Which of the following forms part of tuning correlation searches for a new ES installation?
When onboarding a new Splunk Enterprise Security installation, tuning correlation searches primarily involves reviewing and adjusting the adaptive response actions bound to each search, since these actions determine what happens whenever the search's conditions are met, most commonly creating a notable event, but also potentially adding risk scores, running a script, or triggering another downstream action. Getting these adaptive response actions correctly scoped and configured is essential to avoid alert fatigue and to ensure the environment surfaces meaningful notable events, which is why adaptive response configuration is treated as a core part of the correlation search tuning process for a freshly deployed ES environment, rather than adjusting role-based permissions or storage/index plumbing that are configured once and rarely revisited during tuning.
Community Discussion