Splunk Enterprise Security
Highlighted

How to fetch configured correlation data, query notable events, including associated correlation rules for an app?

Explorer

How to fetch configured correlation data, Query notable events, including associated correlation rules for an app?

0 Karma
Highlighted

Re: How to fetch configured correlation data, query notable events, including associated correlation rules for an app?

SplunkTrust
SplunkTrust

Query notable events with index=notable.
Correlations rules are stored in the app's savedsearches.conf files.
What other correlation data do you seek?

---
If this reply helps you, an upvote would be appreciated.
Highlighted

Re: How to fetch configured correlation data, query notable events, including associated correlation rules for an app?

Explorer

Thanks for responding, but I am trying to fetch all the available correlation data through rest call, is there any api to achieve this in splunk?

0 Karma
Highlighted

Re: How to fetch configured correlation data, query notable events, including associated correlation rules for an app?

SplunkTrust
SplunkTrust

Again I ask what correlation data to you seek?
See the REST API manuals for how to get data from Splunk using REST. https://docs.splunk.com/Documentation/Splunk/8.0.2/RESTUM/RESTusing
https://docs.splunk.com/Documentation/Splunk/8.0.2/RESTREF/RESTprolog

---
If this reply helps you, an upvote would be appreciated.
0 Karma