Splunk Enterprise Security

HowTo deploy a set of correlation search within new app to different Splunk ES


Hello everyone,

i have a set of correlation search (about 250) to deploy in different Splunk ES.

Instead of writing them one by one in every Splunk, i would create an application with all those correlation search and later deploy it to the Splunk.

It is sufficient to popolate savedsearch.conf file with one stanza per correlation search?

Thanks in advance,




0 Karma


That's the general idea, but may not be enough.  If any of the searches use macros, or lookups then you'll also need to populate macros.conf, or transforms.conf.  Datamodels require a bit more effort to transfer.

If this reply helps you, Karma would be appreciated.
0 Karma


most of the correlation searches relies on Data Model, but they are all implemented in the various Splunk.

Of course, those correlation searches will be able to generate notable within their native action, that's right?

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...