- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VijaySrrie
Builder
01-02-2020
10:06 AM
Hi ,
How to create custom correlation search is ES app. For eg: Traffic to suspicious country
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

woodcock
Esteemed Legend
01-02-2020
11:42 AM
The easiest way is to find one that is already very similar, go to the CLI and edit savedsearches.conf
and copy the entire stanza, rename the search, and update the search
and other settings, accordingly.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
01-02-2020
11:43 AM
From an ES dashboard select Configure->Content->Content management. Click the "Create New Content" button and select "Correlation Search". Fill in the form and click Save.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

woodcock
Esteemed Legend
01-02-2020
11:42 AM
The easiest way is to find one that is already very similar, go to the CLI and edit savedsearches.conf
and copy the entire stanza, rename the search, and update the search
and other settings, accordingly.
