Splunk Enterprise Security

Correlation searches scheduling to overcome downtimes and event delays

tibi
Observer

Hello,

 

Hello,

 

Any suggestions on how to configure the correlation search schedule in a way that will not be affected by a maintenance downtime ? 

 

For example if you have a correlation search that is schedule to run every hour at minute 5 for the last hour . how can be configured to cover also the skipped run and to not miss alerts?

 

Thanks.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you do your correlation search over a couple of hours bucketed by hour, then append the previous results and remove duplicates?

0 Karma

tibi
Observer

thanks for the reply.

 

please can you provide an example how to configure the cs and how to exclude duplicates?

0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...

Secure Your Future: Mastering Upgrade Readiness for Splunk 10

Spotlight: The Splunk Health Assistant Add-On  The Splunk Health Assistant Add-On is your ultimate companion ...

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...