Splunk Enterprise Security

Enterprise Security: what makes a correlation search a correlation search?

danielbb
Motivator

I'm looking at a sample correlation search called Abnormally High Number of HTTP Method Events By Src -

| tstats `summariesonly` count as web_event_count from datamodel=Web.Web by Web.src, Web.http_method 
| `drop_dm_object_name("Web")` 
| xswhere web_event_count FROM count_by_http_method_by_src_1d in web by http_method is above high

What makes it a correlation search?

1 Solution

lkutch_splunk
Splunk Employee
Splunk Employee

Hi,
According to the ES tutorial... it's not just a search, but a search that then does one of the following:
"A correlation search is a type of search that evaluates events from one or more data sources for defined patterns. When the search finds a pattern, it creates a notable event, adjusts a risk score, or performs an adaptive response action. A correlation search is a saved search with extended capabilities making it easier to create, edit, and use searches for security use cases."
https://docs.splunk.com/Documentation/ES/5.3.1/Tutorials/CorrelationSearch

So since it creates a notable event, it's a correlation search.

View solution in original post

lkutch_splunk
Splunk Employee
Splunk Employee

Hi,
According to the ES tutorial... it's not just a search, but a search that then does one of the following:
"A correlation search is a type of search that evaluates events from one or more data sources for defined patterns. When the search finds a pattern, it creates a notable event, adjusts a risk score, or performs an adaptive response action. A correlation search is a saved search with extended capabilities making it easier to create, edit, and use searches for security use cases."
https://docs.splunk.com/Documentation/ES/5.3.1/Tutorials/CorrelationSearch

So since it creates a notable event, it's a correlation search.

danielbb
Motivator

Ok, makes sense.

This particular search has the following Adaptive Response Actions -

1) Risk Analysis
2) Notable

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...