Splunk Answers-a-thon!

How can I set up notable events and correlation searches in Splunk ES?

yeasuh
Splunk Employee
Splunk Employee

How can I set up notable events and correlation searches in Splunk ES?

Labels (2)
0 Karma

ejahnke
Explorer

Hey yeasuh,

head over to https://docs.splunk.com/Documentation/ES/7.1.1/Tutorials/CorrelationSearch

Assuming you already got an idea for a CS you Skip to Part 2 and follow the instructions there. You could also use the guided mode, if youre not that comfortable with using SPL.

For the notable part: Go to Step 5 and chose the adaptive response action "Notable ". The docs are pretty thorough and should anwers all your questions. If you got any more questions after going thru the docs just hit me up. Cheers!

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...