Splunk Enterprise Security

Enabled Correlation Search not running?

indmin
Loves-to-Learn Lots

I have enabled several correlation searches in ES. Those search run normally and return result as expected if I search them manually

However, those searches are not running as schedule and never show up if I search using "index=_internal sourcetype=scheduler". Also, their statistics in "Content Management" page suggest that they have been never triggered.

Do you have any suggestion on this issue??? 

Screenshot 2022-11-15 173903.png

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...