mikefg
Communicator

Thank you for the clarification.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...