Hello,
We'd like to help our analysts to tell which correlation search is impacted in case of log source issue. But we can't find the way to list the dependence Correlation Search --> Data Model or Index it is based on.
Do you know if there is a way to do it?
For information, we have 3 types of Correlation Searches:
- Using an index, like index=internal action=create_user ...
- Using a datamodel, like | from datamodel:"Change_Analysis"."Account_Management" | ...
- Using a datamodel via tstats, like | tstats allow_old_summaries=t count from datamodel="Authentication" ...
Thanks for the help.
See if this gets you started in the right direction.
| rest /services/saved/searches
| search is_scheduled=1 disabled=0
| fields title eai:acl.app search datamodel index
| rex field=search "from datamodel[:=]\"?(?<datamodel>\w+)" | rex field=search "^index\s*=\s*(?<index>\w+)"
See if this gets you started in the right direction.
| rest /services/saved/searches
| search is_scheduled=1 disabled=0
| fields title eai:acl.app search datamodel index
| rex field=search "from datamodel[:=]\"?(?<datamodel>\w+)" | rex field=search "^index\s*=\s*(?<index>\w+)"
Hi @richgalloway
Thanks for the help, That's exactly what we were searching for!
We only implemented one more condition: | where match('action.correlationsearch.enabled', "1|[Tt]|[Tt][Rr][Uu][Ee]")
. Without it all deactivated searches are listed as well (have no idea why disabled=0
doesn't help).