Hi, Why splunk correlationsearches not running on SplunkEnterpriseSecurity App ? but correlationsearch run another app for example search and reporting app ES versiyon 6.2.0 Splunk Version 8...
...irstTime | `hoursago(24)` | stats dc(dest) as dest_count by transport,dest_port | search dest_count>10
In the correlationsearch properties (Configure->CorrelationSearches->Edit Correlation...
We have defined more than 20 correlationsearches but the correlation_searches_lister (Configure > CorrelationSearches) shows only the first 20. There is no possibility to navigate to the next 2...
When you create or edit a correlationsearch, you can configure the Time range, Cron schedule, and Throttling. I have several correlationsearchesconfigured like this:
Time range: Start: -1...
Hello friends, We have Splunk ES and we stored our data in different indexes (OS logs, Network logs, ...) I have a question about correlationsearches. Some correlationsearches didn't use Data M...
Hi all,
On a similar note to this question, I would also like to know the complete list of pre-configured correlationsearches available in ES 4.0
We don't have ES installed and therefore I c...
...? Because when it's a correlationsearch, it would turn into a notable event for incident handling, which is what I'm trying to do with my alerts. But, I'm not sure how to configure the correlationsearch...
Thanks in advance for any assistance you can please lend.
Can someone please tell me how I can configure an Enterprise Security correlationsearch that triggers only when a specific a...
Reg. Correlationsearches. Do they have to be configured in Splunk Ent. & ES? Could they be only on one of these 2 ? And reused in the whole environment? If can be on one side? How do I benefit a...
...ingle search to:
extract all traceIds that happened between 17:00 and 17:05
search for the captured traceIds in larger range (say between 16:00 and 18:00)
Is that possible? Thank you!