Splunk Enterprise Security

Complete list and descriptions of pre-configured correlation searches in ES 4.0

javiergn
Super Champion

Hi all,

On a similar note to this question, I would also like to know the complete list of pre-configured correlation searches available in ES 4.0

We don't have ES installed and therefore I can't run the rest query suggested there, but I need this information in order to discuss the list internally before we can proceed with the POC and evaluation.

Thanks,
Javier

0 Karma
1 Solution

javiergn
Super Champion

Actually I'm going to answer myself as I just discovered I can have my own ES instance online and it's free for the next 15 days.

View solution in original post

saurabh_tek
Communicator

Hello Javiergn,
Although you have figured out yourself about the Enterprise security sandbox (link : http://blogs.splunk.com/2015/09/24/try-splunk-enterprise-security-for-free/). Now you can see the searches and queries running to power them. - Saurabh

0 Karma

javiergn
Super Champion

Actually I'm going to answer myself as I just discovered I can have my own ES instance online and it's free for the next 15 days.

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...