Splunk Enterprise Security

Splunk App for Enterprise Security: Is there a way to reset all the correlation searches to default?

hcheang
Path Finder

Hello,

I forgot to copy the default correlation searches and made some alteration to the queries. As a result, I'm not receiving any alerts or scheduled report. Is there a way to reset all the correlation searches to default so that I can compare and find the problem? Also, if there is nothing wrong with the search queries, what should I check to find why any correlation searches or scheduled reports are not sent to the email address specified even though there are events occurring?

Thanks in advance!

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

There are backups in the EnterpriseSecuritySuiteInstaller/default/src folder.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!