Splunk ES Correlation Searches (Rules) Best & Cool Practices
1 min readJan 15, 2024
The following document is by far the top accessed resource from my solo business website. Since its first release in late 2020 I’ve received lots of feedback and suggestions.
What's it about?
It's a 15-page PDF covering the challenges you encounter when writing or maintaining correlation searches in Splunk's Enterprise…