How to fetch configured correlation data, Query notable events, including associated correlation rules for an app?
@sacumen see if the following rest query gives what you are looking for
| rest /servicesNS/-/-/saved/searches
| search title=*
| table title cron_schedule eai:acl.owner actions dispatch.earliest_time dispatch.latest_time search
Query notable events with index=notable
.
Correlations rules are stored in the app's savedsearches.conf files.
What other correlation data do you seek?
Thank you, I had the same query and this answer helped 🙂
Thanks for responding, but I am trying to fetch all the available correlation data through rest call, is there any api to achieve this in splunk?
Again I ask what correlation data to you seek?
See the REST API manuals for how to get data from Splunk using REST. https://docs.splunk.com/Documentation/Splunk/8.0.2/RESTUM/RESTusing
https://docs.splunk.com/Documentation/Splunk/8.0.2/RESTREF/RESTprolog