Splunk Enterprise Security

How come I'm unable to disable a correlation search nor able to save the changes made on it?

shiv1593
Communicator

Hi All,

This is a two fold question.

Specs: Splunk Enterprise Security Version 6.6.1

Problem 1: I'm trying to disable a correlation search, but am unable to do so. When I click on disable, inside the content management, it says "Searches have been sucessfully disabled", but the one particular search isn't getting disabled.

The problem is that the app TA-Domaintools, using which the search was created, is no longer configured properly. By the time I took over the administration of our environment, we have seemed to have lost the API key and the credentials for it. It asks for reconfiguration, but we can't do that without the credentials.

Problem 2: The app is scheduled to run on a cron schedule of every 5 minutes. Since I was unable to disable the search, I tried to schedule to run on every December 31st, at 12 AM. The cron i put in there is 12/31*/12*. The syntax is wrong, so I tried to save the original one, /5***

But then, it started throwing an error while saving: ' there was an error saving the correlation search. invalid alert_comparator="" '.

Can anyone help me in changing the cron schedule to December 31st of every year/disabling the search itself? Thanks in advance for your help.

Regards,
Shiv

0 Karma
1 Solution

shiv1593
Communicator

Solved it: Disable all the searches that Correlation search was referencing to/referencing the data (we didn't need them too) and the search got disabled.

For cron schedules, I found a great website, where you can build yours and use them in Splunk. https://crontab.guru/

View solution in original post

0 Karma

shiv1593
Communicator

Solved it: Disable all the searches that Correlation search was referencing to/referencing the data (we didn't need them too) and the search got disabled.

For cron schedules, I found a great website, where you can build yours and use them in Splunk. https://crontab.guru/

0 Karma

accsam
New Member

Try with the below cron schedule

0 0 31 12 *

0 Karma

shiv1593
Communicator

Hi Accsam,

Tried that. But it is throwing the following alert ' there was an error saving the correlation search. invalid alert_comparator="" '

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...