Splunk Enterprise Security

HowTo deploy a set of correlation search within new app to different Splunk ES

LM_ACN
Engager

Hello everyone,

i have a set of correlation search (about 250) to deploy in different Splunk ES.

Instead of writing them one by one in every Splunk, i would create an application with all those correlation search and later deploy it to the Splunk.

It is sufficient to popolate savedsearch.conf file with one stanza per correlation search?

Thanks in advance,

Luca

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's the general idea, but may not be enough.  If any of the searches use macros, or lookups then you'll also need to populate macros.conf, or transforms.conf.  Datamodels require a bit more effort to transfer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

LM_ACN
Engager

most of the correlation searches relies on Data Model, but they are all implemented in the various Splunk.

Of course, those correlation searches will be able to generate notable within their native action, that's right?

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...