Splunk Enterprise Security

How do I access a list of Saved searches for different apps. To change their timing in ES? Any helpful SPLs ? Thank u

SamHTexas
Builder

I need to access these saved searches & change their timing due to them conflicting / running at the same time so many are being skipped. Any helpfu

Labels (1)
Tags (1)
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

In Enterprise Security, you can change the timing of the correlation searches in Content Management: 
https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Configurecorrelationsearches#Change_correlation... 

There's also a filter by App, so that you can view only the searches related to the app you're interested in. 

Let me know if that helps.

SamHTexas
Builder

Thank u. The Instructions on the link says: 

  1. From the Splunk ES menu bar, select Configure > Content > Content Management.
  2. Filter the Content Management page by a Type of Correlation Search to view only correlation searches.
  3. Review the names and descriptions of the correlation searches to determine which ones to enable to support your security use cases.

I don't see configure on the ES menu bar....... Please advise

Tags (1)
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

When you're in the Enterprise Security (ES) app, Configure is located in the ES menu bar as follows (I've circled it in orange): 

Screen Shot 2021-07-27 at 9.57.10 AM.png

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...