What is the easiest way to rename a correlation search? There is rename link/button on the correlation search page, and the name field is not editable within the correlation search edit page.
Hi, they have to be renamed at the config file level because there are two configuration files involved.
jcoates-mba:default jcoates$ cd ~/Downloads/SplunkEnterpriseSecurityInstaller/default/src/etc/apps/SA-ThreatIntelligence/default/
jcoates-mba:default jcoates$ grep "Rule\]" savedsearches.conf
[Threat - Threat List Activity - Rule]
[Threat - Watchlisted Events - Rule]
jcoates-mba:default jcoates$ grep "Rule\]" correlationsearches.conf
[Threat - Threat List Activity - Rule]
[Threat - Watchlisted Events - Rule]
correlationsearches.conf is been deprecated in the newer version of Enterprise security.
Hi, they have to be renamed at the config file level because there are two configuration files involved.
jcoates-mba:default jcoates$ cd ~/Downloads/SplunkEnterpriseSecurityInstaller/default/src/etc/apps/SA-ThreatIntelligence/default/
jcoates-mba:default jcoates$ grep "Rule\]" savedsearches.conf
[Threat - Threat List Activity - Rule]
[Threat - Watchlisted Events - Rule]
jcoates-mba:default jcoates$ grep "Rule\]" correlationsearches.conf
[Threat - Threat List Activity - Rule]
[Threat - Watchlisted Events - Rule]