- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Under the Content Management section, we only see the Enable and Disable options for the correlation searches. Is there a way to clone, or delete them? Changing their names is needed quite often.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

No there is no feature in the ES UI for that. Renaming would be nice. Best you can do is find the search under saved searches. Delete then recreate it.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Update on this.
In current versions (6.x and higher) you are now able to Clone a Correlation Search under Content Management in Enterprise Security.
To delete a correlation search you can go to Settings > Searches, reports, and alerts
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

There is no delete or clone in the Content Management in ES app. You can find your correlation search and delete or clone it in Splunk Enterprise "Settings" ->"Searches, reports and alerts".
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

No there is no feature in the ES UI for that. Renaming would be nice. Best you can do is find the search under saved searches. Delete then recreate it.
