Splunk Enterprise Security

Enterprise Security: what makes a correlation search a correlation search?

danielbb
Motivator

I'm looking at a sample correlation search called Abnormally High Number of HTTP Method Events By Src -

| tstats `summariesonly` count as web_event_count from datamodel=Web.Web by Web.src, Web.http_method 
| `drop_dm_object_name("Web")` 
| xswhere web_event_count FROM count_by_http_method_by_src_1d in web by http_method is above high

What makes it a correlation search?

1 Solution

lkutch_splunk
Splunk Employee
Splunk Employee

Hi,
According to the ES tutorial... it's not just a search, but a search that then does one of the following:
"A correlation search is a type of search that evaluates events from one or more data sources for defined patterns. When the search finds a pattern, it creates a notable event, adjusts a risk score, or performs an adaptive response action. A correlation search is a saved search with extended capabilities making it easier to create, edit, and use searches for security use cases."
https://docs.splunk.com/Documentation/ES/5.3.1/Tutorials/CorrelationSearch

So since it creates a notable event, it's a correlation search.

View solution in original post

lkutch_splunk
Splunk Employee
Splunk Employee

Hi,
According to the ES tutorial... it's not just a search, but a search that then does one of the following:
"A correlation search is a type of search that evaluates events from one or more data sources for defined patterns. When the search finds a pattern, it creates a notable event, adjusts a risk score, or performs an adaptive response action. A correlation search is a saved search with extended capabilities making it easier to create, edit, and use searches for security use cases."
https://docs.splunk.com/Documentation/ES/5.3.1/Tutorials/CorrelationSearch

So since it creates a notable event, it's a correlation search.

danielbb
Motivator

Ok, makes sense.

This particular search has the following Adaptive Response Actions -

1) Risk Analysis
2) Notable

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...