I need to access these saved searches & change their timing due to them conflicting / running at the same time so many are being skipped. Any helpfu
In Enterprise Security, you can change the timing of the correlation searches in Content Management:
https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Configurecorrelationsearches#Change_correlation...
There's also a filter by App, so that you can view only the searches related to the app you're interested in.
Let me know if that helps.
Thank u. The Instructions on the link says:
I don't see configure on the ES menu bar....... Please advise
When you're in the Enterprise Security (ES) app, Configure is located in the ES menu bar as follows (I've circled it in orange):