Hi, Why splunk correlationsearches not running on SplunkEnterpriseSecurity App ? but correlationsearch run another app for example search and reporting app ES versiyon 6.2.0 Splunk Version 8...
Reg. Correlationsearches. Do they have to be configured in Splunk Ent. & ES? Could they be only on one of these 2 ? And reused in the whole environment? If can be on one side? How do I benefit a...
...irstTime | `hoursago(24)` | stats dc(dest) as dest_count by transport,dest_port | search dest_count>10
In the correlationsearch properties (Configure->CorrelationSearches->Edit Correlation...
We have defined more than 20 correlationsearches but the correlation_searches_lister (Configure > CorrelationSearches) shows only the first 20. There is no possibility to navigate to the next 2...
Hello friends, We have Splunk ES and we stored our data in different indexes (OS logs, Network logs, ...) I have a question about correlationsearches. Some correlationsearches didn't use Data M...
When you create or edit a correlationsearch, you can configure the Time range, Cron schedule, and Throttling. I have several correlationsearchesconfigured like this:
Time range: Start: -1...
...? Because when it's a correlationsearch, it would turn into a notable event for incident handling, which is what I'm trying to do with my alerts. But, I'm not sure how to configure the correlationsearch...
Hi all,
On a similar note to this question, I would also like to know the complete list of pre-configured correlationsearches available in ES 4.0
We don't have ES installed and therefore I c...
Is there a way to be able to configure Maintenance Windows for Services to include all Episodes without adding each service to “Association” in the correlationsearch? The problem with doing that i...
In Splunk Enterprise Security (ES), we cannot save a correlationsearch as a user with ess_admin. This works if user is admin.
The navigation is: ES/Configure/Content Management/Create new C...