Splunk Search

correlate uses and samples

Paul_tcs
Explorer

Hi All,

Am trying to find the usage of correlation. When i try my search using coorelation, it gives me an output, but am unable to understand the result.

index="citicom" alerts|correlate email, application

result gives as
Rowfield email APPLICATION
email 1.00 1.00
application 1.00 1.00

can anyone explain me the coorelation with some simple example?

Tags (2)
0 Karma

HiroshiSatoh
Champion

It is inferred from the result of sampling.

NO col1 col2 col3
1 A X Y
2 B

3 C X
4 D

5 E

     col1       col2       col3

col1 100%(5/5) 40%(2/5) 20%(1/5)
col2 40%(2/5) 100%(2/2) 50%(1/2)

col3 20%(1/5) 50%(1/2) 100%(1/1)

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...