Splunk Enterprise Security

HowTo deploy a set of correlation search within new app to different Splunk ES

LM_ACN
Engager

Hello everyone,

i have a set of correlation search (about 250) to deploy in different Splunk ES.

Instead of writing them one by one in every Splunk, i would create an application with all those correlation search and later deploy it to the Splunk.

It is sufficient to popolate savedsearch.conf file with one stanza per correlation search?

Thanks in advance,

Luca

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's the general idea, but may not be enough.  If any of the searches use macros, or lookups then you'll also need to populate macros.conf, or transforms.conf.  Datamodels require a bit more effort to transfer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

LM_ACN
Engager

most of the correlation searches relies on Data Model, but they are all implemented in the various Splunk.

Of course, those correlation searches will be able to generate notable within their native action, that's right?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...