Splunk Search

Enterprise Search: Can we delete or clone correlation searches in the Content Management section?

danielbb
Motivator

Under the Content Management section, we only see the Enable and Disable options for the correlation searches. Is there a way to clone, or delete them? Changing their names is needed quite often.

Tags (1)
0 Karma
1 Solution

starcher
SplunkTrust
SplunkTrust

No there is no feature in the ES UI for that. Renaming would be nice. Best you can do is find the search under saved searches. Delete then recreate it.

View solution in original post

Azeemering
Builder

Update on this.
In current versions (6.x and higher) you are now able to Clone a Correlation Search under Content Management in Enterprise Security.
To delete a correlation search you can go to Settings > Searches, reports, and alerts

cyue_splunk
Splunk Employee
Splunk Employee

There is no delete or clone in the Content Management in ES app. You can find your correlation search and delete or clone it in Splunk Enterprise "Settings" ->"Searches, reports and alerts".

0 Karma

starcher
SplunkTrust
SplunkTrust

No there is no feature in the ES UI for that. Renaming would be nice. Best you can do is find the search under saved searches. Delete then recreate it.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...