Splunk Enterprise Security

HowTo deploy a set of correlation search within new app to different Splunk ES

LM_ACN
Engager

Hello everyone,

i have a set of correlation search (about 250) to deploy in different Splunk ES.

Instead of writing them one by one in every Splunk, i would create an application with all those correlation search and later deploy it to the Splunk.

It is sufficient to popolate savedsearch.conf file with one stanza per correlation search?

Thanks in advance,

Luca

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's the general idea, but may not be enough.  If any of the searches use macros, or lookups then you'll also need to populate macros.conf, or transforms.conf.  Datamodels require a bit more effort to transfer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

LM_ACN
Engager

most of the correlation searches relies on Data Model, but they are all implemented in the various Splunk.

Of course, those correlation searches will be able to generate notable within their native action, that's right?

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...