Hi All
I have configured a test Correlation search using Content Management tab. Now I am getting below message in splunk repeatedly:-
<>
I disabled the search and deleted the alert Rule that was created in SEARCH & REPORTING app as a part of this correlation search creation (I guess so..correct me also on this)...
This resulted in removal of Correlation search from ES that I created and disabled..
but still I am getting the same message...
Kindly share if I have done anything incorrect or something else needs to be done????
↧