Splunk Enterprise Security

Splunk App for Enterprise Security: Is there a way to reset all the correlation searches to default?

hcheang
Path Finder

Hello,

I forgot to copy the default correlation searches and made some alteration to the queries. As a result, I'm not receiving any alerts or scheduled report. Is there a way to reset all the correlation searches to default so that I can compare and find the problem? Also, if there is nothing wrong with the search queries, what should I check to find why any correlation searches or scheduled reports are not sent to the email address specified even though there are events occurring?

Thanks in advance!

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

There are backups in the EnterpriseSecuritySuiteInstaller/default/src folder.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...