Splunk Enterprise Security

What is the easiest way to rename a correlation search?

sspinner
Explorer

What is the easiest way to rename a correlation search? There is rename link/button on the correlation search page, and the name field is not editable within the correlation search edit page.

0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, they have to be renamed at the config file level because there are two configuration files involved.

jcoates-mba:default jcoates$ cd ~/Downloads/SplunkEnterpriseSecurityInstaller/default/src/etc/apps/SA-ThreatIntelligence/default/
jcoates-mba:default jcoates$ grep "Rule\]" savedsearches.conf 
[Threat - Threat List Activity - Rule]
[Threat - Watchlisted Events - Rule]
jcoates-mba:default jcoates$ grep "Rule\]" correlationsearches.conf 
[Threat - Threat List Activity - Rule]
[Threat - Watchlisted Events - Rule]

View solution in original post

Inayath_khan
Path Finder

correlationsearches.conf is been deprecated in the newer version of Enterprise security.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, they have to be renamed at the config file level because there are two configuration files involved.

jcoates-mba:default jcoates$ cd ~/Downloads/SplunkEnterpriseSecurityInstaller/default/src/etc/apps/SA-ThreatIntelligence/default/
jcoates-mba:default jcoates$ grep "Rule\]" savedsearches.conf 
[Threat - Threat List Activity - Rule]
[Threat - Watchlisted Events - Rule]
jcoates-mba:default jcoates$ grep "Rule\]" correlationsearches.conf 
[Threat - Threat List Activity - Rule]
[Threat - Watchlisted Events - Rule]
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...