Splunk Enterprise Security

Correlation searches scheduling to overcome downtimes and event delays

tibi
Observer

Hello,

 

Hello,

 

Any suggestions on how to configure the correlation search schedule in a way that will not be affected by a maintenance downtime ? 

 

For example if you have a correlation search that is schedule to run every hour at minute 5 for the last hour . how can be configured to cover also the skipped run and to not miss alerts?

 

Thanks.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you do your correlation search over a couple of hours bucketed by hour, then append the previous results and remove duplicates?

0 Karma

tibi
Observer

thanks for the reply.

 

please can you provide an example how to configure the cs and how to exclude duplicates?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...