Reporting

correlation search was not found

vin02
Path Finder

we are using enterprise security 4.7.x. we have created custom app and added saved search in that to trigger the incident review.its creating the incident in the incident review page but while i am clicking the link correlation search, its redirecting to pop-up like correlation search was not found.

could you please help on this.

0 Karma
1 Solution

jstoner_splunk
Splunk Employee
Splunk Employee

There are a number of switches/options available within the savedsearches.conf for correlation searches that were previously in the correlationsearches.conf file. If you look at your savedsearches.conf file in DA-ESS-EndpointProtection/default/ (for example) you will see saved searches that are used for reports v correlation searches and the different options that correlation searches use including a number of action.notable and action.risk options, cron_schedule amongst others.

My suggestion would be to use these correlation searches as a template so that when you click on it, it will populate appropriately. Alternatively, you could use the Configure->Content Management and click Create New Content->Correlation Search, specify your app and create the conditions and notable from there.

View solution in original post

0 Karma

jstoner_splunk
Splunk Employee
Splunk Employee

There are a number of switches/options available within the savedsearches.conf for correlation searches that were previously in the correlationsearches.conf file. If you look at your savedsearches.conf file in DA-ESS-EndpointProtection/default/ (for example) you will see saved searches that are used for reports v correlation searches and the different options that correlation searches use including a number of action.notable and action.risk options, cron_schedule amongst others.

My suggestion would be to use these correlation searches as a template so that when you click on it, it will populate appropriately. Alternatively, you could use the Configure->Content Management and click Create New Content->Correlation Search, specify your app and create the conditions and notable from there.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...