Splunk Enterprise Security

Where to find more correlation searches?

echojacques
Builder

My Splunk + Enterprise Security installation came with 51 canned correlation searches. For example, searches to discover Brute Force Behavior, LogMeIn activity, etc. All have been very useful and leave me wanting more.

Is there a place where I can get/find more correlation searches without having to write them myself? I think the correlation searches are just as useful/valuable as Splunk apps.

Thanks.

1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

One thing to note is that correlation searches are just Splunk searches with a decision in them... Gather data, make a test, and check the result. Here's a blog post on the basic technique: http://blogs.splunk.com/2012/10/01/simple-correlation-in-splunk/

As Luke notes, we'd be happy to help if you have a specific idea in mind!

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

One thing to note is that correlation searches are just Splunk searches with a decision in them... Gather data, make a test, and check the result. Here's a blog post on the basic technique: http://blogs.splunk.com/2012/10/01/simple-correlation-in-splunk/

As Luke notes, we'd be happy to help if you have a specific idea in mind!

echojacques
Builder

Thanks, and I'll post if I think of new correlation search ideas. Just thought there might be a place where Splunk users are sharing them.

0 Karma

LukeMurphey
Champion

There isn't really a another source for Correlation Searches. That said, I would love to hear your ideas; perhaps I could get a few written for you. Let me know what ideas you have.

lukejadamec
Super Champion

There is a place, here.
Like Luke^ said, post what you think you need.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...