Splunk Enterprise Security

How come I'm unable to disable a correlation search nor able to save the changes made on it?

shiv1593
Communicator

Hi All,

This is a two fold question.

Specs: Splunk Enterprise Security Version 6.6.1

Problem 1: I'm trying to disable a correlation search, but am unable to do so. When I click on disable, inside the content management, it says "Searches have been sucessfully disabled", but the one particular search isn't getting disabled.

The problem is that the app TA-Domaintools, using which the search was created, is no longer configured properly. By the time I took over the administration of our environment, we have seemed to have lost the API key and the credentials for it. It asks for reconfiguration, but we can't do that without the credentials.

Problem 2: The app is scheduled to run on a cron schedule of every 5 minutes. Since I was unable to disable the search, I tried to schedule to run on every December 31st, at 12 AM. The cron i put in there is 12/31*/12*. The syntax is wrong, so I tried to save the original one, /5***

But then, it started throwing an error while saving: ' there was an error saving the correlation search. invalid alert_comparator="" '.

Can anyone help me in changing the cron schedule to December 31st of every year/disabling the search itself? Thanks in advance for your help.

Regards,
Shiv

0 Karma
1 Solution

shiv1593
Communicator

Solved it: Disable all the searches that Correlation search was referencing to/referencing the data (we didn't need them too) and the search got disabled.

For cron schedules, I found a great website, where you can build yours and use them in Splunk. https://crontab.guru/

View solution in original post

0 Karma

shiv1593
Communicator

Solved it: Disable all the searches that Correlation search was referencing to/referencing the data (we didn't need them too) and the search got disabled.

For cron schedules, I found a great website, where you can build yours and use them in Splunk. https://crontab.guru/

0 Karma

accsam
New Member

Try with the below cron schedule

0 0 31 12 *

0 Karma

shiv1593
Communicator

Hi Accsam,

Tried that. But it is throwing the following alert ' there was an error saving the correlation search. invalid alert_comparator="" '

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...