Splunk Enterprise Security

HowTo deploy a set of correlation search within new app to different Splunk ES

LM_ACN
Engager

Hello everyone,

i have a set of correlation search (about 250) to deploy in different Splunk ES.

Instead of writing them one by one in every Splunk, i would create an application with all those correlation search and later deploy it to the Splunk.

It is sufficient to popolate savedsearch.conf file with one stanza per correlation search?

Thanks in advance,

Luca

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's the general idea, but may not be enough.  If any of the searches use macros, or lookups then you'll also need to populate macros.conf, or transforms.conf.  Datamodels require a bit more effort to transfer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

LM_ACN
Engager

most of the correlation searches relies on Data Model, but they are all implemented in the various Splunk.

Of course, those correlation searches will be able to generate notable within their native action, that's right?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...